Health Care Cybersecurity and Resiliency Act of 2026
Current understanding
The Health Care Cybersecurity and Resiliency Act of 2026 would direct HHS to establish minimum cybersecurity practices for private health care entities and coordinate incident response with CISA. It would also expand breach notification requirements — notably requiring disclosure of the number of affected individuals — layering new obligations on top of the existing HIPAA/HITECH breach notification framework. As introduced, the bill has not advanced beyond initial referral.
Evidence log
- 2026-03-23 — Health Care Cybersecurity and Resiliency Act of 2026: cross-connection with health-location-data-protection: Both target health data protection but from different angles: cybersecurity minimum standards and breach notification versus substantive collection/use restrictions. (novelty: 3)