Healthcare Cybersecurity and Resiliency
Current understanding
Federal policy on cybersecurity standards for private health care entities, breach notification, and coordination between HHS and CISA on incident response. Builds on existing HIPAA/HITECH Security Rule requirements. The Health Care Cybersecurity and Resiliency Act of 2026 (introduced) would direct HHS to establish minimum cybersecurity practices, coordinate with CISA on incident response, and expand breach notification requirements to include the number of affected individuals.
Evidence log
- 2026-08-04 — Health Information Privacy Reform Act: cross-connection with health-information-privacy-reform-act: Both address federal treatment of protected health information; privacy reform could interact with cybersecurity/resiliency obligations for covered entities. (novelty: 2)
- 2026-07-23 — To require the development of a comprehensive rural hospital cybersecurity workforce development strategy, and for other purposes.: cross-connection with healthcare-workforce: HR9908 links clinician/IT workforce pipeline policy to healthcare cybersecurity resiliency by mandating a dedicated rural hospital cyber workforce strategy. (novelty: 3)