S 3315: Health Care Cybersecurity and Resiliency Act of 2026
S 3315 in plain English: This bill expands federal requirements and resources for cybersecurity in the health care and public health sectors. It directs HHS to require private health care entities to adopt minimum cybersecurity practices, coordinates HHS with CISA to improve health care cybersecurity, and updates breach notification rules.
Stated purpose
This bill aims to strengthen cybersecurity in the health care and public health sectors by expanding federal requirements for minimum cybersecurity practices and improving coordination between the Department of Health and Human Services and the Cybersecurity and Infrastructure Security Agency in preventing and responding to cyber incidents.
Key points
- Requires private health care entities to adopt minimum cybersecurity practices, such as multifactor authentication
- HHS and CISA must establish a joint plan to coordinate responses to significant cybersecurity incidents
- HHS must provide cybersecurity guidance and training specifically tailored to rural health care entities
- Breach notifications must now include the number of individuals whose health information was affected
- HHS must designate one representative to lead oversight and coordination of cybersecurity activities
Arguments supporters make
- Major cyberattacks on hospitals and health systems have disrupted patient care, so requiring minimum security standards like multifactor authentication is a common-sense step to protect lives and sensitive data.
- Clearer rules about how good cybersecurity practices can reduce penalties gives health care organizations a real incentive to invest in better security without fear of being punished for trying.
- Coordinating HHS and CISA with a joint response plan ensures the federal government speaks with one voice during a health sector cyberattack, rather than agencies working at cross-purposes.
Arguments opponents make
- Imposing new federal cybersecurity mandates on health care providers, especially smaller clinics and rural hospitals already operating on thin margins, could create costly compliance burdens without proportional security gains.
- A one-size-fits-all minimum standard may give smaller or less sophisticated entities a false sense of security if they meet the floor but still lack the deeper protections needed against sophisticated attackers.
- Adding another layer of federal coordination between HHS and CISA risks creating bureaucratic overlap that slows response times during an actual crisis rather than speeding them up.
Tradeoffs
Stronger federal cybersecurity requirements may improve protection of patient data and health system operations, but they also place new compliance costs and administrative demands on health care providers, particularly smaller and rural organizations with fewer resources to absorb them.
Current status in Congress: Passed Senate.
NewsClear — neutral news & congressional tracking · Bill of the Week