S 3315 United States Senate · 119th Congress

Health Care Cybersecurity and Resiliency Act of 2026

The Health Care Cybersecurity and Resiliency Act of 2025 requires the Department of Health and Human Services (HHS) to develop a cybersecurity incident response plan within one year, including strategies for risk assessment, prevention, detection, and recovery. It mandates new cybersecurity standards for healthcare entities, such as multifactor authentication for systems holding protected health information, encryption requirements, and mandatory audit protocols. The bill also updates breach reporting rules to require public disclosure of corrective actions and security practices considered during investigations, while creating grants to help rural healthcare providers adopt cybersecurity best practices. Additionally, it establishes training programs for healthcare cybersecurity staff and requires HHS to issue guidance on recognizing security practices that may reduce fines for covered entities. These provisions directly affect hospitals, clinics, and health organizations handling protected health information.
Bill status in committee 1 of 4 stages cleared
Introduction
Dec 2025
Committee Review
Floor Vote
President
Introduced Dec 2, 2025 Last action Mar 23, 2026
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
5
Key actions
2
Committee
3
Mar 23, 2026
Upper · Passed
Committee on Health, Education, Labor, and Pensions. Reported by Senator Cassidy with an amendment in the nature of a substitute. Without written report.
upper
Feb 26, 2026
Upper · Passed
Committee on Health, Education, Labor, and Pensions. Ordered to be reported with an amendment in the nature of a substitute favorably.
upper
Dec 2, 2025
Committee
Read twice and referred to the Committee on Health, Education, Labor, and Pensions.
upper
Dec 2, 2025
Introduced
Introduced in Senate
upper
1 primary · 3 co-sponsors

Sponsors