New US Bills Push Healthcare Cybersecurity Standards Forward
The HISAA is reintroduced and the Health Care Cybersecurity and Resiliency Act advances in Congress.
Why it matters: These bills aim to enforce mandatory cybersecurity standards and provide funding to healthcare providers, enhancing data protection and patient safety. In-house counsel and compliance officers will face evolving regulatory requirements impacting organizational cybersecurity practices.
- The Health Care Cybersecurity and Resiliency Act (S. 3315) passed the Senate unanimously on October 1, 2026.
- The Health Infrastructure Security and Accountability Act was reintroduced on September 17, 2026, by Senators Warner and Wyden.
- The Resiliency Act authorizes HHS grants for hiring cybersecurity staff and upgrading electronic systems.
- The Congressional Budget Office estimates $421 million cost over 2026–2031 to implement the Resiliency Act.
Congress is moving swiftly to bolster cybersecurity in the U.S. healthcare sector amid rising cyberattack threats. The Health Care Cybersecurity and Resiliency Act (S. 3315) passed the Senate unanimously on October 1, 2026. This legislation empowers the Department of Health and Human Services (HHS) to provide grants that enable healthcare entities to hire cybersecurity professionals and modernize electronic systems, aiming to strengthen defenses against data breaches.
Meanwhile, the Health Infrastructure Security and Accountability Act (HISAA) was reintroduced on September 17, 2026, by Senators Mark Warner (D-VA) and Ron Wyden (D-OR). It proposes mandatory cybersecurity standards for healthcare organizations alongside securing federal funding aimed particularly at rural and underserved hospitals to boost their cybersecurity capabilities.
The Congressional Budget Office estimates implementation costs of the Resiliency Act at around $421 million from 2026 through 2031, reflecting a substantial federal investment in healthcare cybersecurity measures (CBO Report).
The legislative urgency responds to an alarming increase in cyberattacks, with 426 hacking-related breaches reported from January through August 2026 alone, affecting the protected health information (PHI) of 73 million Americans. Senator Warner explained the need for robust protections, stating cyberattacks "compromise Americans' most sensitive personal information, delay essential medical care, and put lives at risk." He also emphasized the insufficiency of voluntary standards in ensuring safety and privacy as cybercriminals escalate their attacks.
These bills mark significant steps toward formalizing cybersecurity requirements in healthcare, impacting compliance mandates for healthcare providers and turning cybersecurity from a voluntary best practice into enforceable federal standards.
By the numbers:
- $421 million — projected cost to implement Health Care Cybersecurity and Resiliency Act from 2026-2031
- 426 hacking-related breaches — reported in U.S. healthcare sector Jan-Aug 2026
- 73 million — Americans' PHI compromised in hacking-related breaches Jan-Aug 2026