
Share
With ransomware gangs increasingly targeting hospitals, the Senate's unanimous approval of the Health Care Cybersecurity and Resilience Act signals a rare bipartisan push to protect patient data, especially at small and rural providers.
Imagine a rural hospital's computer systems locking up in the middle of a trauma case. Doctors can't pull up medication histories. Lab results vanish into a digital black hole. This isn't a hypothetical. It's the kind of scenario that has played out at hospitals across the country as ransomware attacks on healthcare systems have surged in recent years, and it's exactly the kind of disaster lawmakers are trying to get ahead of.
This past week, the U.S. Senate passed the bipartisan Health Care Cybersecurity and Resiliency Act of 2026, known as S.3315, by unanimous consent. That's a notable show of agreement in a chamber where consensus is often hard to find, and it reflects just how urgent the cybersecurity problem in healthcare has become.
The bill was first introduced in 2025 by Sen. Bill Cassidy, a physician and Republican from Louisiana who chairs the Senate Health, Education, Labor and Pensions Committee. Its goal is straightforward: push hospitals and health systems, particularly smaller and rural ones that often lack dedicated IT security staff, to adopt baseline cyber hygiene practices. Think of it as requiring every hospital to lock its doors and install smoke detectors rather than leaving that decision up to chance.
Those baseline practices include multifactor authentication, which requires more than just a password to access sensitive systems, and encryption of electronic protected health information, so that even if data is stolen it can't easily be read. The bill also calls on healthcare organizations to align with established cybersecurity frameworks, including the one developed by the National Institute of Standards and Technology, a widely used roadmap for organizations trying to manage digital risk.
Cassidy was joined by a notably diverse group of co-sponsors: Democratic Sens. Maggie Hassan of New Hampshire and Mark Warner of Virginia, Republican Sens. John Cornyn of Texas and Cindy Hyde-Smith of Mississippi, and independent Sen. Angus King of Maine. That cross-aisle, cross-region coalition suggests lawmakers see hospital cybersecurity less as a partisan fight and more as basic infrastructure protection, not unlike making sure bridges don't collapse.
Under the bill, the Department of Health and Human Services would require what it calls "private healthcare-related entities" to build out minimum cybersecurity capabilities. That includes penetration testing, essentially hiring ethical hackers to probe for weaknesses before criminals do, along with ongoing monitoring of networks for signs of intrusion.
The legislation also addresses what happens when things go wrong. It contains provisions for "mitigating penalties relating to violations of health information privacy and security," which could give some breathing room to organizations that are making good-faith efforts to comply but still fall victim to an attack. HHS would also be required to develop specific cybersecurity plans, updated every two years, laying out protocols the department itself must follow.
Money matters here, though the bill is light on specifics. It would provide funding, an amount not yet detailed, for training programs designed to grow the healthcare cybersecurity workforce and help organizations develop stronger practices. It would also create guidance tailored specifically to rural providers, who often operate with razor-thin budgets and little room for expensive security upgrades.

On the coordination side, the bill would designate a single point person within HHS to oversee and coordinate cybersecurity activities across the department. It also directs HHS to work more closely with the Cybersecurity and Infrastructure Security Agency, the federal government's lead civilian cyber defense agency, to share resources and build joint plans for responding to incidents when they occur. Think of it as making sure the fire department and the building inspector are finally talking to each other.
Cassidy has made health data privacy and security something of a signature issue. He previously co-sponsored the 2022 Health Data Use and Privacy Commission Act, and an updated version of that bill cleared the Senate HELP Committee on a unanimous vote this past August. The new cybersecurity act fits into that broader pattern of bipartisan effort, even if progress on comprehensive health privacy reform has been slow and incremental.
It's also worth noting that this bill doesn't exist in isolation. A separate piece of legislation, the Health Infrastructure Security and Accountability Act, has been advancing in recent weeks with a notably different philosophy. Where the Health Care Cybersecurity and Resilience Act leans on training, technical assistance and encouragement, especially for under-resourced providers, HISAA takes a tougher stance. It would impose tiered mandatory standards, require third-party audits, and potentially levy steep fines or Medicare payment reductions against larger organizations that fail to meet their obligations. HISAA does pair that stick with a substantial carrot too: $1.3 billion in funding, including $800 million earmarked specifically for hospitals in rural and underserved urban communities.
Together, the two bills represent something like a debate between two parenting styles, one focused on support and encouragement, the other on firm consequences. Which approach, or combination of approaches, ultimately proves more effective at getting hospitals to harden their defenses remains an open question.
Cassidy put the stakes plainly in a statement following the vote. "Cyberattacks can shut down hospitals and expose patients' private medical records," he said. "At a time when hostile actors are increasingly using sophisticated tactics to breach health care systems, the Health Care Cybersecurity and Resilience Act will help health care providers strengthen their defenses against cyber threats and protect patients' health data."
Hassan echoed that sentiment, emphasizing the particular vulnerability of rural communities. "This bipartisan legislation will help hospitals and health care providers, particularly those in rural communities with fewer resources, strengthen their cybersecurity and respond faster to attacks," she said. "I'm pleased to see that the Senate came together to pass this bill, and I'll keep working across the aisle to protect patients and strengthen our health care system."
For patients, the real-world consequences of hospital cyberattacks go well beyond inconvenience. Delayed surgeries, diverted ambulances and exposed medical records can translate directly into worse health outcomes and real harm. As this bill now moves toward further consideration, the question isn't just whether hospitals will comply with new standards, but whether the resources attached to those standards are enough to make compliance actually achievable, especially for the small and rural providers this legislation is meant to protect.
Tags
Original Sources
Senate passes bipartisan Health Care Cybersecurity and Resilience Act
↗ https://www.healthcareitnews.com/news/senate-passes-bipartisan-health-care-cybersecurity-and-resilience-act
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
7 October 2026
34 articles
Related Articles

The 2026 Nobel Prizes, and the Persistent Gap Science Still Hasn't Closed
Policy & Regulation · 5 min

Trump Declares Anyone Who Says "AI" Instead Of "Super Intelligence" An Enemy
Policy & Regulation · 5 min

Canada Commits $200 Million to Bring AI Out of the Lab and Into Atlantic Businesses
Policy & Regulation · 5 min
Related Articles

The 2026 Nobel Prizes, and the Persistent Gap Science Still Hasn't Closed
Policy & Regulation · 5 min

Trump Declares Anyone Who Says "AI" Instead Of "Super Intelligence" An Enemy
Policy & Regulation · 5 min

Canada Commits $200 Million to Bring AI Out of the Lab and Into Atlantic Businesses
Policy & Regulation · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.