Health Care Cybersecurity and Resiliency Act of 2026
Current understanding
Legislation would require HHS to establish mandatory minimum cybersecurity practices for private health care entities, formalize HHS coordination with CISA on incident response, and expand HIPAA/HITECH breach notification requirements to include the number of affected individuals. The bill builds on existing HIPAA/HITECH and CISA authorities but shifts the healthcare sector from largely voluntary cybersecurity guidance toward enforceable federal minimums. Status: introduced.
Evidence log
- 2026-07-23 — To require the development of a comprehensive rural hospital cybersecurity workforce development strategy, and for other purposes.: cross-connection with rural-hospital-cybersecurity-workforce: Both address healthcare-sector cybersecurity capacity; the rural workforce strategy complements broader HHS cybersecurity resiliency efforts by targeting the workforce pipeline for underserved facilities. (novelty: 3)