The US Senate passed the Health Care Cybersecurity and Resiliency Act of 2026 by unanimous consent, introduced in the wake of the Change Healthcare ransomware attack that ultimately exposed the sensitive healthcare information of 190 million people. The bill orders HHS to require private healthcare-related entities to adopt minimum cybersecurity standards such as multifactor authentication, update its cybersecurity protocols plan biennially, expand workforce training, issue readiness guidance for rural entities and designate a single cybersecurity oversight lead within HHS. HHS must also work with CISA on information sharing and a joint incident-response plan, and notification to breach victims must state the total number affected. Introduced by Senator Bill Cassidy with bipartisan backing from Hassan, Warner and King, the bill has American Hospital Association support — though the AHA wants clarity on whether rules extend to third-party vendors, citing that most PHI breaches reported to OCR stem from hacking incidents at non-hospital providers. House action is pending.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-10-08 |
| Source | The Record |
| Reliability | Tier 2 |