The US House Energy and Commerce Committee's Subcommittee on Health held a legislative hearing on 15 September titled Examining Legislative Proposals to Reform Medicare Provider Payment and Bolster Health Care Cybersecurity, taking up two bills aimed at the sector's security problem β the Rural Hospital Cybersecurity Enhancement Act and the Healthcare Cybersecurity and Resiliency Act of 2026. The figures put before the subcommittee set out why: for five consecutive years more than 700 breaches affecting 500 or more individuals have been reported to HHS OCR, with a record 804 large breaches listed for 2025; as of 30 August 2026, 496 large breaches have been reported this year, putting 2026 on course for another 700-plus year, and more than 74.6 million individuals have had protected health information exposed so far, against 140.5 million last year. The composition of the problem is the argument for the bills: of this year's 496 large breaches, 426 β 86 per cent β are attributed to hacking and other IT incidents, and those account for 97.8 per cent of the individuals affected, which means the sector's exposure is almost entirely an information-security failure rather than a compliance-paperwork one. The hearing also frames the regulatory gap: a proposed update to the HIPAA Security Rule carrying new security requirements has been heavily criticised by industry groups, health systems and hospitals, and the final rule has been delayed until at least July 2027. That leaves a sector with a record breach year, an enforcement regime that reporting rates suggest is not producing compliance, and a replacement rule that will not arrive inside the current reporting cycle β the case the two bills are being written against.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-09-17 |
| Source | HIPAA Journal |
| Reliability | Tier 2 |