Hackers have shut down hospitals, delayed patient care and walked off with the private medical records of millions of Americans. Now the U.S. Senate is fighting back. The chamber passed the Health Care Cybersecurity and Resiliency Act by unanimous consent, with no objection from either party, and sent the bipartisan bill co-led by Virginia Sen. Mark R. Warner to the House.
Warner (D-Va.) wrote the legislation with Sens. Bill Cassidy, M.D. (R-La.), Maggie Hassan (D-N.H.) and John Cornyn (R-Texas). It sends federal grant money to health care providers to build up their cyber defenses and requires the agencies that respond to attacks to work together more closely. It also gives extra help to rural hospitals and clinics, which often don’t have the staff or the budget to protect themselves.
“Cyberattacks on our health care systems can have life-or-death consequences for patients and put the sensitive information of millions of Americans at risk,” Warner said. “I’m proud to have helped pass this critical legislation through the Senate, and I urge the House to act quickly. This bill will strengthen our cybersecurity, better protect patients and their information, and give rural health care providers in Virginia and across the country additional tools to defend against cyber threats.”
Cassidy, a physician, said the danger is getting worse. “Cyberattacks can shut down hospitals and expose patients’ private medical records,” he said. “At a time when hostile actors are increasingly using sophisticated tactics to breach health care systems, the Health Care Cybersecurity and Resilience Act will help health care providers strengthen their defenses against cyber threats and protect patients’ health data.”
Hassan said her state has already been hit. “Cyberattacks have exposed patients’ private medical information and disrupted critical patient care in New Hampshire and across the country,” she said. “This bipartisan legislation will help hospitals and health care providers, particularly those in rural communities with fewer resources, strengthen their cybersecurity and respond faster to attacks. I’m pleased to see that the Senate came together to pass this bill, and I’ll keep working across the aisle to protect patients and strengthen our health care system.”
Cornyn said patients deserve to trust that their data is protected. “Patients deserve absolute confidence that their sensitive medical data stored online is protected and shielded from cybersecurity breaches or ransomware attacks,” he said. “This legislation would strengthen interagency coordination and improve security practices for rural providers, ensuring Texans’ health care is not delayed or compromised by cyberattacks.”
The bill authorizes grants to help health care organizations prevent and respond to cyberattacks, and it provides training on cybersecurity best practices. Rural health clinics and other rural providers would get guidance on preventing breaches, recovering from them and working with federal agencies. The bill also requires the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA) to coordinate their response to attacks on the health care sector. It updates regulations so that organizations covered by the Health Insurance Portability and Accountability Act (HIPAA) follow current cybersecurity best practices. Finally, the HHS secretary would have to create and carry out a formal plan for responding to cybersecurity incidents.
The bill now goes to the House, where it will need to pass before it can be sent to the president’s desk. The full text is available on Warner’s Senate website.




