Democratic senators have reintroduced their bid to tighten healthcare cybersecurity standards and direct $1.3 billion of federal funds toward updating hospitals’ protections and practices.
The Health Infrastructure Security and Accountability Act was brought late last week by Sen. Mark Warner, D-VA, who serves as vice chairman of the Select Committee on Intelligence, and Sen. Ron Wyden, D-OR, ranking member of the budget committee. It treads much of the same ground as the same-named bill they had introduced in 2024, with the senators noting that cyberattacks against healthcare have only increased in frequency and sophistication in the two years since.
“As cybercriminals ramp up their attacks on hospitals and health care providers, it’s becoming increasingly clear that voluntary standards are not enough to protect Americans’ health, safety, and privacy,” Warner said in a release announcing the bill’s reintroduction. “This legislation would establish strong, commonsense cybersecurity protocols for health care entities, while also getting resources to rural and underserved hospitals to strengthen their defenses and protect the patients who depend on them.”
The senators’ bill (PDF) would require Health and Human Services to adopt new minimum cybersecurity standards for healthcare entities and their associates within two years, with tighter requirements for those of “systemic” or national security importance.
Within three years, covered entities would also be required to conduct and document a security risk analysis and attesting that they are in compliance with applicable standards. The bill also outlines civil penalties for noncompliance and a scaling, but capped, user fee.
To help the industry comply with the heightened requirements, the bill would also provide $800 million in upfront payments to 2,000 rural and urban safety net hospitals over two years. After that point, another $500 million would be available to all Medicare hospitals that are complying with the enhanced cybersecurity standards.
“Congress cannot wait to act until another catastrophic cyberattack compromises the safety and privacy of American families’ most personal information," Wyden said in the press release.
Though it is among the first to raise alarms over rising cybersecurity threats, the hospital industry has historically been opposed to stiffer mandatory security and privacy standards, or at least has requested that they come alongside substantial financial support to help lessen implementation burden. Still, some healthcare groups had criticized the penalty structure of Warner and Wyden's earlier iteration that is generally unchanged in the newer edition.
With the government funded through the next couple of months and midterm elections well underway, it’s widely expected that no new federal healthcare legislation will be passed until early December (or later) as part of an appropriations package. Legislation passed the current Republican-controlled Congress has also largely aimed to reduce federal funding for the healthcare industry, at odds with the Democratic senators’ $1.3 billion of implementation assistance.