S 5443: Health Infrastructure Security and Accountability Act of 2026
S 5443 in plain English: This bill would strengthen cybersecurity requirements for healthcare entities, increasing penalties for violations and providing federal funding to help hospitals and other providers adopt cybersecurity practices. It sets new civil and criminal penalties for noncompliance and allocates hundreds of millions of dollars in incentive payments through Medicare.
Stated purpose
The bill aims to strengthen cybersecurity standards for health information by increasing oversight and compliance requirements for health care entities, and to provide Medicare-based support to hospitals dealing with cyberattacks.
Key points
- Imposes civil penalties of up to $5,000 per day for cybersecurity compliance failures
- Creates felony criminal penalties of up to $1,000,000 fine or 10 years imprisonment for serious violations
- Provides $800,000,000 to help healthcare providers adopt essential cybersecurity practices
- Provides $500,000,000 to help providers adopt enhanced cybersecurity practices
- Appropriates $40,000,000 for fiscal year 2027 and $15,000,000 per year for fiscal years 2029–2033 for implementation
Arguments supporters make
- Major cyberattacks on health systems have disrupted patient care and exposed sensitive data, so stronger, regularly updated security rules are overdue.
- Tiered requirements mean the largest and most critical health organizations face stricter standards, targeting oversight where the risk is greatest.
- Medicare payment support and a safe-practices program give hospitals real financial tools to recover from attacks and invest in prevention without shutting down care.
Arguments opponents make
- Smaller providers and rural hospitals may struggle to afford compliance with new mandated standards and user fees on top of existing financial pressures.
- Giving the Secretary broad, unreviewable authority to classify which entities face the toughest requirements removes normal checks and could be applied inconsistently or unfairly.
- Adding another layer of federal cybersecurity mandates on top of existing HIPAA rules may create duplicative burdens without guaranteeing better real-world security outcomes.
Tradeoffs
Stronger cybersecurity protections and oversight come at the cost of higher compliance burdens and fees on health care organizations, which could strain smaller or less-resourced providers even as larger systems gain clearer federal guidance. The bill also trades judicial and administrative review of certain agency decisions for faster, more flexible government action on emerging cyber threats.
Current status in Congress: In committee.
NewsClear — neutral news & congressional tracking · Bill of the Week