The US Senate has passed the bipartisan Health Care Cybersecurity and Resilience Act, introduced by Senators Bill Cassidy, Maggie Hassan, Jon Cornyn, and Mark Warner.
The bill was first introduced in 2024, but failed to pass before the end of that congressional term. It was reintroduced in December 2025.
Having passed the Senate by unanimous consent, the Health Care Cybersecurity and Resilience Act now heads to the US House of Representatives for consideration.
“Cyberattacks on our healthcare sector not only put patients’ sensitive health data at risk but can delay life-saving care. This bipartisan legislation ensures health institutions can safeguard Americans’ health data against increasing cyber threats,” claims Cassidy. Its purpose is to assist the sector in reducing the number of future successful criminal attacks.
Healthcare is a primary target for cybercriminals. More than 730 cyber breaches affected over 270 million Americans last year – costing an average of $10 million per breach.
Major incidents include the historic Anthem breach of 2015 (compromising the PI and health records of 78.8 million customers, and costing more than $115 million); the ransomware attack against Ascension in 2024 (which disrupted clinical operations and electronic health records across 11 US states), and the Change Healthcare attack in 2024 that is believed to have exposed the data of over 190 million people while causing significant delays in care and electronic prescribing.
The definitive criminal weapon of choice in this war against healthcare is ransomware coupled with double-extortion (and increasingly, pure data-extortion). Ransomware is devastating to healthcare. The sector is caught between government advice not to pay ransoms and its own requirement to protect its patients. Criminals expect it to pay a ransom rather than risk the health of patients. The new Act aims to help the sector improve its resilience against these attacks.
“Patients deserve absolute confidence that their sensitive medical data stored online is protected and shielded from cybersecurity breaches or ransomware attacks,” said Cornyn. “This legislation would strengthen interagency coordination and improve security practices for rural providers, ensuring Texans’ health care is not delayed or compromised by cyberattacks.”
Hopefully, the intention is to protect patients beyond the borders of Texas.
Key elements of the Act include the provision of grants to improve cyberattack prevention and response, and training in best cybersecurity practices; improved support for rural health clinics; better coordination between HHS and CISA (to improve response to cyberattacks); updates to current regulations to ensure use of the best cybersecurity practices; and a requirement for the HHS Secretary to develop and implement a cybersecurity incident response plan.
The Act attempts to provide central cybersecurity guidance across the various existing frameworks. Of particular relevance is the formalized inter-agency coordination establishing the Administration for Strategic Preparedness and Response (ASPR) as the clear Sector Risk Management Agency, and building a direct pipeline for CISA to provide tailored, actionable threat intelligence.
The Act is generally welcomed by the healthcare sector, but the security industry cautions that success will depend on how consistently it is enforced. There are concerns about the financial strain of compliance if federal funding or technical assistance fails to keep pace with the regulatory requirements.
The reality is that this is fundamentally a new compliance requirement on healthcare. The concept of regulation is good in theory but difficult to fulfill in practice. This regulation requires full compliance from two parties – both the government and the healthcare sector.
Related: Millions Impacted Across Several US Healthcare Data Breaches
Related: Data Breaches at Healthcare Organizations in Illinois and Texas Affect 600,000
Related: Serial-to-IP Converter Flaws Expose OT and Healthcare Systems to Hacking
Related: Healthcare IT Platform CareCloud Probing Potential Data Breach
