Healthcare organizations face unprecedented cybersecurity challenges in an increasingly hostile threat environment.
In response to major breaches and security incidents affecting the industry, the Health Infrastructure Security and Accountability Act (HISAA) has been re-introduced and the U.S. Senate has advanced the Health Care Cybersecurity and Resiliency Act (HCCRA). This blog post summarizes the key provisions of these bills.
Health Infrastructure Security and Accountability Act
Overview and Reintroduction
In September 2026, Senators Mark Warner (D-Virginia) and Ron Wyden (D-Oregon) reintroduced HISAA, building on comprehensive cybersecurity legislation they first proposed in 2024. The reintroduced bill contains substantially identical provisions to the original version.
EBG previously provided a detailed overview of the prior HISAA bill and its key requirements here.
Key Provisions
The reintroduced HISAA bill retains all of the substantive provisions of the original version, which would substantially overhaul the existing HIPAA Security Rule. Key provisions include:
Mandatory Minimum Cybersecurity Standards
- The bill would require the U.S. Department of Health and Human Services (HHS) to develop and maintain both minimum security standards applicable to all HIPAA covered entities and business associates and enhanced security standards applicable to certain entities determined by HHS to be of systematic importance to national security. Both sets of standards would be updated at least every two years and would address cybersecurity risks including ransomware and other threats.
Risk Assessments and Business Continuity Planning
- Covered entities and business associates would be required to conduct annual cybersecurity risk assessments documenting their exposure to risks and establishing recovery plans for natural disasters, disruptive cyber incidents, and other technological failures. Entities would also be expected to conduct stress tests to evaluate their capability to recover essential functions following a cyber event.
Independent Audits
- Covered entities and business associates would be required to contract with independent auditors to assess their compliance with HHS-established security requirements on an annual basis. Entities subject to enhanced security standards would be required to submit the audit findings to HHS.
Enforcement and Penalties
- New tiered civil monetary penalties would be established for failure to comply with the minimum or enhanced security requirements and, unlike current HIPAA penalties, the new penalties would not be subject to statutory maximums. Additionally, failure to meet the audit and reporting obligations would result in civil monetary penalties of up to $5,000 per day, and criminal penalties would apply to entities knowingly submitting false information.
Fees and Funding
- Recognizing the cost of implementing new security standards, particularly for smaller and rural entities, the bill would allocate $1.3 billion to assist healthcare organizations. Specifically, $800 million would go to rural and urban safety-net hospitals over two years, with an additional $500 million available to incentivize all hospitals to adopt enhanced cybersecurity practices. However, each covered entity and business associate would be required to pay annual fees established by HHS to support data security and oversight activities.
Health Care Cybersecurity and Resiliency Act of 2026
Overview and Status
HCCRA was initially proposed in 2025 in direct response to the catastrophic Change Healthcare ransomware attack, which disrupted healthcare operations nationwide and exposed the industry's vulnerabilities to sophisticated cyber threats. On October 1, 2026, the U.S. Senate passed the bill unanimously. The legislation now proceeds to the House of Representatives for consideration.
EBG has previously provided additional background on this bill and the broader regulatory landscape surrounding healthcare cybersecurity here.
Key Provisions
HCCRA would significantly modify the HIPAA Security Rule and create extensive new requirements for covered entities and business associates, as follows:
Mandatory Cybersecurity Standards and Practices
- The bill would mandate that the HIPAA Security Rule be updated to require HIPAA covered entities and business associates to adopt minimum risk-based cybersecurity practices, including (1) multifactor authentication, (2) encryption of protected health information, (3) penetration testing, and (4) other cybersecurity standards as reflected in national cybersecurity frameworks.
Safe Harbor Provision for Recognized Security Practices
- The bill would require HHS to promulgate regulations, within one year after enactment of the bill, to implement the "safe harbor" for recognized security practices enacted as part of the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2021. The safe harbor would reduce penalties in the event of violations, audits, or cybersecurity incidents for entities that have maintained recognized security practices for at least 12 months prior to the triggering event.
Cybersecurity Grant Program
- The bill would establish a federal grant program to assist nonprofit hospitals, federally qualified health centers, rural health clinics, and Indian Health Service facilities. A recipient of such a grant would be required to use the funds for certain cybersecurity practices including: (1) hiring and training cybersecurity personnel, (2) updating electronic data systems, (3) conducting security risk assessments, and (4) developing or improving cybersecurity incident response plans.
Training and Supporting Cybersecurity Workforce
- The bill provides that HHS would provide training to the healthcare sector on cybersecurity risks and ways to mitigate such risks. In addition, HHS, in coordination with the Health Resources and Services Administration, would be required to develop a strategic plan to support growing the cybersecurity workforce of health care entities, including: (1) development of training programs and educational materials; (2) development of best practices to train the health care cybersecurity workforce; (3) development of best practices to leverage artificial intelligence to support cybersecurity preparedness; and (4) alignment with the National Initiative for Cybersecurity Education Workforce Framework.
Implications for Health Care Organizations
Although both bills must clear additional legislative hurdles before becoming law, the overwhelming bipartisan support for health care cybersecurity reform suggests that significant new cybersecurity obligations are likely coming.
HCCRA represents one of the most substantial legislative efforts to overhaul health care cybersecurity, and HISAA would be the most significant revision to HIPAA since the HITECH Act in 2009. While some of the provisions in each of these bills are similar to requirements contained in the changes to the HIPAA Security Rule regulations proposed in 2025, that proposed rule has been delayed and finalization remains uncertain.
We will continue to monitor the progress of both bills through the legislative process and will provide updates as developments occur. Please contact us if you would like to discuss the implications of this legislation for your organization or need assistance to assess your cybersecurity compliance posture.
* * * *
If you have questions, please reach out to the author(s).
The Health Law Advisor blog is currently edited by Emily Chi Fogler.
Authors
- Member of the Firm