US Senate Passes Healthcare Cyber Bill in the Wake of the Change Healthcare Breach
The US Senate has passed the Health Care Cybersecurity and Resiliency Act of 2026 by unanimous consent. The bill was introduced after the ransomware attack on Change Healthcare, which exposed the sensitive health information of 190 million people. It could expand federal cyber requirements for healthcare organisations.
The bill directs the Department of Health and Human Services (HHS) to work with the Cybersecurity and Infrastructure Security Agency (CISA) to share cybersecurity information with healthcare entities and to create a joint plan for coordinating responses to significant incidents. Healthcare companies would also have to state the total number of victims when notifying people about unauthorised access to their health information. Senator Bill Cassidy introduced the bill with bipartisan backing, and the American Hospital Association (AHA) welcomed its grant funding for cybersecurity measures.
The AHA also wants clarity on whether the rules will cover third-party vendors. It said most reported health data breaches resulted from hacking incidents targeting non-hospital providers, including third-party service and software providers, and argued that these parties should meet the same privacy and security standards as covered entities and business associates. The Change Healthcare incident, which snarled the US healthcare system for months, was its most notable example. This summary is based on the opening of the source article only.