Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The U.S. Senate passed the Health Care Cybersecurity and Resiliency Act by unanimous consent on October 2, 2026. The measure would help health care organizations prevent and respond to cyberattacks, while directing future updates to federal health-data security rules. It is not law: the Falls Church News-Press reported that it was sent to the House, where it must pass before it can go to the President.

What the Senate passed—and what happens next

The Senate passed the measure by unanimous consent, rather than in a recorded roll-call vote, according to Senator Mark Warner’s October 2 announcement. Warner, Bill Cassidy, Maggie Hassan, and John Cornyn announced the passage. The Falls Church News-Press reported that the bill was sent to the House for consideration (Falls Church News-Press report).

Senate passage is one step in the legislative process, not enactment. The House must pass the measure before it can be sent to the President. The sources available for this article establish no subsequent House action, so its status here is the status reported after the Senate vote: Senate-passed legislation awaiting House consideration.

What the act proposes

The sponsors’ summary and linked draft bill text describe a package of grants, training, coordination, guidance, reporting changes, and proposed regulatory updates. These are provisions the bill would authorize or direct; passage in the Senate does not put them into effect.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Grants and practical support

The draft gives HHS discretion to award grants to eligible entities. Potential applicants include certain public or nonprofit health centers, Indian Health Service facilities, hospitals, cancer centers, rural health clinics, academic health centers, and certain nonprofit partners. The proposed uses include hiring and training staff, upgrading electronic systems, joining threat-sharing organizations, reducing reliance on legacy systems, and obtaining third-party assistance.

The bill does not guarantee an award to every eligible organization. Its text leaves HHS discretion over grant awards, and it does not establish that funding is currently available.

Training and rural-provider guidance

The measure would provide cybersecurity training and offer rural providers best-practice guidance. The aim is to help health organizations strengthen prevention and response, including providers that may have fewer resources for specialized security work.

HHS–CISA coordination and incident response

The draft would require the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA) to coordinate and share health-sector resources and threat information. It also assigns HHS cybersecurity oversight responsibilities and calls for an HHS incident-response plan covering risk assessment, prevention, detection, damage reduction, data protection, and recovery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Breach reporting and proposed HIPAA rule updates

The bill would update the public breach-reporting portal and breach-reporting practices. It also directs HHS to update HIPAA privacy, security, and breach-notification regulations. The draft specifically calls for multifactor authentication, safeguards to encrypt protected health information, and audits that include penetration testing. It leaves room for the Secretary of HHS to set other minimum standards.

These are proposed future regulatory requirements, not security rules that became operative when the Senate passed the bill. The linked bill text is a draft with an unfilled bill number and introductory placeholders, rather than enacted or final statutory text (linked bill text).

How this differs from Warner and Wyden’s separate proposal

The Health Care Cybersecurity and Resiliency Act is not the same measure as the Health Infrastructure Security and Accountability Act. Warner and Ron Wyden reintroduced the latter on September 17, 2026. That separate proposal is described by its sponsors as establishing minimum standards and includes its own audit and funding provisions. Those details should not be attributed to the Senate-passed act.

Measure Sponsors identified in the sources Status in the cited coverage Policy approach
Health Care Cybersecurity and Resiliency Act Mark Warner, Bill Cassidy, Maggie Hassan, and John Cornyn Passed the Senate by unanimous consent on October 2, 2026; sent to the House, according to the Falls Church News-Press report Combines proposed grants and training with HHS–CISA coordination, rural guidance, reporting changes, and future HIPAA-related regulatory updates.
Health Infrastructure Security and Accountability Act Mark Warner and Ron Wyden Reintroduced September 17, 2026; the cited source does not establish Senate passage A distinct proposal described by its sponsors as establishing minimum standards, with separate audit and funding provisions.

The September 17 announcement of the Warner–Wyden proposal concerns that separate bill, not the measure that cleared the Senate on October 2.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the proposal is focused on health care

Warner’s office said in a December 4, 2025 release that more than 730 cyber breaches affected over 270 million Americans “last year,” and that more than 190 million people’s data was exposed in the Change Healthcare attack. These figures are claims attributed to the senator’s office and retain its stated time framing; they are not independently verified here (Warner’s December 4, 2025 release).

In the October 2 release, Warner said cyberattacks can have life-or-death consequences for patients and put sensitive information at risk. Cassidy warned that attacks can shut down hospitals and expose medical records; Cornyn said patients deserve confidence that their data is protected. These are statements from the bill’s sponsors, not independent assessments of the proposal’s likely effects.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.