Healthcare organizations face unprecedented cybersecurity challenges in an increasingly hostile threat environment.

In response to major breaches and security incidents affecting the industry, the Health Infrastructure Security and Accountability Act (HISAA) has been re-introduced and the U.S. Senate has advanced the Health Care Cybersecurity and Resiliency Act (HCCRA). This blog post summarizes the key provisions of these bills.

Health Infrastructure Security and Accountability Act

Overview and Reintroduction

In September 2026, Senators Mark Warner (D-Virginia) and Ron Wyden (D-Oregon) reintroduced HISAA, building on comprehensive cybersecurity legislation they first proposed in 2024. The reintroduced bill contains substantially identical provisions to the original version.

EBG previously provided a detailed overview of the prior HISAA bill and its key requirements here.

Key Provisions

The reintroduced HISAA bill retains all of the substantive provisions of the original version, which would substantially overhaul the existing HIPAA Security Rule.  Key provisions include:

Mandatory Minimum Cybersecurity Standards

  • The bill would require the U.S. Department of Health and Human Services (HHS) to develop and maintain both minimum security standards applicable to all HIPAA covered entities and business associates and enhanced security standards applicable to certain entities determined by HHS to be of systematic importance to national security. Both sets of standards would be updated at least every two years and would address cybersecurity risks including ransomware and other threats.

Risk Assessments and Business Continuity Planning

  • Covered entities and business associates would be required to conduct annual cybersecurity risk assessments documenting their exposure to risks and establishing recovery plans for natural disasters, disruptive cyber incidents, and other technological failures. Entities would also be expected to conduct stress tests to evaluate their capability to recover essential functions following a cyber event.

Independent Audits

  • Covered entities and business associates would be required to contract with independent auditors to assess their compliance with HHS-established security requirements on an annual basis. Entities subject to enhanced security standards would be required to submit the audit findings to HHS.

Enforcement and Penalties

  • New tiered civil monetary penalties would be established for failure to comply with the minimum or enhanced security requirements and, unlike current HIPAA penalties, the new penalties would not be subject to statutory maximums.  Additionally, failure to meet the audit and reporting obligations would result in civil monetary penalties of up to $5,000 per day, and criminal penalties would apply to entities knowingly submitting false information.

Fees and Funding

  • Recognizing the cost of implementing new security standards, particularly for smaller and rural entities, the bill would allocate $1.3 billion to assist healthcare organizations. Specifically, $800 million would go to rural and urban safety-net hospitals over two years, with an additional $500 million available to incentivize all hospitals to adopt enhanced cybersecurity practices.  However, each covered entity and business associate would be required to pay annual fees established by HHS to support data security and oversight activities.  

Health Care Cybersecurity and Resiliency Act of 2026

Overview and Status

HCCRA was initially proposed in 2025 in direct response to the catastrophic Change Healthcare ransomware attack, which disrupted healthcare operations nationwide and exposed the industry's vulnerabilities to sophisticated cyber threats. On October 1, 2026, the U.S. Senate passed the bill unanimously.  The legislation now proceeds to the House of Representatives for consideration.

EBG has previously provided additional background on this bill and the broader regulatory landscape surrounding healthcare cybersecurity here.

Key Provisions

HCCRA would significantly modify the HIPAA Security Rule and create extensive new requirements for covered entities and business associates, as follows:     

Mandatory Cybersecurity Standards and Practices

  • The bill would mandate that the HIPAA Security Rule be updated to require HIPAA covered entities and business associates to adopt minimum risk-based cybersecurity practices, including (1) multifactor authentication, (2) encryption of protected health information, (3) penetration testing, and (4) other cybersecurity standards as reflected in national cybersecurity frameworks.

Safe Harbor Provision for Recognized Security Practices

  • The bill would require HHS to promulgate regulations, within one year after enactment of the bill, to implement the "safe harbor" for recognized security practices enacted as part of the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2021. The safe harbor would reduce penalties in the event of violations, audits, or cybersecurity incidents for entities that have maintained recognized security practices for at least 12 months prior to the triggering event.

Cybersecurity Grant Program

  • The bill would establish a federal grant program to assist nonprofit hospitals, federally qualified health centers, rural health clinics, and Indian Health Service facilities. A recipient of such a grant would be required to use the funds for certain cybersecurity practices including:  (1) hiring and training cybersecurity personnel, (2) updating electronic data systems, (3) conducting security risk assessments, and (4) developing or improving cybersecurity incident response plans. 

Training and Supporting Cybersecurity Workforce

  • The bill provides that HHS would provide training to the healthcare sector on cybersecurity risks and ways to mitigate such risks. In addition, HHS, in coordination with the Health Resources and Services Administration, would be required to develop a strategic plan to support growing the cybersecurity workforce of health care entities, including:  (1) development of training programs and educational materials; (2) development of best practices to train the health care cybersecurity workforce; (3) development of best practices to leverage artificial intelligence to support cybersecurity preparedness; and (4) alignment with the National Initiative for Cybersecurity Education Workforce Framework.

Implications for Health Care Organizations

Although both bills must clear additional legislative hurdles before becoming law, the overwhelming bipartisan support for health care cybersecurity reform suggests that significant new cybersecurity obligations are likely coming.  

HCCRA represents one of the most substantial legislative efforts to overhaul health care cybersecurity, and HISAA would be the most significant revision to HIPAA since the HITECH Act in 2009.  While some of the provisions in each of these bills are similar to requirements contained in the changes to the HIPAA Security Rule regulations proposed in 2025, that proposed rule has been delayed and finalization remains uncertain.    

We will continue to monitor the progress of both bills through the legislative process and will provide updates as developments occur. Please contact us if you would like to discuss the implications of this legislation for your organization or need assistance to assess your cybersecurity compliance posture.

* * * *

If you have questions, please reach out to the author(s).

The Health Law Advisor blog is currently edited by Emily Chi Fogler.

Back to Health Law Advisor Blog

Search This Blog

Authors

Related Services

Topics

Archives

Jump to Page

Subscribe

Sign up to receive an email notification when new Health Law Advisor posts are published:

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.