The bill strengthens federal coordination, planning, and sector‑specific support to make healthcare cybersecurity more resilient, but it relies largely on guidance rather than guaranteed funding—raising compliance costs, potential privacy and legal risks, and uncertainty about effective implementation for smaller providers and taxpayers.
Hospitals, health systems, and state/local coordinators will get clearer federal prioritization, defined roles, and coordinated support for healthcare cybersecurity, enabling focused federal attention and resources on high‑risk health infrastructure.
Hospitals, clinics, and healthcare IT teams will benefit from improved threat information sharing and a designated cybersecurity liaison, which should speed detection and incident response across the sector.
Owners/operators (including rural and small/medium facilities) will receive sector‑specific plans, tailored recommendations, and training guidance to strengthen resilience of EHRs, medical devices, and operational systems.
Hospitals, clinics, and healthcare vendors—particularly small and rural providers—could face substantial new compliance and administrative costs from broader definitions, asset listings, training, and expectations tied to prioritized cybersecurity measures.
Many requirements (plans, training, liaison, prioritized support) lack assured funding or enforceable resources, so effectiveness may be limited and costs may shift to providers or require future appropriations from taxpayers.
Sharing cyber threat indicators and publicly managing an asset priority list could create privacy, liability, or reputational risks for healthcare organizations and raise public concern about medical data security.
Based on analysis of 9 sections of legislative text.
Directs CISA and HHS to coordinate, train, update a sector risk plan, create criteria/list for high‑risk healthcare assets, and report to Congress—without authorizing new funding.
Official title: To enhance the cybersecurity of the Healthcare and Public Health Sector.
Introduced June 9, 2025 by Jason Crow · Last progress June 9, 2025
Requires federal cybersecurity coordination, planning, training, reporting, and targeted risk management for the Healthcare and Public Health Sector. It directs CISA and HHS to appoint a dedicated cybersecurity liaison, update a sector risk-management plan, provide sector-focused training, create objective criteria and a biannual list of "high-risk covered assets," and deliver several briefings and reports to Congress. The Act emphasizes information sharing, resource prioritization for high-risk assets, workforce assessment and support for rural and small/medium providers, and clarifies it does not authorize new surveillance or additional appropriations.