MikhbarMIKHBAR
Cybersecurity

Senate Passes Bipartisan Healthcare Cybersecurity Bill

The US Senate has passed the Health Care Cybersecurity and Resilience Act by unanimous consent, sending the bipartisan legislation to the House of Representatives.

Senate Passes Bipartisan Healthcare Cybersecurity Bill

Senate Passes Bipartisan Healthcare Legislation

The US Senate has officially passed the bipartisan Health Care Cybersecurity and Resilience Act, which was originally [introduced](https://www.securityweek.com/bipartisan-legislation-seeks-stronger-healthcare-cybersecurity/) by Senators Bill Cassidy, Maggie Hassan, Jon Cornyn, and Mark Warner. Initially brought to Congress in 2024, the bill failed to pass before the close of that congressional term but was subsequently [reintroduced](https://www.help.senate.gov/rep/newsroom/press/chair-cassidy-colleagues-reintroduce-legislation-to-strengthen-cybersecurity-in-health-care) in December 2025. Having secured passage through the Senate via unanimous consent, the legislation now proceeds to the US House of Representatives for further consideration.

Lawmakers behind the initiative emphasize the critical nature of shielding medical infrastructure. "Cyberattacks on our healthcare sector not only put patients' sensitive health data at risk but can delay life-saving care. This bipartisan legislation ensures health institutions can safeguard Americans' health data against increasing cyber threats," stated Senator Cassidy. The overarching purpose of the measure is to assist the healthcare sector in significantly reducing future successful criminal attacks.

The Escalating Cyber Threat Landscape in Healthcare

The [Healthcare](https://www.securityweek.com/topics/healthcare/) sector remains a primary target for malicious actors looking to exploit vulnerabilities. Last year alone saw more than 730 cyber breaches impacting over 270 million Americans, resulting in an average expense of [$10 million per breach](https://www.securityweek.com/cost-of-data-breach-in-us-rises-to-10-22-million-says-latest-ibm-report/). Major historical and recent events underscore the severity of the crisis, including the 2015 [Anthem](https://www.securityweek.com/health-insurer-anthem-suffers-massive-data-breach/) breach that compromised personal information and health records for 78.8 million customers at a cost exceeding $115 million.

Additional high-profile incidents include the 2024 ransomware attack against [Ascension](https://www.securityweek.com/5-6-million-impacted-by-ransomware-attack-on-healthcare-giant-ascension/), which disrupted clinical operations and electronic health records across 11 US states, and the 2024 [Change Healthcare](https://www.securityweek.com/change-healthcare-cyberattack-causes-significant-disruption/) cyberattack. The latter is believed to have exposed the data of over 190 million individuals while introducing profound delays in care and electronic prescribing across the country.

Ransomware and Double-Extortion Challenges

Security analysts point out that the definitive criminal weapon of choice in campaigns targeting medical entities is ransomware paired with double-extortion tactics, alongside an increase in pure data-extortion methods. These attacks prove particularly devastating because hospitals and care providers find themselves trapped between government advisories discouraging ransom payments and their primary ethical and legal obligation to protect patients.

Criminal organizations frequently rely on the expectation that medical providers will pay a ransom rather than risk delaying or compromising patient health. Commenting on the legislative goals, Senator Cornyn noted, "Patients deserve absolute confidence that their sensitive medical data stored online is protected and shielded from cybersecurity breaches or ransomware attacks. This legislation would strengthen interagency coordination and improve security practices for rural providers, ensuring Texans' health care is not delayed or compromised by cyberattacks."

Key Elements and Interagency Coordination

To counter these persistent criminal tactics, the newly passed Act outlines several key provisions aimed at uplifting the sector's cyber resilience. These elements include grants designated for cyberattack prevention and response, training programs focusing on best cybersecurity practices, targeted support for rural health clinics, and enhanced operational coordination between the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA).

Furthermore, the legislation mandates updates to current regulations to guarantee the implementation of leading cybersecurity protocols and requires the HHS Secretary to develop and execute a comprehensive cybersecurity incident response plan. The framework also establishes the Administration for Strategic Preparedness and Response (ASPR) as the clear Sector Risk Management Agency, creating a direct pipeline for CISA to deliver tailored, actionable threat intelligence.

Industry Reception and Compliance Concerns

While the healthcare sector has broadly welcomed the legislative push, members of the cybersecurity industry caution that the ultimate success of the Act will depend entirely on consistent enforcement. Experts have raised concerns regarding the potential financial strain of compliance, noting that regulatory burdens could overwhelm organizations if federal funding or technical assistance fails to keep pace.

Ultimately, the legislation introduces a fundamentally new compliance requirement for the healthcare market. Observers observe that while structured regulation remains effective in theory, it presents practical challenges that demand full and synchronized cooperation from both the federal government and healthcare institutions.

Sources

  • SecurityWeekSenate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

Continue chronologically

You are readingSenate Passes Bipartisan Healthcare Cybersecurity Bill
Rejetto HFS Vulnerability Discovered by AI Hit by Exploitation
Older storyRejetto HFS Vulnerability Discovered by AI Hit by ExploitationOctober 5, 2026 · 3 min