BACK TO BLOGS Back to Press Releases

Senate passes healthcare cybersecurity bill: What IT leaders should prepare

Written by:

Written by:

Healthcare organizations may be moving closer to more prescriptive federal cybersecurity requirements. On October 2, 2026, the U.S. Senate passed the bipartisan Health Care Cybersecurity and Resiliency Act of 2025 by unanimous consent. The bill now moves to the House of Representatives. It is not yet law, and it does not create immediate compliance deadlines for healthcare organizations.

The development still deserves attention from healthcare IT and compliance teams. The bill would direct the Department of Health and Human Services (HHS) to update HIPAA regulations with specific technical safeguards while expanding federal coordination, training, and financial assistance.  

The direction is clear: Healthcare cybersecurity requirements are shifting from broadly defined risk management toward controls that organizations can implement, test, and document.

What healthcare cybersecurity requirements would the bill create?

If enacted, the legislation would require HHS to update the HIPAA privacy, security, and breach-notification regulations for covered entities and business associates. The updated regulations would require:

  • Multifactor authentication (MFA), or a successor technology, for access to information systems that may contain protected health information
  • Safeguards to encrypt protected health information
  • Audits, including penetration testing, to maintain information-system protections
  • Additional minimum cybersecurity standards determined by HHS using threat analysis and consensus-based practices

HHS would set the effective date for each requirement and provide regulated entities with a reasonable period to comply. That means the bill itself would not switch these obligations on immediately. The regulatory process would establish the detailed requirements and implementation timelines.

The bill would also require HHS and the Cybersecurity and Infrastructure Security Agency to coordinate more closely, share sector-specific threat information, and improve defensive resources.  

Other provisions address healthcare cybersecurity training, rural readiness guidance, incident-response planning within HHS, and grants for eligible providers to adopt cybersecurity best practices. Grant funds could support workforce training, system modernization, threat-information sharing, legacy-system reduction, and qualified third-party assistance.

How does this relate to the proposed HIPAA Security Rule update?

The bill is part of a broader movement toward measurable security controls.  

HHS has already proposed changes to the HIPAA Security Rule that would require measures including MFA, encryption of electronic protected health information at rest and in transit, network segmentation, vulnerability scanning, annual penetration testing, compliance audits, and written incident-response procedures. That proposal has not become a final rule.

The Senate bill and the proposed HIPAA update are separate actions, and neither should be treated as a current final mandate. Together, however, they show where federal expectations are heading.  

Policies alone will not be enough. Organizations may increasingly need to demonstrate that security controls are deployed, tested, and producing evidence.

What healthcare IT and compliance teams should prepare now

Healthcare organizations do not need to wait for final legislation to assess their readiness. Many of the proposed measures also align with HHS’s voluntary Healthcare and Public Health Cybersecurity Performance Goals. Those goals address areas such as MFA, encryption, asset inventory, incident response, vulnerability management, and endpoint protection.

Start with the systems and data in scope. Maintain an accurate inventory of endpoints, servers, cloud services, medical devices, applications, and third-party connections that store, process, or transmit electronic protected health information. Map where that information resides and which users, service accounts, vendors, and applications can reach it.

Next, assess whether access controls work consistently. Confirm that MFA covers relevant systems and remote-access paths. Remove unnecessary standing administrative privileges. Review service accounts, shared credentials, and emergency-access workflows so least privilege does not interfere with patient care.

Technical prevention should also be part of the readiness plan:  

  • Application Allowlisting can stop unauthorized software from executing.  ‍
  • Ringfencing™ can restrict what approved applications are permitted to access or launch.  ‍
  • Privileged Access Management can provide administrative elevation only when it is needed, while network controls can reduce lateral movement between clinical and business systems.  

Together, these controls support compliance efforts by enforcing policy rather than relying on written intent alone.

Finally, test and document. Conduct risk assessments, vulnerability scans, penetration tests, recovery exercises, and incident-response drills on a defined schedule. Retain policy decisions, test results, corrective actions, access records, and control logs.  

Compliance teams need evidence that safeguards operate as intended, and IT teams need the same evidence to identify and correct control failures before an incident.

Preparation should focus on resilience, not a checklist

The bill may change as it moves through the House, and future HHS regulations would determine the final details. Healthcare organizations should therefore avoid treating the current text as a finished compliance checklist.

The more durable approach is to prepare for the outcome policymakers are seeking: fewer preventable intrusions, stronger protection for patient information, and less disruption to care.  

Healthcare IT leaders should know what is running, limit what applications and users can do, protect sensitive data, test their defenses, and retain evidence. Those steps improve security now while putting organizations in a stronger position if new healthcare cybersecurity requirements become law.

How ThreatLocker helps you prevent cyberattacks from impacting patient care.

Frequently asked questions

Has the Health Care Cybersecurity and Resiliency Act become law?

No. The Senate passed the bill on October 2, 2026, but the House must also approve it before it can be presented to the president. Its requirements are therefore proposed, not current legal obligations.

Who would be affected by the proposed cybersecurity standards?

The bill directs HHS to update HIPAA regulations governing covered entities and business associates. The precise scope, effective dates, and implementation details would be established through those updated regulations.

What should healthcare organizations prioritize first?

Begin with an accurate asset and data inventory, then assess multifactor authentication, encryption, privileged access, endpoint controls, segmentation, incident response, and recovery. Document testing and remediation so the organization can demonstrate that controls are operating effectively.

‍

No items found.

Start your path to stronger defenses

Start your trial

Try ThreatLocker free for 30 days and experience full Zero Trust protection in your own environment.

Book a demo

Schedule a customized demo and explore how ThreatLocker aligns with your security goals.

Ask an expert

Just starting to explore our platform? Find out what ThreatLocker is, how it works, and how it’s different.