Health Care Cybersecurity and Resiliency Act of 2026
Latest action (Oct 5, 2026) — Held at the desk.
What it does
Congressional Research Service, Mar 23, 2026This bill expands federal requirements and resources for preventing and responding to cybersecurity incidents in the health care and public health sectors.
The bill directs the Department of Health and Human Services (HHS) to
require private health care-related entities to adopt minimum cybersecurity practices (e.g., multifactor authentication),more specifically identify the standards for mitigating penalties relating to violations of health information privacy and security,expand and update biennially a specified plan that details cybersecurity protocols for HHS personnel,provide training and best practices to support the expansion of the workforce for health care cybersecurity, provide guidance on cybersecurity readiness to rural entities, anddesignate one representative to lead oversight and coordination of cybersecurity activities within HHS.Also, HHS and the Cybersecurity and Infrastructure Security Agency (CISA) must coordinate to improve health care cybersecurity, including by (1) providing resources for entities receiving information from HHS or CISA programs, and (2) establishing a joint cybersecurity capability plan to coordinate responses to significant incidents.
Additionally, the bill requires health care providers and plans to include the number of individuals affected when notifying individuals of unauthorized access to health information (i.e., a breach).
Face Value
as reported to the SenateHow much of this bill its name accounts for.
- Every bill starts at100
- Length−1
26 sections, against 20 before length counts against a bill.
Face Value measures reach, not honesty. A big bill can be accurately named, and a low score is not an accusation — it means the contents reach further than any short title could describe. Count it yourself ↗ How this is worked out
Discussion
4 commentsSign in to join the discussion and put your vote on the record.