The U.S. Senate passed a healthcare cybersecurity bill that was introduced in the wake of the ransomware attack on Change Healthcare, which exposed the sensitive healthcare information of 190 million people. The Health Care Cybersecurity and Resiliency Act of 2026 was passed by unanimous consent last week, potentially expanding federal cyber requirements for healthcare organizations. The bill orders the Department of Health and Human Services (HHS) to: The bill also orders HHS to work with the Cybersecurity and Infrastructure Security Agency (CISA) to provide cybersecurity information for healthcare entities and create a joint cyber plan to coordinate responses to significant incidents. Healthcare companies will also be forced to include the total number of data breach victims when notifying people about unauthorized access to their health information. The bill was introduced by Senator Bill Cassidy (R-LA) but had bipartisan backing from Sens. Maggie Hassan (D-NH), Mark Warner (D-VA) and Angus King (I-ME). “Cyberattacks can shut down hospitals and expose patients' private medical records,” Cassidy said. “At a time when hostile actors are increasingly using sophisticated tactics to breach health care systems, the Health Care Cybersecurity and Resilience Act will help health care providers strengthen their defenses against cyber threats and protect patients’ health data.” It also had the backing of the American Hospital Association (AHA), which lauded the bill for including grant funding to support the adoption of cybersecurity measures. The AHA — which represents nearly 5,000 hospitals, health systems and other healthcare organizations — noted that it wants more clarity on whether the rules will extend to third-party vendors. “Most protected health information (PHI) data breaches reported to the Office of Civil Rights resulted from hacking incidents targeting non-hospital healthcare providers, including third-party service and software providers,” AHA said. The organization cited several recent examples, the most notable of which was the Change Healthcare incident which snarled the U.S. healthcare system for months and exposed troves of healthcare data for 190 million Americans. “We believe third parties handling health information should be held to the same privacy and security standards as covered entities and business associates,” the AHA added. In recent months there have been dozens of high-profile data breaches involving healthcare technology providers that exposed millions of records. Healthcare data company Aesto informed federal regulators last month that more than 9.5 million people had sensitive information leaked during a cyberattack at the end of 2025. Baylor Genetics had a breach that impacted more than 2.8 million people and another 3.7 million people were impacted by a March cybersecurity incident involving electronic health records giant CareCloud. Republican and Democratic leaders in the House did not respond to requests for comment about the bill. “Cyberattacks on our health care systems can have life-or-death consequences for patients and put the sensitive information of millions of Americans at risk,” Warner said in a statement. “I’m proud to have helped pass this critical legislation through the Senate, and I urge the House to act quickly. This bill will strengthen our cybersecurity, better protect patients and their information, and give rural health care providers in Virginia and across the country additional tools to defend against cyber threats.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.