Skip to content
Brief Security & Trust ·

US Senate passes bill to strengthen healthcare cybersecurity

The Health Care Cybersecurity and Resilience Act cleared the Senate by unanimous consent and now goes to the House.

In brief
  • The Senate passed the Health Care Cybersecurity and Resilience Act by unanimous consent, per SecurityWeek. The House must still act.
  • SecurityWeek calls the Act in effect a new compliance requirement. Who pays for it is left open.

SecurityWeek reported on 5 October that the US Senate passed the Health Care Cybersecurity and Resilience Act by unanimous consent. It first appeared in 2024, lapsed, and returned in December 2025. The bill would fund grants and training, support rural clinics, and tighten coordination between HHS and CISA, the US cyber defence agency. It would also require an HHS incident response plan and make ASPR the lead sector risk agency.

The bill now goes to the House. SecurityWeek gives no vote date, grant amounts or compliance deadlines. It names ransomware with double extortion as the main weapon against healthcare: attackers lock systems, steal data, and threaten to leak it. Some now only steal. The sector is caught between government advice not to pay and the need to protect patients. SecurityWeek counts over 730 breaches in the year before its article, reaching over 270 million Americans, at about $10 million each. Those figures describe the problem, not the bill's effect.

SecurityWeek's writer calls the Act in effect a new compliance requirement. Industry voices say success depends on consistent enforcement and on funding and technical help keeping pace. Healthcare budget signers, and the vendors serving them, should ask who pays for compliance, what ASPR as lead agency changes, and how tailored CISA threat intelligence would feed their incident response.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: SecurityWeek.