CiberLATAMbywhalemate

US Senate Approves Health Care Cybersecurity Bill

The Senate passed S.3315 and Gillibrand introduced S.5594, moving federal health cybersecurity and privacy proposals forward.

Whalemate Labs · AI-assisted researchPublished:3 min read

The U.S. Senate approved S.3315, the Health Care Cybersecurity and Resiliency Act of 2026, with an amendment and by unanimous consent. In parallel, Sen. Kirsten Gillibrand introduced S.5594 to create a federal Data Protection Agency and strengthen personal privacy.

The U.S. Senate approved S.3315, the Health Care Cybersecurity and Resiliency Act of 2026, with an amendment and by unanimous consent. The bill has already been sent to the House of Representatives, so it is not law yet. In parallel, Sen. Kirsten Gillibrand introduced S.5594, the Data Protection Act, to create a federal Data Protection Agency and set new privacy measures.

What did the Senate approve on health care?

The Senate gave S.3315, in engrossed form, a green light, and the measure now moves to the House of Representatives. According to Congress.gov and GovInfo.gov, the bill expands federal requirements and resources to prevent and respond to cybersecurity incidents in health care and public health, and it coordinates actions between the Secretary of Health and Human Services and the director of CISA.

The measure also directs the Department of Health and Human Services to require minimum cybersecurity practices from private entities tied to health care. The requirements cited include encryption, multifactor authentication, and security monitoring, always on a risk-based basis for covered organizations and their business associates, according to the legislative record and a Govly signal.

What else would S.3315 include if it becomes law?

The bill would provide grants, training, additional support for rural providers, and an HHS incident response plan, along with stronger coordination between HHS and CISA. A statement from the Senate Health Committee, from Sen. Bill Cassidy's office, frames the proposal as a tool to improve interagency coordination and avoid disruptions or compromises in care caused by cyberattacks.

Coverage from Franklin County News and Press adds that the bill would update the rules that apply to organizations subject to HIPAA so they align with current cybersecurity practices. That point underscores the bill's practical reach across providers and other entities connected to the health system.

What does the new privacy bill propose?

S.5594 was introduced by Kirsten Gillibrand and referred to the Senate Committee on Commerce, Science, and Transportation after its first and second readings. The bill aims to create a federal Data Protection Agency and establish measures to protect personal privacy, according to Congress.gov and the senator's statement.

Gillibrand also said the agency would have the authority to limit the collection, use, and disclosure of personal data, oversee high-risk practices, maintain a public registry of data brokers, impose civil penalties and injunctions, and develop model privacy standards. The proposal comes at a time when, according to Route Fifty, federal legislative momentum on privacy stalled after a House subcommittee hearing in early June, while states continued passing their own laws.

Sources

View all