The Senate passed the Health Care Cybersecurity and Resilience Act by unanimous consent on Thursday, sending the House a bill that would push the Department of Health and Human Services to set minimum cybersecurity practices for hospitals, clinics and the vendors that serve them.

Unanimous votes are rare enough in the current Congress that the tally is itself the story's first fact. The bill was introduced by Bill Cassidy, the Louisiana Republican who chairs the Senate Health, Education, Labor and Pensions Committee, and cosponsored by Maggie Hassan of New Hampshire, John Cornyn of Texas and Mark Warner of Virginia, with Cindy Hyde-Smith of Mississippi and Angus King of Maine also signed on. The committee advanced it 22 to 1 in February.

The substance is narrower than the vote suggests, and the gap between the two is where the bill's real work begins. Most of what the legislation promises depends on a rulemaking that HHS has not completed, and the money it once guaranteed for the providers who need help most is no longer guaranteed at all.

What the bill asks HHS to do

The centerpiece is a directive to modernize the HIPAA Security Rule, the regulation that has governed how health care organizations protect electronic patient information since 2003. The bill calls on HHS to write minimum cybersecurity practices into that rule, naming multifactor authentication and penetration testing among the requirements.

Those two items sound modest. In practice they are the difference between a sector that relies on passwords alone and one that assumes its perimeter will be breached. Penetration testing forces an organization to pay for a simulated attack and act on the findings, which is a recurring cost rather than a one-time purchase. For a rural hospital with a single information technology director, both requirements land on the same short list of things that have never fit in the budget.

The bill also asks for better coordination between HHS and the Cybersecurity and Infrastructure Security Agency when a health care organization is attacked, more guidance for rural providers on preventing and surviving breaches, cybersecurity training for the workforce, and an incident response plan that the HHS secretary would have to develop and implement.

Because the requirements would live inside the HIPAA Security Rule, they would be enforced the way that rule is enforced now, by the Office for Civil Rights using the authority it already has. The bill does not build a new regulator or a new set of penalties. It changes what the existing rule requires, which is a quieter intervention than it sounds and a more durable one, since a standard written into a regulation outlasts the administration that wrote it.

The rule that has been waiting since January 2025

There is a version of this rulemaking already on the shelf. In the final days of the Biden administration, HHS published a proposed update to the HIPAA Security Rule that included many of the same requirements the Senate bill now names. The department never finalized it, and the Office for Civil Rights under the current administration has not moved the proposal forward.

That history is the argument for the bill and the caution about it. Congress can require an agency to write a rule, and it can set a standard in statute that the agency has to reach. What it cannot do is compress the notice-and-comment process into a vote, which means the requirements hospitals will face are still unwritten, still subject to public comment, and still shaped by the same department that has let the proposal sit.

The bill's sponsors say the sector cannot wait for the next attempt. Cassidy has spent the year on health data, moving a Health Information Privacy Reform Act through the Senate by unanimous consent in July and running investigations into breaches and privacy failures at health systems and vendors, among them NYC Health + Hospitals, Hims & Hers, Instructure, OPEXUS and UnitedHealth Group. The cybersecurity bill is the enforcement-shaped piece of that agenda, aimed at the minimum standards rather than the incidents that follow their absence.

The grants lost their funding line on the way through

As introduced, the bill paired its requirements with grants to help health care organizations pay for them. As passed, it still creates the grant program, but the amended text no longer expressly authorizes Congress to appropriate money for it through fiscal 2030. Funding now depends on a separate appropriations process or another source of authority.

That change matters most for the providers the bill singles out for help. Large health systems have cybersecurity teams and capital budgets. Rural hospitals often have neither, and the cost of compliance is the reason their trade groups have asked for support rather than mandates. The Senate has now asked them to meet a standard and left the question of who pays for it to a later vote, which is the same arrangement that has left the proposed rule in limbo for a year and a half.

The bill's other provisions have the same structure. Guidance for rural providers, training and federal coordination are all things an agency can do without new money. They are also thinner than a funded program, and their reach depends on how much attention HHS gives them after the bill becomes law.

What hospital technology officers asked for

The industry's response has been supportive and specific about what it wants next. Cassie Ballard, senior director of congressional affairs at the College of Healthcare Information Management Executives, said in a statement that the minimum standards provision is among the most consequential in the bill because it gives HHS a set of frameworks to consider during the rulemaking.

Ballard described the problem the standards would solve as an absence of a single authority. Hospitals currently answer to recommendations from multiple federal agencies, professional societies and industry groups, with overlapping and sometimes competing guidance, and her members have asked for a clear, authoritative source of truth. She also made the case for restraint in how the standards are enforced, arguing that oversight should produce security improvements without adding unnecessary burden, and pointed to the Cybersecurity Performance Goals that HHS developed with the industry as the reference point her members still use.

That position is not neutral. CHIME represents the people who would have to implement whatever HHS writes, and its members have an interest in standards that are clear, achievable and funded. It is also the position of a group that has watched voluntary frameworks multiply without resolving the underlying question of which one governs.

Why the sector keeps ending up here

Health care's cybersecurity problem is structural. Hospitals run on software and connected devices that were often bought without security requirements, they hold records that are valuable on the black market, and they cannot shut down while they fix a breach. Ransomware crews have learned that a hospital is a target that will pay to restore patient care, and third-party vendors have become the path of least resistance into systems whose own defenses are adequate.

The bill's provisions read like a response to that pattern. Coordination with CISA addresses the incident itself. Guidance for rural providers addresses the organizations with the least capacity to prepare. The training and response-plan requirements address the human layer, which is where a great many breaches begin. What the bill does not do is set the specific technical requirements itself. It names two, hands the rest to HHS, and creates a framework for the department to fill.

The alternative, writing the requirements into the statute, is what the bill's sponsors avoided on purpose. Technical standards age quickly, and a rule can be updated without a floor vote. The trade is speed for specificity: a rulemaking gives the department room to weigh hospital budgets against security needs, and it gives the industry a formal chance to argue about what the minimum should be. It also gives any future administration the option of doing nothing, which is the outcome the current proposal has already produced once.

What the House does with it

The bill now goes to the House, where the parallel effort is already under way and more fragmented. Warner has urged the House to act quickly, and two health care cybersecurity bills have been introduced there, including the Rural Hospital Cybersecurity Enhancement Act. A chamber that has its own proposals can treat a Senate bill as a starting point, a vehicle or a reason to wait, and the calendar gives it little incentive to move first.

The Senate's unanimous vote is a genuine achievement in a Congress that agrees on little, and it is also the cheapest kind of agreement. Nobody had to vote for a specific requirement, a specific deadline or a specific appropriation. Those decisions were moved to the rulemaking, where the department that has not yet acted on its own proposal will now be asked to act on Congress's instruction, and to the appropriations process, where the grants will compete with everything else.

The test of the bill will not be Thursday's vote. It will be whether HHS publishes a rule with the requirements the sponsors described, and whether the grants that are supposed to help small hospitals meet them survive the spending fight the bill deliberately avoided.

Primary sources

  1. The Senate Health, Education, Labor and Pensions Committee for the bill's passage by unanimous consent, the sponsor and cosponsor list, the statements of Senators Cassidy, Hassan, Cornyn and Warner, and Cassidy's prior health privacy legislation and investigations.
  2. BankInfoSecurity for the amended text's treatment of the grant program, the requirement that HHS modernize the HIPAA Security Rule with multifactor authentication and penetration testing, the February committee vote, the House bills and the statement from the College of Healthcare Information Management Executives.
  3. The Federal Register for the proposed HIPAA Security Rule update to strengthen the cybersecurity of electronic protected health information, published January 6, 2025.