Sens. Ron Wyden (D-Ore.) and Mark Warner (D-Va.) reintroduced the Health Infrastructure Security and Accountability Act on September 17. The bill first appeared in the Senate Finance Committee on September 26, 2024, months after the Change Healthcare ransomware attack froze claims processing nationwide. It never got a floor vote in the 118th Congress. This time it arrives with the same numbers attached.

The bill directs HHS to set minimum cybersecurity standards for HIPAA covered entities and business associates. Standards would be revised every two years. A heightened tier applies to organizations HHS designates systemically important or critical to national security. Covered organizations would need continuity plans for technology failures or intrusions, annual security risk analyses, and an independent security audit. CEOs and chief information security officers would sign annual written compliance attestations, and HHS would audit at least 20 regulated entities a year.

Civil penalties scale with intent. $500 for a violation made with no knowledge. $5,000 for reasonable cause. $50,000 for willful neglect that gets corrected. $250,000 for willful neglect left uncorrected. That ceiling is well above HIPAA's current structure, and it applies per violation, not per breach.

The bill pairs the mandate with money: $1.3 billion total. Of that, $800 million is set aside over two years for roughly 2,000 rural and urban safety net hospitals to reach a baseline set of cybersecurity goals. The remaining $500 million funds incentives for any hospital that adopts a more advanced tier of controls afterward.

HISAA targets hospitals and health plans by name, but the business associate clause is where device manufacturers get pulled in. A company qualifies as a business associate the moment its cloud platform stores or transmits patient data on a covered entity's behalf. Remote monitoring portals, therapy management dashboards, and firmware update services do exactly that. FDA's premarket cybersecurity authority under Section 524B has nothing to do with this bill. The attestation and audit exposure lands on device makers anyway, through the HIPAA back door, regardless of what the device itself is regulated as.

The Healthcare Leadership Council opposed the original 2024 version, arguing it singles out the industry for punishment instead of offering support against cybercriminals. That objection has not gone away, and the bill's path through the Senate Finance Committee in a midterm year is no more certain now than it was two years ago. Nothing in HISAA takes effect until it passes, but the attestation language and the per violation penalty structure are worth reading now, before a markup forces the question.