Security News

US Senate Passes Healthcare Cyber Bill in the Wake of the Change Healthcare Breach

The Record · 7 Oct 2026
Key Takeaway Check how your suppliers and software providers protect the data you share with them, because a breach at a third party can expose your customers' information too.

The US Senate has passed the Health Care Cybersecurity and Resiliency Act of 2026 by unanimous consent. The bill was introduced after the ransomware attack on Change Healthcare, which exposed the sensitive health information of 190 million people. It could expand federal cyber requirements for healthcare organisations.

The bill directs the Department of Health and Human Services (HHS) to work with the Cybersecurity and Infrastructure Security Agency (CISA) to share cybersecurity information with healthcare entities and to create a joint plan for coordinating responses to significant incidents. Healthcare companies would also have to state the total number of victims when notifying people about unauthorised access to their health information. Senator Bill Cassidy introduced the bill with bipartisan backing, and the American Hospital Association (AHA) welcomed its grant funding for cybersecurity measures.

The AHA also wants clarity on whether the rules will cover third-party vendors. It said most reported health data breaches resulted from hacking incidents targeting non-hospital providers, including third-party service and software providers, and argued that these parties should meet the same privacy and security standards as covered entities and business associates. The Change Healthcare incident, which snarled the US healthcare system for months, was its most notable example. This summary is based on the opening of the source article only.

Answering for this at board level? Our cyber governance framework ->

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.