US reintroduces health cyber law
Warner and Wyden reintroduced a bill to set mandatory health cyber standards, with audits, continuity plans and $1.3 billion.
Senators Mark Warner and Ron Wyden reintroduced the Health Infrastructure Security and Accountability Act in the United States. The bill would require the HHS to set and enforce mandatory cybersecurity minimums for health providers, health plans, clearinghouses and business associates, with tougher rules for critical entities.
U.S. senators Mark Warner and Ron Wyden have reintroduced the Health Infrastructure Security and Accountability Act in the Senate. The bill would require the Department of Health and Human Services to establish and enforce mandatory minimum cybersecurity standards for health providers, health plans, clearinghouses and business associates. It also calls for stricter requirements for entities that are systemically important or critical to national security.
What does the bill require?
The proposal orders continuity plans for technology failures or intrusions, annual cybersecurity testing, independent audits, higher penalties for failing security requirements and annual HHS oversight. According to the U.S. Senate Committee on Finance, it also includes periodic updates to those standards.
What funding does it include?
The bill includes $1.3 billion to strengthen hospital cybersecurity, according to the Finance Committee's release. Of that total, $800 million would go to rural hospitals and hospitals in underserved urban areas.
| Data | Scope | Source |
|---|---|---|
| $1.3 billion | Total fund for hospital cybersecurity | United States Senate Committee on Finance |
| $800 million | Support for rural hospitals and hospitals in underserved urban areas | United States Senate Committee on Finance |
| $500 to $250,000 | HIPAA penalties depending on the type of violation | HIPAA Journal |
What changed from 2024?
According to HIPAA Journal, the 2026 version keeps much of the text introduced in 2024, but shifts the timeline forward by two years. The review also says the bill includes minimum standards updated at least every two years, annual risk assessments, independent audits and HIPAA penalties ranging from $500 to $250,000 depending on the type of violation.
Becker's Hospital Review said the reintroduction seeks to replace the U.S. health sector's long-standing reliance on voluntary guidance with enforceable federal minimum standards. BankInfoSecurity, for its part, framed it as another effort to raise security requirements for HIPAA-covered organizations and their business associates, with financial support aimed at rural and safety-net hospitals.
KFF Health News also confirmed the institutional roles of the sponsors: Warner is vice chair of the Select Committee on Intelligence, and Wyden is the ranking member of the budget committee. SecureWorld described the bill as a move to make mandatory standards that had long been treated as voluntary guidance, although its reference to possible penalties for executives' inaccurate statements about compliance was left as an unconfirmed point.
Sources
- Senators revive healthcare cybersecurity bill with $1.3B for hospitalsbeckershospitalreview.com· Becker's Hospital ReviewUnverified URL
- Warner, Wyden Introduce Bill to Strengthen Cybersecurity Standards for American Health Care Systemfinance.senate.gov· United States Senate Committee on Finance
- Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Acthipaajournal.com· HIPAA Journal
- Senators Renew Push for Tougher Healthcare Cyber Regsbankinfosecurity.com· BankInfoSecurity
- Tuesday, Sept. 22, 2026kffhealthnews.org· KFF Health News
- Bill Would Force U.S. Hospitals to Take Cybersecurity Seriouslysecureworld.io· SecureWorld



