Greg Garcia, executive director of the Healthcare Sector Coordinating Council's cybersecurity working group, testified before the House Energy and Commerce Subcommittee on Health on September 15. The hearing, convened by Chairmen Brett Guthrie and Morgan Griffith, examined two bills: the Rural Hospital Cybersecurity Enhancement Act (H.R. 9908, from Reps. Erin Houchin and Kim Schrier, with a Senate companion at S. 2169), and a House companion to the Health Care Cybersecurity and Resiliency Act of 2026. The Senate version of that second bill, S. 3315 from Sen. Bill Cassidy, already cleared the Senate HELP Committee on a 22 to 1 vote.

Garcia backed both bills and asked for more. He wants dedicated funding to replace medical devices too old to secure, workforce development and loan forgiveness programs modeled on physician and National Science Foundation scholarship pipelines, and expanded Regional Extension Centers and community college training. What the sector needs, he told the subcommittee, is "a concerted, multi-pronged combination of government programs, assistance and funding coupled with market-based mutual support."

The device replacement ask is the line manufacturers should track. HSCC is telling Congress that some installed devices cannot reach a defensible security posture through patching alone, and that the actual fix is capital, not code. If that funding lands, it becomes a forcing function for end-of-life and trade-in programs, not just for the next cybersecurity bulletin.

Neither bill has reached a floor vote, and the House companion to the Resiliency Act had no bill number assigned as of the hearing. Garcia's own summary works as a caution against reading this as settled: "some of it is bitter medicine, some of it should be simple and habitual," he said. The easy parts of this fix are not the parts still stuck in committee.