U.S. Sens. Mark Warner (D-Va.) and Ron Wyden (D-Ore.) reintroduced legislation Thursday aimed at strengthening cybersecurity standards across the nation’s health care system as hospitals and medical providers face increasingly frequent cyberattacks.
The Health Infrastructure Security and Accountability Act would establish mandatory minimum cybersecurity standards for health care providers, health plans, clearinghouses and companies that handle protected health information. It would also provide $1.3 billion to help hospitals improve cybersecurity, including $800 million targeted toward rural hospitals and those serving underserved urban communities.
“Cyberattacks on our health care system compromise Americans’ most sensitive personal information, delay essential medical care, and put lives at risk,” Warner said. “As cybercriminals ramp up their attacks on hospitals and health care providers, it’s becoming increasingly clear that voluntary standards are not enough to protect Americans’ health, safety, and privacy.”
Under the legislation, the Department of Health and Human Services would be required to establish, enforce and regularly update cybersecurity standards, with additional requirements for health care organizations considered systemically important or critical to national security.
Health care organizations covered by the legislation would also be required to develop plans for maintaining or restoring operations following a cyberattack or major technology failure, conduct annual cybersecurity testing and undergo independent security audits.
The legislation would increase penalties for organizations that fail to comply with security requirements and strengthen federal oversight by requiring HHS to conduct annual cybersecurity audits.
“Americans share their most sensitive personal information with their health care providers, and in return they expect every effort to be made to keep it secure,” Wyden said. “The frequency and sophistication of cyberattacks has dramatically increased in every part of the health care system, and will only grow.”
The legislation also raises a much larger question that the News-Press will examine as part of its continuing series on data, artificial intelligence, surveillance and privacy: Has the government infrastructure responsible for protecting Americans’ data kept pace with the extraordinary growth of the data itself?
Health care provides a particularly important case study. The expansion of electronic health records accelerated dramatically during the Obama administration, building on federal requirements and incentives enacted through the 2009 HITECH Act and later changes associated with the Affordable Care Act. The result has been a health care system in which enormous amounts of highly sensitive information can move among hospitals, doctors, insurers, pharmacies, government agencies and private technology companies.
But health care is only one piece of a much larger transformation. Financial records, tax information, vehicle and location data, biometric information, communications, consumer behavior, education records and increasingly AI-generated and AI-processed information now touch virtually every part of American life.
That leaves a question extending well beyond cybersecurity: Who is ultimately responsible for protecting all of it?
Data oversight today is divided among numerous federal and state agencies, each operating under different laws, authorities and enforcement structures. As technology increasingly crosses those traditional boundaries, policymakers face a fundamental question over whether the existing regulatory structure remains adequate or whether the country eventually needs a substantially different approach to data governance and data-related crime.
Could that mean a dedicated federal agency focused on data protection? Expanded authority for existing regulators? A specialized law-enforcement capability for increasingly sophisticated data crimes? Or would creating another federal bureaucracy introduce its own privacy, surveillance and accountability concerns?
There are no simple answers. But as data becomes infrastructure underlying health care, banking, transportation, government, commerce, communications and everyday life, deciding who controls it, who can access it, who protects it and what happens when it is abused is becoming increasingly difficult to treat as a collection of unrelated policy questions.
The News-Press will examine those questions more closely next week as this series expands its look at the rapidly changing relationship among government, private industry, artificial intelligence, cybersecurity, surveillance and the enormous quantities of data Americans generate every day.
