YourVoice.Now Summary
Civil LibertiesTransparency & AccountabilityCorporate BenefitsWorkers & JobsWould make hospitals and insurers encrypt your medical records within three years, with grants for rural clinics.
Civil Liberties
New federal rules would make hospitals, insurers, and their vendors encrypt patient records and use two-step login. Regular testing for weak spots would also be required. The rules would start three years after the bill becomes law.
HHS would expand its own emergency plan for cyberattacks. The plan covers the systems and data HHS holds. It would be reviewed every two years and after any major attack.
Transparency & Accountability
When a hospital or insurer tells you your health data was exposed, the notice would have to say how many people were hit. That count is not required today.
HHS would send Congress a yearly report on the top cyber threats to health care and the major attacks of the past year. The first one is due a year after the bill becomes law.
HHS would have to account for each audit or fine where it gave credit for a company's security work. This yearly accounting starts two years after the bill becomes law.
Corporate Benefits
HHS would write rules on how a company's security work can cut fines or end an audit early. Money spent on security would count. The rules are due within one year.
Workers & Jobs
HHS and CISA would train health care staff to spot and stop cyberattacks. HHS would also write a plan to grow the health cybersecurity workforce, including steps for rural sites.
More about this bill
Your medical records would get new federal security rules. Hospitals, insurers, and the vendors they hire would have to encrypt patient data. They would also need two-step login and regular security testing. The rules would take effect three years after the bill becomes law. Breach notices would change too. When your health data is exposed, the notice would have to say how many people were affected. Safety-net providers could get federal grants to pay for this work. Community health centers, rural clinics, Indian Health Service sites, and nonprofit hospitals could apply. Grants would last up to three years. They could fund new staff, training, and system upgrades. No dollar amount is set. The money is approved through 2030. Rural providers would also get federal guidance and hands-on help. A federal plan would aim to grow the health cyber workforce. The Department of Health and Human Services (HHS) would run most of this work. HHS and the Cybersecurity and Infrastructure Security Agency (CISA) would build a joint response plan within one year. HHS would name one official to lead its cyber work. That official would not handle HIPAA enforcement. HHS would report to Congress each year on threats and major attacks. New rules would spell out how strong security steps can lower fines. HHS would also list every case where those steps changed a fine or audit. A federal-state group would study how to cut duplicate breach reports.
Congressional Summary
Health Care Cybersecurity and Resiliency Act of 2026This bill expands federal requirements and resources for preventing and responding to cybersecurity incidents in the health care and public health sectors.The bill directs the Department of Health and Human Services (HHS) to require private health care-related entities to adopt minimum cybersecurity practices (e.g., multifactor authentication),more specifically identify the standards for mitigating penalties relating to violations of health information privacy and security,expand and update biennially a specified plan that details cybersecurity protocols for HHS personnel,provide training and best practices to support the expansion of the workforce for health care cybersecurity, provide guidance on cybersecurity readiness to rural entities, anddesignate one representative to lead oversight and coordination of cybersecurity activities within HHS.Also, HHS and the Cybersecurity and Infrastructure Security Agency (CISA) must coordinate to improve health care cybersecurity, including by (1) providing resources for entities receiving information from HHS or CISA programs, and (2) establishing a joint cybersecurity capability plan to coordinate responses to significant incidents.Additionally, the bill requires health care providers and plans to include the number of individuals affected when notifying individuals of unauthorized access to health information (i.e., a breach).
Legislative Subjects
Details
- Congress
- 119th
- Chamber
- Senate
- Status
- summarized
- Action
- Reported to Senate
- Action Date
- 2026-03-23
- Date Added
- 2026-07-08
- Source
- Congress.gov →
Like reading a bill in plain English?
We're building an app that does this for every bill in Congress and lets you tell your reps how you want them to vote. We're a small team getting ready to launch, and we're trying to show investors that real people want this. Be one of them. Help us get it built. Leave your email and we'll tell you the moment the app is ready.