The United States Senate has unanimously passed the bipartisan Health Care Cybersecurity and Resilience Act, marking a pivotal step towards bolstering the protection of patient data within the healthcare industry. Introduced by Senators Bill Cassidy, Maggie Hassan, Jon Cornyn, and Mark Warner, the legislation aims to enhance cybersecurity measures across the healthcare sector.
Legislation Reintroduced for Stronger Cyber Defenses
Originally introduced in 2024, the bill had previously failed to pass but was successfully reintroduced in December 2025. It now proceeds to the US House of Representatives for further consideration. Senator Cassidy emphasized the urgency of this measure, highlighting the potential risks cyberattacks pose to patient health data and care delivery.
Cybercriminals have increasingly targeted the healthcare industry, with over 730 breaches reported last year affecting more than 270 million Americans. These incidents cost, on average, $10 million per breach, underscoring the dire need for stronger defenses.
High-Profile Cyber Incidents underscore Risks
The healthcare sector has experienced several significant cyberattacks, such as the massive Anthem breach in 2015, which compromised the data of 78.8 million individuals and resulted in a $115 million loss. Ransomware attacks, like those on Ascension and Change Healthcare in 2024, have disrupted services and exposed sensitive information of millions, further driving the need for robust cybersecurity legislation.
Ransomware remains a dominant threat, often forcing healthcare providers to choose between paying ransoms or risking patient safety. The new legislation seeks to enhance resilience and provide guidance to mitigate such threats.
Key Provisions and Industry Reactions
The Act proposes grants for cybersecurity improvements, training programs, and better coordination between the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA). It also mandates updates to cybersecurity practices and requires the HHS Secretary to implement a comprehensive incident response plan.
While the healthcare sector generally supports the Act, experts caution that its success largely depends on consistent enforcement and sufficient funding. Concerns about the financial burden of compliance persist, especially if federal support does not align with regulatory demands.
In conclusion, the Health Care Cybersecurity and Resilience Act represents a significant legislative effort to safeguard the healthcare sector from cyber threats. As it awaits approval from the House of Representatives, the focus remains on ensuring effective implementation and support for this critical initiative.
