VYPR
advisoryPublished Oct 7, 2026· 1 source

Senate Passes Healthcare Cybersecurity Bill Following Change Healthcare Breach

The U.S. Senate has unanimously passed the Health Care Cybersecurity and Resiliency Act of 2026, aiming to strengthen federal cybersecurity standards for healthcare organizations in the wake of the massive Change Healthcare breach.

The U.S. Senate has passed the Health Care Cybersecurity and Resiliency Act of 2026, a legislative measure introduced in response to the devastating ransomware attack on Change Healthcare that exposed the sensitive health information of approximately 190 million individuals. The bill, which advanced through unanimous consent, is poised to significantly expand federal cybersecurity requirements for entities operating within the healthcare sector.

The newly passed legislation mandates that the Department of Health and Human Services (HHS) implement several key initiatives. These include requiring all private healthcare-related entities to adopt minimum cybersecurity standards, such as multi-factor authentication. Additionally, the bill calls for the expansion and biennial updating of a plan detailing cybersecurity protocols for HHS personnel, the provision of training and best practices to bolster the healthcare cybersecurity workforce, and the delivery of guidance on cybersecurity readiness specifically tailored for rural healthcare entities. A designated representative within HHS will also be appointed to lead oversight and coordination of cybersecurity activities.

Furthermore, the Health Care Cybersecurity and Resiliency Act directs HHS to collaborate with the Cybersecurity and Infrastructure Security Agency (CISA) to disseminate crucial cybersecurity information to healthcare entities. This partnership will also focus on creating a joint cyber plan to ensure coordinated responses to significant cybersecurity incidents. A notable provision requires healthcare companies to disclose the total number of data breach victims when notifying individuals about unauthorized access to their health information.

The bill garnered bipartisan support, with Senator Bill Cassidy (R-LA) leading the effort alongside Senators Maggie Hassan (D-NH), Mark Warner (D-VA), and Angus King (I-ME). Senator Cassidy emphasized the critical need for enhanced defenses, stating, "Cyberattacks can shut down hospitals and expose patients' private medical records. At a time when hostile actors are increasingly using sophisticated tactics to breach health care systems, the Health Care Cybersecurity and Resilience Act will help health care providers strengthen their defenses against cyber threats and protect patients’ health data."

The American Hospital Association (AHA), representing nearly 5,000 hospitals and health systems, has endorsed the bill, particularly praising its inclusion of grant funding to support the adoption of cybersecurity measures. However, the AHA has also called for greater clarity on whether the new regulations will extend to third-party vendors, noting that many recent breaches have targeted these service providers.

Recent months have seen a spate of high-profile data breaches impacting healthcare technology providers, affecting millions of patient records. Examples include a breach at healthcare data company Aesto that exposed sensitive information for over 9.5 million people, a breach at Baylor Genetics impacting more than 2.8 million individuals, and another incident involving electronic health records giant CareCloud that affected 3.7 million people.

Senator Mark Warner highlighted the life-or-death implications of cyberattacks on healthcare systems, stating, "Cyberattacks on our health care systems can have life-or-death consequences for patients and put the sensitive information of millions of Americans at risk." He urged the House of Representatives to act swiftly on the legislation, emphasizing its role in strengthening defenses and providing essential tools for rural providers.

The passage of this bill signifies a growing recognition of the critical need for robust cybersecurity within the healthcare sector, driven by the increasing frequency and severity of cyber threats and the profound impact of incidents like the Change Healthcare breach on patient data and healthcare operations.

Synthesized by Vypr AI