The US Senate passed the bipartisan Health Care Cybersecurity and Resilience Act by unanimous consent, and the bill now heads to the House of Representatives.

 

What happened

Senators Bill Cassidy, Maggie Hassan, Jon Cornyn, and Mark Warner introduced the bill, and the Senate passed it by unanimous consent. The House of Representatives will consider it next. The Act aims to help healthcare reduce the number of successful criminal attacks and improve its resilience against ransomware.

 

Going deeper

The Act includes several provisions:

  • Grants to improve cyberattack prevention and response, plus training in best cybersecurity practices
  • Improved support for rural health clinics
  • Better coordination between HHS and CISA to improve responses to cyberattacks
  • Updates to current regulations so they reflect the best cybersecurity practices
  • A requirement that the HHS Secretary develop and implement a cybersecurity incident response plan

The Act also tries to provide central cybersecurity guidance across the existing frameworks. It formally establishes the Administration for Strategic Preparedness and Response (ASPR) as the clear Sector Risk Management Agency and provides a way for CISA to provide tailored, actionable threat intelligence.

 

What was said

Senator Cassidy said, "Cyberattacks on our healthcare sector not only put patients' sensitive health data at risk but can delay life-saving care."

Senator Cornyn said, "This legislation would strengthen interagency coordination and improve security practices for rural providers, ensuring Texans' health care is not delayed or compromised by cyberattacks."

 

By the numbers

  • More than 730 cyber breaches affected over 270 million Americans last year.
  • Each breach cost an average of $10 million.
  • The 2015 Anthem breach compromised the personal information and health records of 78.8 million customers and cost more than $115 million.
  • The 2024 ransomware attack on Ascension disrupted clinical operations and electronic health records across 11 US states.

 

Why it matters

Attackers bet that hospitals will pay rather than risk patients' health, so the bill puts resources behind prevention and response instead. It also directs help to rural health clinics and builds a way for CISA to share threat intelligence with the sector.

The Act also adds a new compliance requirement for healthcare. The regulation works only if both parties deliver: the government must provide funding and technical assistance, and healthcare organizations must comply. If federal support falls behind the requirements, the financial strain could fall on providers.

 

The bottom line

Healthcare organizations should follow the bill's progress and begin assessing how new compliance requirements could affect their security practices and budgets.

 

FAQs

What is a Sector Risk Management Agency?

It is the federal agency responsible for coordinating security and resilience efforts for a specific critical infrastructure sector, such as healthcare.

 

What does passing by unanimous consent mean?

It means no senator objected, so the Senate approved the bill without a formal roll-call vote.

 

What happens after the Senate passes a bill?

The House must also pass the same bill, and then the president must sign it before it becomes law.

 

Why are rural health clinics more vulnerable to cyberattacks?

Rural clinics often have smaller budgets and fewer IT and security staff than large health systems.