Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

US Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

The US Senate has just passed a landmark bipartisan bill aimed at bolstering healthcare cybersecurity, sending it to the House of Representatives for consideration. The Health Care Cybersecurity and Resilience Act is designed to help the healthcare sector fortify itself against cyber threats, which have become increasingly common in recent years.

Healthcare institutions are prime targets for cybercriminals, who often use ransomware attacks that can delay life-saving care and put patients’ sensitive health data at risk. Last year alone, over 270 million Americans were affected by more than 730 cyber breaches, with each breach costing an average of $10 million. Notorious incidents like the Anthem breach in 2015, which compromised the personal and health records of 78.8 million customers, and the 2024 ransomware attack on Ascension that disrupted clinical operations across 11 US states, serve as stark reminders of the sector’s vulnerability.

The bill, reintroduced by Senators Bill Cassidy, Maggie Hassan, Jon Cornyn, and Mark Warner after initially failing to pass in 2024, aims to address this problem. Key elements of the Act include providing grants for improved cyberattack prevention and response, training in best cybersecurity practices, enhanced support for rural health clinics, better interagency coordination between HHS and CISA, updated regulations to ensure use of top-notch cybersecurity practices, and a requirement for the HHS Secretary to develop and implement a comprehensive cybersecurity incident response plan.

The legislation seeks to provide centralized guidance across existing frameworks and establish clear Sector Risk Management Agency status for the Administration for Strategic Preparedness and Response (ASPR). This inter-agency coordination will enable CISA to provide tailored threat intelligence to healthcare institutions, helping them stay ahead of cyber threats. While the bill is generally welcomed by the healthcare sector, there are concerns that success will depend on consistent enforcement and adequate federal funding or technical assistance.

The passage of this bill marks a significant step towards protecting patients’ sensitive health data from cyber threats. However, its implementation will require sustained effort from both government agencies and healthcare institutions to ensure compliance with new regulations. Ultimately, the success of this legislation will hinge on effective coordination and consistent enforcement – two crucial elements that have often been lacking in previous attempts to strengthen healthcare cybersecurity.


Source: SecurityWeek — 2026-10-05