← My Government dashboard

Government Watch

Mentioned 1× · first seen 09-jul-2026 · last seen 09-jul-2026

Health Care Cybersecurity and Resiliency Act of 2026

Current understanding

The Health Care Cybersecurity and Resiliency Act of 2026 would direct HHS to establish minimum cybersecurity practices for private health care entities and coordinate incident response with CISA. It would also expand breach notification requirements — notably requiring disclosure of the number of affected individuals — layering new obligations on top of the existing HIPAA/HITECH breach notification framework. As introduced, the bill has not advanced beyond initial referral.

Evidence log

  • 2026-03-23 — Health Care Cybersecurity and Resiliency Act of 2026: cross-connection with health-location-data-protection: Both target health data protection but from different angles: cybersecurity minimum standards and breach notification versus substantive collection/use restrictions. (novelty: 3)

Open questions

Related

Contributing findings

Legislative introduced
Health Care Cybersecurity and Resiliency Act of 2026
23-mar-2026 novelty 3 per-area 3 introduces

Ask about this page

Replies are grounded in this page's wiki content and the findings linked above. Citations to findings render as [F123] links.

Stages other doctrine resolution introduced proposed rule passed chamber executive action final rule enacted district opinion circuit opinion opinion

build build 392 · ea9c128-dirty · 2026-08-09