Official title: Require the Secretary of Health and Human Services and the Director of the Cybersecurity and Infrastructure Security Agency to coordinate to improve cybersecurity in the health care and public health sectors, and for other purposes.
Introduced December 2, 2025 by Bill Cassidy · Last progress December 2, 2025
The bill strengthens health‑sector cybersecurity—reducing breach risk, improving coordination, and funding technical support—at the cost of new federal spending, significant compliance burdens (especially for small and rural providers), and some privacy/vendor‑risk tradeoffs that will require careful implementation and sustained funding to avoid capacity gaps.
Patients and people who depend on healthcare services will face a lower risk of data breaches and fewer care interruptions because hospitals and clinics must adopt stronger protections (grants, HHS plans, MFA/encryption, monitoring, coordinated info‑sharing, recovery protocols).
Hospitals, health systems, and clinical providers will gain funding, technical assistance, and clearer federal coordination to modernize IT, improve incident response, and reduce downtime from cyberattacks.
Rural, tribal, and other smaller community providers will receive targeted guidance, technical help, and recommended low‑cost options (shared IT, part‑time CISO, workforce programs) to strengthen cyber defenses and reduce urban/rural protection gaps.
Small, rural, and resource‑constrained providers will face significant upfront and ongoing compliance costs and staffing strains (MFA, encryption, monitoring, penetration testing, reporting, documented security practices), risking diversion of resources from patient care and potential closures.
Taxpayers and federal budgets could face materially higher spending because the bill authorizes open‑ended appropriations and creates new recurring HHS/CISA program costs (grants, training, reporting, coordination).
Grant funding is time‑limited (typically up to 3 years), so providers may face sustainability gaps and difficulty retaining cybersecurity staff or maintaining services after federal support ends.
Based on analysis of 12 sections of legislative text.
Establishes grants, training, coordination, and new HIPAA/HHS cybersecurity regulations to strengthen health‑sector cybersecurity and streamline incident reporting.
Provides grants, training, regulatory updates, and interagency coordination to improve cybersecurity in the health and public health sector. It funds multi‑year grants for eligible providers, directs HHS and CISA to plan and coordinate incident response and information sharing, requires new HHS regulations and updates to HIPAA Security Rule implementation, and creates reporting and rural assistance requirements. Requires HHS to develop workforce and technical assistance programs, convene a multi‑agency working group to reduce duplicative reporting, add breach-notification details, and publish guidance and a joint capability plan; authorizes appropriations for grants for FY2026–FY2030 and sets multiple implementation deadlines (mostly 1–3 years).