YourVoice.Now
Back to Dashboard
S-3315Senate2026-03-23Health

Health Care Cybersecurity and Resiliency Act of 2026

YourVoice.Now Summary

Civil LibertiesTransparency & AccountabilityCorporate BenefitsWorkers & Jobs

Would make hospitals and insurers encrypt your medical records within three years, with grants for rural clinics.

Civil Liberties

Encryption and two-step login — required for medical records within 3 years

New federal rules would make hospitals, insurers, and their vendors encrypt patient records and use two-step login. Regular testing for weak spots would also be required. The rules would start three years after the bill becomes law.

HHS plan to protect patient data — updated at least every 2 years

HHS would expand its own emergency plan for cyberattacks. The plan covers the systems and data HHS holds. It would be reviewed every two years and after any major attack.

Transparency & Accountability

Health breach letters — must state how many people were affected

When a hospital or insurer tells you your health data was exposed, the notice would have to say how many people were hit. That count is not required today.

Yearly report on health system hacks — due to Congress within 1 year

HHS would send Congress a yearly report on the top cyber threats to health care and the major attacks of the past year. The first one is due a year after the bill becomes law.

Fine decisions reported yearly — every case where security practices counted

HHS would have to account for each audit or fine where it gave credit for a company's security work. This yearly accounting starts two years after the bill becomes law.

Corporate Benefits

Lower HIPAA fines for health companies — when security practices are in place

HHS would write rules on how a company's security work can cut fines or end an audit early. Money spent on security would count. The rules are due within one year.

Workers & Jobs

Cyber training for health workers — federal plan due within 1 year

HHS and CISA would train health care staff to spot and stop cyberattacks. HHS would also write a plan to grow the health cybersecurity workforce, including steps for rural sites.

More about this bill

Your medical records would get new federal security rules. Hospitals, insurers, and the vendors they hire would have to encrypt patient data. They would also need two-step login and regular security testing. The rules would take effect three years after the bill becomes law. Breach notices would change too. When your health data is exposed, the notice would have to say how many people were affected. Safety-net providers could get federal grants to pay for this work. Community health centers, rural clinics, Indian Health Service sites, and nonprofit hospitals could apply. Grants would last up to three years. They could fund new staff, training, and system upgrades. No dollar amount is set. The money is approved through 2030. Rural providers would also get federal guidance and hands-on help. A federal plan would aim to grow the health cyber workforce. The Department of Health and Human Services (HHS) would run most of this work. HHS and the Cybersecurity and Infrastructure Security Agency (CISA) would build a joint response plan within one year. HHS would name one official to lead its cyber work. That official would not handle HIPAA enforcement. HHS would report to Congress each year on threats and major attacks. New rules would spell out how strong security steps can lower fines. HHS would also list every case where those steps changed a fine or audit. A federal-state group would study how to cut duplicate breach reports.

Congressional Summary

Health Care Cybersecurity and Resiliency Act of 2026This bill expands federal requirements and resources for preventing and responding to cybersecurity incidents in the health care and public health sectors.The bill directs the Department of Health and Human Services (HHS) to require private health care-related entities to adopt minimum cybersecurity practices (e.g., multifactor authentication),more specifically identify the standards for mitigating penalties relating to violations of health information privacy and security,expand and update biennially a specified plan that details cybersecurity protocols for HHS personnel,provide training and best practices to support the expansion of the workforce for health care cybersecurity, provide guidance on cybersecurity readiness to rural entities, anddesignate one representative to lead oversight and coordination of cybersecurity activities within HHS.Also, HHS and the Cybersecurity and Infrastructure Security Agency (CISA) must coordinate to improve health care cybersecurity, including by (1) providing resources for entities receiving information from HHS or CISA programs, and (2) establishing a joint cybersecurity capability plan to coordinate responses to significant incidents.Additionally, the bill requires health care providers and plans to include the number of individuals affected when notifying individuals of unauthorized access to health information (i.e., a breach).

Legislative Subjects

Administrative law and regulatory proceduresComputer security and identity theftComputers and information technologyCongressional oversightDepartment of Health and Human ServicesEmployment and training programsGovernment information and archivesGovernment studies and investigationsHealth programs administration and fundingPublic-private cooperationRural conditions and development

Details

Congress
119th
Chamber
Senate
Status
summarized
Action
Reported to Senate
Action Date
2026-03-23
Date Added
2026-07-08
Source
Congress.gov →

Like reading a bill in plain English?

We're building an app that does this for every bill in Congress and lets you tell your reps how you want them to vote. We're a small team getting ready to launch, and we're trying to show investors that real people want this. Be one of them. Help us get it built. Leave your email and we'll tell you the moment the app is ready.

By default, we'll only email you once — when the app launches. Unless you opt in below, you won't receive anything else. We don't share or sell your email.