If you run a small clinic, the bill the Senate just passed creates cybersecurity grants with no money attached. The security requirements are already spelled out: encryption, a second login step, and regular testing of your systems, and as written they would apply to every practice HIPAA covers.
The bill is the Health Care Cybersecurity and Resiliency Act (S.3315), which the U.S. Senate passed by unanimous consent on September 30, 2026.
What the Senate passed
The bill authorizes federal grants for cybersecurity at under-resourced providers and directs the Department of Health and Human Services (HHS) to tighten the cybersecurity rules under the Health Insurance Portability and Accountability Act (HIPAA). It now goes to the House of Representatives.
Senator Maggie Hassan (D-NH), one of the senators behind the bill, said in the Senate HELP Committee announcement that the bill "will help hospitals and health care providers, particularly those in rural communities with fewer resources, strengthen their cybersecurity and respond faster to attacks."
What the bill would ask providers to do
The requirements would bind every covered entity and business associate under HIPAA, whether or not they receive a grant. Section 8 of the bill as the Senate passed it directs HHS to update the HIPAA Security Rule so that covered entities and business associates adopt minimum cybersecurity practices, including:
- Multifactor authentication (MFA), meaning a second login step such as a code sent to your phone
- Encryption of protected health information (PHI)
- Monitoring, including penetration testing, where someone tries to break into your systems on purpose to find weak spots
- Other minimum standards drawn from national frameworks such as the NIST Cybersecurity Framework
Those rules would take effect 36 months after the bill becomes law, and HHS could use enforcement discretion for organizations facing "extraordinary circumstances." The HIPAA Journal's summary of the Senate-passed bill lists the same encryption, multifactor authentication, monitoring, and penetration testing requirements.
Section 7 also has HHS write rules on how "recognized security practices" count when it sets fines after a violation. If you can show what you had in place, that record could be weighed in your favor.
The bill arrives while a separate route to similar rules has stalled: the HHS Office for Civil Rights (OCR) proposed its own HIPAA Security Rule update with extensive cybersecurity requirements, and the final rule has been pushed back to at least July 2027, with no decision on whether it will be published.
Treat the bill's list as a preview of where federal expectations are heading, whichever route gets there first.
The bill sets aside no money
The Senate-passed bill lets HHS award grants but includes no line authorizing money for them. An earlier committee version authorized "such sums as may be necessary" for fiscal years 2026 through 2030, and that line is gone from the text the Senate passed. The HIPAA Journal notes that the House and Senate Appropriations Committees would decide how much is made available.
The grant list is also narrower than the requirement list: as written, eligible applicants are federally qualified health centers, Indian Health Service facilities, nonprofit hospitals, rural health clinics as Medicare defines them, and nonprofits that partner with or coordinate referrals with those organizations.
A privately owned dental, chiropractic, or physical therapy office is not on that list. The encryption and MFA requirements in Section 8 would still apply to it.
For providers who do qualify, grants would run up to three years and could pay for hiring and training staff, outside contractors, risk assessments, and incident response plans. Applicants would need to show baseline measures and a plan to keep the work going after the grant ends.
SecurityWeek reported concerns from the security industry about "the financial strain of compliance if federal funding or technical assistance fails to keep pace with the regulatory requirements." Plan your budget as if no grant money reaches you this fiscal year.
Small practices are the least ready for these requirements
Paubox's survey of healthcare organizations with fewer than 250 employees, published in What small healthcare practices get wrong about HIPAA and email security, found that 34% lack internal IT support and 33% say they don't have enough time for compliance tasks.
The same survey found that 98% of small practices say their platform encrypts email by default. Only half have phishing or spoofing protection beyond their platform's default settings, and 20% have no email archiving or record of what was sent.
The report cites Agape Health, a North Carolina federally qualified health center, which paid $25,000 to OCR after emailing PHI unencrypted to the wrong recipient.
Rural providers face the same gaps with less room to absorb them. In Paubox's report Rural Healthcare Left Vulnerable to Cyber Attacks, 73% of rural healthcare leaders said they struggle to maintain HIPAA compliance because they lack staff and funding, and half named budget as a top barrier to adopting HIPAA compliant email, nearly double the rate of their urban peers.
What you can do before any money arrives
The controls named in Section 8 are things you can check now, without waiting for a grant or a final rule.
Check whether your email is encrypted by default
When you send a patient's records to a referral partner, do you do anything different from sending a regular email? If encryption depends on someone remembering a keyword or clicking a button, a busy front desk will sometimes miss it.
HIPAA compliant email encrypts every message automatically, with no keyword or button.
Turn on a second login step for every email account
Check that multifactor authentication is on for every account in your practice, including shared inboxes and the account someone set up years ago and nobody uses daily.
Ask your vendors what they cover
Your email provider, billing service, and electronic health record (EHR) vendor all handle patient information for you. Do you have a signed business associate agreement (BAA) with each one, and do you know what it says about security and breach notice?
Go deeper: The importance of reviewing your BAA
Write down who you would call
Incident response plans are one of the things the grants would fund, and you can write a short one today: who to call, which accounts to lock, and how to reach patients if email goes down.
What to watch next
Before any of this reaches your practice, the House has to pass the bill, and Congress would still have to fund the grants. Separately, OCR still has to decide on its own Security Rule update.
Of the bill's requirements, encryption on every email and a second login step on every account are the two a small practice can check this month.
Paubox Email Suite encrypts every outbound email by default and works with Google Workspace and Microsoft 365, so recipients read encrypted email directly in their inbox with no portal or password.
Related: What the new cybersecurity standards mean for healthcare budgets
