The Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act of 2026, by unanimous consent on September 30. Sens. Bill Cassidy, Mark Warner, Maggie Hassan, and John Cornyn sponsored the bill, which the HELP Committee advanced 22 to 1 before it reached the floor. It now goes to the House.
The text sets a floor for every HIPAA covered entity and business associate: multifactor authentication, encryption of electronic protected health information, continuous monitoring for cyber events, and penetration testing, all aligned to the NIST Cybersecurity Framework. HHS has to revisit the standards every two years and publish a formal incident response plan. The bill also designates the Administration for Strategic Preparedness and Response as the sector's single point of coordination with CISA.
Money comes with the mandate. Grants fund training and baseline controls at rural and under resourced providers, with the exact appropriation left to the Appropriations Committees. The updated OCR breach portal will show whether an organization had recognized security practices in place at the time of a breach. That turns every future incident report into a public scorecard of who skipped the floor.
S. 3315 is not the only health care cyber bill moving this fall. HISAA, reintroduced by Sens. Ron Wyden and Mark Warner on September 17, carries steeper per violation penalties and sits in the Finance Committee with no floor vote yet. A remote monitoring platform or therapy management portal that stores or transmits patient data for a covered entity becomes a business associate the moment the contract is signed. That holds regardless of what the device itself is regulated as.