Senators Mark Warner and Ron Wyden reintroduced the Health Infrastructure Security and Accountability Act on 17 September, seeking to impose cybersecurity standards on the US healthcare system and make funding available for rural and underserved hospitals to invest in essential controls. The bill was first introduced on 25 September 2024 in the 118th Congress, when 394 hacking-related healthcare breaches had been reported to HHS OCR involving the protected health information of 43 million Americans. Two years on, OCR's breach portal lists 426 hacking-related breaches for 1 January to 31 August 2026, involving 73 million individuals — an 8 per cent increase in breach count and a 70 per cent increase in affected individuals. The senators' argument is unchanged: attacks delay patient care and the losses stem from lax practices by providers and their business partners. OCR published voluntary cybersecurity performance goals for the sector in January 2024, which as the agency predicted proved insufficient on their own.
| Attribute | Detail |
|---|---|
| Sector | Legal Services |
| Date | 2026-09-19 |
| Source | HIPAA Journal |
| Reliability | Tier 2 |