
US Senate Advances Bills to Strengthen Healthcare Cybersecurity Measures
TL/DR –
Healthcare organizations in the U.S. face an increasing number of cybersecurity challenges, leading to the reintroduction of the Health Infrastructure Security and Accountability Act (HISAA) and the advancement of the Health Care Cybersecurity and Resiliency Act (HCCRA) by the Senate. The HISAA stipulates the creation of minimum and enhanced security standards, mandatory risk assessments and business continuity planning, independent audits, new tiered civil monetary penalties, and allocated funding for implementation. The HCCRA would revise the HIPAA Security Rule, mandate minimum risk-based cybersecurity practices, implement a “safe harbor” provision, establish a federal grant program for certain healthcare organizations, and provide training on cybersecurity risks and mitigation strategies.
Cybersecurity Legislation Advances in Health Care Industry
In an environment of growing cybersecurity threats, healthcare organizations find themselves challenged. The Health Infrastructure Security and Accountability Act (HISAA) has been re-introduced and the Health Care Cybersecurity and Resiliency Act (HCCRA) has advanced in the U.S. Senate in response to major security breaches affecting the industry. The key provisions of these bills are outlined below.
HISAA: An Overview
September 2026 witnessed Senators Mark Warner (D-Virginia) and Ron Wyden (D-Oregon) reintroducing HISAA, based on the comprehensive cybersecurity legislation they initially proposed in 2024. The bill mirrors the original with exact provisions. More details about the previous HISAA bill can be found here.
HISAA: Key Elements
HISAA overhaul the existing HIPAA Security Rule and includes new requirements such as mandatory minimum cybersecurity standards, risk assessments, business continuity planning, and independent audits. Furthermore, the bill enforces varied penalties for compliance failure and allocates funds to assist healthcare organizations in meeting these standards. Details on each of these elements can be found in the original article.
HCCRA: An Update
The HCCRA was initially proposed in 2025 after the catastrophic Change Healthcare ransomware attack, which revealed the industry’s vulnerabilities to sophisticated cyber threats. The U.S. Senate unanimously passed the bill in October 2026 and it now awaits consideration in the House of Representatives. More background on this bill can be found here.
HCCRA: Highlights
HCCRA aims to modify the HIPAA Security Rule, creating new requirements for covered entities and business associates. These include mandatory cybersecurity standards and practices, a ‘safe harbor’ provision, a federal grant program for cybersecurity practices, and measures to train and support the cybersecurity workforce. Details on each of these elements can be found in the original article.
Consequences for Healthcare Organizations
While these bills still need to cross additional legislative barriers before becoming law, the strong bipartisan support suggests new cybersecurity obligations for healthcare organizations are likely on the horizon. HCCRA and HISAA represent significant legislative efforts to revamp health care cybersecurity, potentially introducing the most substantial changes to HIPAA since the HITECH Act in 2009. Despite some overlap with the proposed changes to HIPAA Security Rule regulations in 2025, the finalization of which remains uncertain. Further updates will be provided as the legislative process progresses.
—
Read More Health & Wellness News ; US News