Sen. Cassidy Leads Bipartisan Bill to Mandate Cybersecurity Standards for Hospitals and Clinics
Health Care Cybersecurity and Resiliency Act of 2026
The Health Care Cybersecurity and Resiliency Act of 2026 has been approved by the Senate committee and is now waiting for a vote by the full Senate. It is currently placed on the legislative calendar and is actively moving through the process.
This bill’s path across every version that has carried it.
Scores run from -100 (strongly harmful) to +100 (strongly beneficial) for each group, combining impact, certainty, scope, and duration ratings of 1-5. How impact scoring works
Small healthcare practices like independent physician offices and small clinics will face new mandatory cybersecurity requirements including multi-factor authentication, encryption, and penetration testing. While these protections improve security, the compliance costs could be significant for small operations. The grant program may help some, but eligibility is limited to nonprofits, FQHCs, and rural clinics.
Placed on Senate Legislative Calendar under General Orders. Calendar No. 365.
The bill is now on the schedule for the full chamber to consider. It's in line for debate and a vote.
Committee on Health, Education, Labor, and Pensions. Reported by Senator Cassidy with an amendment in the nature of a substitute. Without written report.
The committee approved this bill and is sending it to the full chamber for a vote. This is a significant step — most bills never get this far.
Committee on Health, Education, Labor, and Pensions. Ordered to be reported with an amendment in the nature of a substitute favorably.
The committee approved this bill and is sending it to the full chamber for a vote. This is a significant step — most bills never get this far.
Read twice and referred to the Committee on Health, Education, Labor, and Pensions.
Sent to a congressional committee for expert review. The committee decides whether this bill moves forward.
Introduced in Senate
The bill was officially filed and given a number. It now enters the legislative queue.
The Senate HELP Committee advanced the Health Care Cybersecurity and Resiliency Act, which requires publishing cybersecurity guidance for rural medical practices and improved coordination between federal agencies. The bill also proposes grants for under-resourced practices to improve defenses.
The bill seeks to introduce new cybersecurity requirements including multifactor authentication, data encryption, and regular security audits. It would provide financial assistance to under-resourced providers, including hospitals, cancer centers, and rural health clinics.
The Health Care Cybersecurity and Resiliency Act would revamp HHS cybersecurity measures, mandating a comprehensive incident response plan and coordination with CISA. Legislators cited the 2024 Change Healthcare breach as the primary catalyst for the bill.
No votes or related bills recorded for this bill yet.
Document Type
Congressional Bill
Official Title
Health Care Cybersecurity and Resiliency Act of 2026
Analysis generated by AI. Always verify with official sources.