News
Senate Passes Healthcare Cybersecurity Bill With New Standards and Support for Rural Providers
- By John K. Waters
- 10/05/2026
The U.S. Senate has passed bipartisan legislation that would establish minimum cybersecurity practices for healthcare organizations and strengthen federal coordination when attacks threaten patient care. The measure also would support security improvements at rural providers, including migration to secure cloud platforms.
The Health Care Cybersecurity and Resiliency Act of 2026, S. 3315, passed by unanimous consent on Sept. 30. It still requires House approval and the president’s signature to become law. The American Hospital Association reported the Senate action on Oct. 5.
“Cyberattacks on our health care systems can have life-or-death consequences for patients and put the sensitive information of millions of Americans at risk,” Sen. Mark Warner, D-Va., said in an announcement of the Senate’s passage.
Warner joined Sens. Bill Cassidy, R-La., Maggie Hassan, D-N.H., and John Cornyn, R-Texas, in announcing the action. The lawmakers described the legislation as a response to attacks that expose medical information and interrupt healthcare services. Warner urged the House to act quickly, while Hassan emphasized the challenges facing rural providers with fewer resources.
The Senate-passed text would direct the Department of Health and Human Services to update security regulations to require risk-based practices, including multifactor authentication, encryption of protected health information, and monitoring that includes penetration testing. The updated requirements would take effect 36 months after enactment.
It also would require HHS and the Cybersecurity and Infrastructure Security Agency to establish a joint plan for significant healthcare cyber incidents within a year. Separately, HHS would expand its own incident response plan to address departmental systems.
For rural organizations, proposed guidance would address secure cloud migration and shared or outsourced security expertise. Authorized grants could support cloud migration and incident response planning, linking infrastructure upgrades to cybersecurity readiness.
The hospital industry’s response highlights another concern for healthcare technology leaders: where responsibility falls when outside companies handle sensitive information.
In a statement submitted for a Sept. 15 House hearing, the American Hospital Association welcomed grant opportunities and workforce support in a related House proposal. But it asked lawmakers to clarify how cybersecurity standards would apply to third-party vendors.
The association said, “third parties handling health information should be held to the same privacy and security standards as covered entities and business associates.” It cited the Change Healthcare attack as an example of the risks posed by service and software providers.
That position underscores the challenge behind the legislation: improving security at individual hospitals while addressing dependencies beyond their walls. Federal coordination and assistance could help providers prepare, but the association’s comments show that the scope of vendor accountability remains a point of debate.
Senate passage moves the proposal forward. For healthcare IT leaders, the next question is whether the House will advance legislation that turns those proposed protections into enforceable requirements.
About the Author
John K. Waters is the editor in chief of a number of Converge360.com sites, with a focus on high-end development, AI and future tech. He's been writing about cutting-edge technologies and culture of Silicon Valley for more than two decades, and he's written more than a dozen books. He also co-scripted the documentary film Silicon Valley: A 100 Year Renaissance, which aired on PBS. He can be reached at [email protected].