Legislation Reintroduced to Strengthen Healthcare Cybersecurity
Legislation has been reintroduced by two Democratic senators to strengthen healthcare cybersecurity. The Health Infrastructure Security and Accountability Act was first introduced in 2024 following the cyberattack on Change Healthcare, which caused massive disruption across the United States and resulted in the theft of the protected health information of an estimated 192.7 million Americans.
The legislation, reintroduced by Senators Ron Wyden (D-OR) and Mark Warner (D-VA), calls for higher security standards in healthcare, requiring the Department of Health and Human Services (HHS) to adopt mandatory minimum security standards for HIPAA-covered entities and their business associates, and enhanced cybersecurity requirements for covered entities of systemic importance or importance to national security – Change Healthcare, for example.
The HHS’ Office for Civil Rights (OCR) has already proposed stronger cybersecurity standards in an update to the HIPAA Security Rule; however, a final rule has been delayed until at least July 2027. The proposed Security Rule update attracted strong criticism, and no decision has been made about whether a final rule will be issued. Several industry groups and health systems have called for the final rule to be scrapped.
One of the main criticisms was the cost of implementing the proposed cybersecurity requirements, especially for rural health systems and underserved hospitals that do not have the available funds to make the necessary cybersecurity improvements. That sticking point is addressed by the Health Infrastructure Security and Accountability Act, which calls for $1.3 billion in funding to be provided to incentivize hospitals to improve security. A significant proportion of the funding will be provided to rural and underserved hospitals to allow them to make the necessary cybersecurity improvements.
In 2024, when the bill was introduced, 741 large data breaches had been reported to OCR, the majority of which were hacking incidents. Large data breaches and hacking incidents especially have continued to increase, and last year, 804 large data breaches were reported to OCR – a new record. More than 500 large data breaches have already been reported to OCR this year, and almost 75 million individuals have been affected.
The HHS introduced voluntary cybersecurity performance goals in 2024 – essential and enhanced – to improve healthcare cybersecurity; however, voluntary goals alone are not sufficient to drive the necessary behavioural change across the sector. Legislation is required to force HIPAA-regulated entities to adopt stronger cybersecurity measures to make the healthcare system much more resilient. “Congress cannot wait to act until another catastrophic cyberattack compromises the safety and privacy of American families’ most personal information,” said Sen. Wyden.
Two other healthcare cybersecurity bills are being considered by Congress, such as the Rural Hospital Cybersecurity Enhancement Act and the Health Care Cybersecurity and Resiliency Act of 2026, both of which were discussed at a House Energy and Commerce subcommittee hearing this month.
