Skip to main content
S. 3315 Senate Health

Health Care Cybersecurity and Resiliency Act of 2025

Introduced
Dec 2, 2025
Sponsor
Sen. Cassidy, Bill (R-LA)
View on Congress.gov (opens in a new tab)

STAGE 3 OF 8 — CALENDARS AND SCHEDULING

Currently in the Senate. Last action: placed on senate legislative calendar under general orders. calendar no. 365 on Mar 23, 2026.

  1. Senate Introduced in Senate Dec 2, 2025
  2. Senate Read twice and referred to the Committee on Health, Education, Labor, and Pensions. Dec 2, 2025
  3. Senate Committee on Health, Education, Labor, and Pensions. Ordered to be reported with an amendment in the nature of a substitute favorably. Feb 26, 2026
  4. Senate Committee on Health, Education, Labor, and Pensions. Reported by Senator Cassidy with an amendment in the nature of a substitute. Without written report. Mar 23, 2026
  5. Senate Placed on Senate Legislative Calendar under General Orders. Calendar No. 365. Mar 23, 2026

Cosponsors

3

Subjects

Administrative law and regulatory proceduresComputer security and identity theftComputers and information technologyCongressional oversightDepartment of Health and Human ServicesEmployment and training programsGovernment information and archivesGovernment studies and investigationsHealth programs administration and fundingPublic-private cooperationRural conditions and development

Committees

  • Health, Education, Labor, and Pensions Committee
    • [Reported By, Mar 23, 2026]
    • [Markup By, Feb 26, 2026]
    • [Referred To, Dec 2, 2025]

Summary

Health Care Cybersecurity and Resiliency Act of 2026This bill expands federal requirements and resources for preventing and responding to cybersecurity incidents in the health care and public health sectors.The bill directs the Department of Health and Human Services (HHS) to require private health care-related entities to adopt minimum cybersecurity practices (e.g., multifactor authentication),more specifically identify the standards for mitigating penalties relating to violations of health information privacy and security,expand and update biennially a specified plan that details cybersecurity protocols for HHS personnel,provide training and best practices to support the expansion of the workforce for health care cybersecurity, provide guidance on cybersecurity readiness to rural entities, anddesignate one representative to lead oversight and coordination of cybersecurity activities within HHS.Also, HHS and the Cybersecurity and Infrastructure Security Agency (CISA) must coordinate to improve health care cybersecurity, including by (1) providing resources for entities receiving information from HHS or CISA programs, and (2) establishing a joint cybersecurity capability plan to coordinate responses to significant incidents.Additionally, the bill requires health care providers and plans to include the number of individuals affected when notifying individuals of unauthorized access to health information (i.e., a breach). 

[Summary as of: Reported to Senate]

Comments · 0

Loading...

Loading comments...