S 3315: Health Care Cybersecurity and Resiliency Act of 2026

S 3315 in plain English: This bill expands federal requirements and resources for cybersecurity in the health care and public health sectors. It directs HHS to require private health care entities to adopt minimum cybersecurity practices, coordinates HHS with CISA to improve health care cybersecurity, and updates breach notification rules.

Stated purpose

This bill aims to strengthen cybersecurity in the health care and public health sectors by expanding federal requirements for minimum cybersecurity practices and improving coordination between the Department of Health and Human Services and the Cybersecurity and Infrastructure Security Agency in preventing and responding to cyber incidents.

Key points

Arguments supporters make

Arguments opponents make

Tradeoffs

Stronger federal cybersecurity requirements may improve protection of patient data and health system operations, but they also place new compliance costs and administrative demands on health care providers, particularly smaller and rural organizations with fewer resources to absorb them.

Current status in Congress: Passed Senate.

NewsClear — neutral news & congressional tracking · Bill of the Week