US Senate passes bipartisan health care cybersecurity bill by unanimous consent
The Health Care Cybersecurity and Resilience Act would fund training, support rural clinics and require HHS to build an incident response plan. It now goes to the House.
At a glance
- The bill passed the Senate by unanimous consent and was introduced by Senators Bill Cassidy, Maggie Hassan, John Cornyn and Mark Warner.
- It would fund prevention and response training, strengthen support for rural health clinics and tighten HHS–CISA coordination.
- The HHS Secretary would be required to develop a cybersecurity incident response plan and refresh regulations around current best practice.
- Sponsors cited more than 730 breaches affecting over 270 million Americans in the past year, at an average cost of $10 million each.
The US Senate passed the Health Care Cybersecurity and Resilience Act by unanimous consent, SecurityWeek reported, sending to the House a bill that would put federal money behind cyberattack training for health providers and formalise how the Department of Health and Human Services works with CISA. The measure was introduced by Senators Bill Cassidy, Maggie Hassan, John Cornyn and Mark Warner.
What happened
According to SecurityWeek, the bill would mandate grants for training in preventing and responding to cyberattacks, expand support for rural health clinics, improve coordination between HHS and CISA, update regulations to reflect current cybersecurity best practice, and require the HHS Secretary to develop a cybersecurity incident response plan. Unanimous consent means no senator objected, which is the Senate's route for measures that attract no organised opposition.
SecurityWeek reported that HHS already coordinates with CISA as the designated Sector Risk Management Agency for health care, receiving tailored threat intelligence; the bill would put that relationship and the response planning around it on a firmer footing rather than create it from scratch.
Technical details
The numbers the sponsors used to make their case are the clearest measure of the problem. SecurityWeek reported that more than 730 breaches affected over 270 million Americans in the previous year, at an average cost of about $10 million per breach. The bill's backers pointed to the 2015 Anthem breach, which exposed 78.8 million records and cost the insurer more than $115 million, and the 2024 Change Healthcare attack, which exposed data on more than 190 million people.
Senator Cassidy argued that cyberattacks not only put sensitive health data at risk but can delay life-saving care, SecurityWeek reported — the operational point that separates health care from most other regulated sectors, where a breach costs money and trust but not treatment time.
Who is affected
US health providers, insurers and the vendors in their supply chain would fall within the scope, with rural clinics singled out for additional support because they typically lack dedicated security staff. Nothing changes yet: the bill now needs to pass the House before it can become law.
What to do
SecurityWeek reported that security practitioners caution the bill's success will depend on consistent enforcement and on federal funding keeping pace with the compliance burden it creates — a familiar pattern where new requirements land hardest on the smallest providers. Health organisations watching the bill can usefully work ahead of it on the items it names: a written and exercised incident response plan, documented coordination paths to CISA and HHS, and an inventory of third-party processors, since the largest incidents cited in the debate reached patients through vendors rather than through the providers themselves.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



