Requires CISA and HHS to coordinate healthcare cybersecurity, appoint a liaison, provide sector training, update a Risk Management Plan, and allow designation of high‑risk healthcare assets.
Official title: Enhance the cybersecurity of the Healthcare and Public Health Sector.
Introduced May 21, 2025 by Jacklyn Sheryl Rosen · Last progress May 21, 2025
The bill strengthens federal coordination, tailored threat intelligence, and sector-specific guidance to better protect patient care and privacy from cyberattacks, but it risks imposing costs and administrative burdens on smaller providers and agencies, may expose sensitive information if not tightly controlled, and lacks guaranteed new funding to ensure equitable implementation.
Hospitals, clinics, and health systems get clearer federal roles, definitions, and a coordinated Sector Risk Management Plan so they can work with CISA, HHS, and state coordinators more effectively to prepare for and respond to cyber threats.
Hospitals and health systems receive tailored cyber threat indicators, a qualified liaison, and prioritized resources that speed detection and incident response, reducing disruptions to patient care and operations.
Patients — including millions with chronic conditions — stand to have stronger privacy and data protection as improved defenses, information sharing, and reduced breaches lower risks of identity theft and medical-record misuse.
Small, rural, and resource-constrained hospitals and clinics may face significant new compliance, reporting, and upgrade costs to meet statutory definitions, prioritized controls, and expectations — straining budgets and potentially diverting funds from patient care.
The Act specifies no new appropriations and contains limits on funding signals, which could force agencies to reallocate existing resources or delay implementation and the delivery of promised support to providers.
New reporting, inventories, liaison staffing, and product development create administrative burdens for federal agencies and the Comptroller General that could divert staff time from active operational cyber defense.
Based on analysis of 9 sections of legislative text.
Requires CISA and HHS to coordinate on improving cybersecurity across the Healthcare and Public Health Sector. Creates a CISA liaison to HHS, requires updates to a sector Risk Management Plan, authorizes HHS to identify high‑risk healthcare assets, mandates CISA training for owners/operators, and directs several reports to Congress on sector cyber preparedness and federal resources—while clarifying no new authority or funding is granted.