S. 3315 · Passed Senate · Health
Health Care Cybersecurity and Resiliency Act of 2026
Sponsor: Bill Cassidy (R-LA)
What it does
- Require private health care entities to adopt minimum cybersecurity practices including multifactor authentication.
- Direct HHS to expand and update biennially a plan detailing cybersecurity protocols for HHS personnel.
- Establish joint coordination between HHS and CISA to improve health care cybersecurity and respond to significant incidents.
- Require health care providers and plans to disclose the number of individuals affected in breach notification.
Official summary
Health Care Cybersecurity and Resiliency Act of 2026 This bill expands federal requirements and resources for preventing and responding to cybersecurity incidents in the health care and public health sectors. The bill directs the Department of Health and Human Services (HHS) to require private health care-related entities to adopt minimum cybersecurity practices (e.g., multifactor authentication), more specifically identify the standards for mitigating penalties relating to violations of health information privacy and security, expand and update biennially a specified plan that details cybersecurity protocols for HHS personnel, provide training and best practices to support the expansion of the workforce for health care cybersecurity, provide guidance on cybersecurity readiness to rural entities, and designate one representative to lead oversight and coordination of cybersecurity activities within HHS. Also, HHS and the Cybersecurity and Infrastructure Security Agency (CISA) must coordinate to improve health care cybersecurity, including by (1) providing resources for entities receiving information from HHS or CISA programs, and (2) establishing a joint cybersecurity capability…
Latest action
Oct 5, 2026: Held at the desk.
Committee: Senate Health, Education, Labor, and Pensions