The measure pairs enforceable minimum standards with $1.3 billion in federal payments, and the hospital industry has opposed similar mandates before.

 

What happened

Senators Mark Warner, a Virginia Democrat and vice chairman of the Select Committee on Intelligence, and Ron Wyden, an Oregon Democrat and ranking member of the budget committee, reintroduced the Health Infrastructure Security and Accountability Act on September 17, 2026, Fierce Healthcare reported. The bill would require the Department of Health and Human Services to adopt minimum cybersecurity standards for covered entities and their business associates within two years, with tighter requirements for organizations judged to be of systemic or national security importance. Within three years, covered entities would have to conduct and document a security risk analysis and formally attest that they comply. It largely repeats a bill the same senators introduced in September 2024, which did not advance.

 

Going deeper

Attestation is what gives the standards teeth. Under the bill text, organizations would document their risk analysis and certify compliance to HHS, with civil penalties attached to noncompliance and separate consequences for executives who certify falsely. Covered entities would also need plans for responding to cyber incidents, natural disasters, and technology failures, along with stress tests measuring whether they can restore main functions, and independent security audits. A user fee would fund the oversight, charged to each covered entity and business associate as a share of national health expenditures, capped at the lesser of the estimated cost of enforcement or $40 million in the 2026 fiscal year and $50 million in 2027, rising with inflation thereafter.

 

What was said

"As cybercriminals ramp up their attacks on hospitals and health care providers, it's becoming increasingly clear that voluntary standards are not enough to protect Americans' health, safety and privacy," Warner said in the announcement, quoted by Fierce Healthcare. Wyden framed the timing in the same release: "Congress cannot wait to act until another catastrophic cyberattack compromises the safety and privacy of American families' most personal information."

 

In the know

Money arrives before the penalties under the bill's structure. The first $800 million would go out as upfront payments over two years to 2,000 rural and urban safety net hospitals adopting needed cybersecurity standards, according to the Senate Finance Committee's section-by-section summary. A further $500 million would become available afterward to Medicare hospitals adopting enhanced practices, and hospitals that have not adopted them by the end of that period would face a payment penalty. Sequencing matters for smaller organizations, since the hospitals least able to fund the work receive support first and the incentive payments for everyone else follow.

 

The big picture

Hospital groups have resisted mandatory standards before, with more than 100 provider organizations asking HHS to withdraw its proposed HIPAA Security Rule update, and the industry has generally argued that any mandate needs substantial funding attached. Some healthcare groups criticized the penalty structure in the 2024 version of this bill, which is largely unchanged. The regulatory route has slowed in parallel, with the Security Rule overhaul pushed back to July 2027. Fierce Healthcare reports that little federal healthcare legislation is expected to pass before December given the appropriations calendar and midterm elections, and that legislation from the current Congress has generally reduced healthcare funding rather than added it. Compliance teams reading the bill will recognize most of its requirements, since risk analysis, incident response planning, and independent audit already appear in existing guidance, and what changes is whether an organization has to attest to them in writing.

 

FAQs

What does attestation add that current rules do not require?

The Security Rule already requires a risk analysis, though nothing compels an organization to certify to HHS that it has one. Attestation creates a dated record an enforcement body can check, and false certification carries consequences distinct from the underlying security failure.

 

What is a cybersecurity stress test?

An exercise testing whether an organization can restore main functions within a defined period after a disruption, rather than checking whether controls exist. Financial regulators have used the approach for years, and the bill would apply the concept to healthcare operations.

 

Who would pay the user fee?

Covered entities and business associates, each charged a share proportional to its part of national health expenditures, so larger organizations would pay more. The total is capped, and the fee would fund HHS oversight and enforcement rather than general spending.

 

How does this bill relate to the HIPAA Security Rule update?

They are separate routes to similar ends. The Security Rule update is a regulation HHS can finalize on its own authority, currently targeted for July 2027, while this bill would create statutory requirements and attach funding. Neither depends on the other advancing.