Senate Passes Health Care Cybersecurity and Resiliency Act After Change Healthcare Exposed 190 Million Records
The U.S. Senate passed S.3315, the Health Care Cybersecurity and Resiliency Act of 2026, by unanimous consent on October 2, 2026. The bill now sits with the House of Representatives. It is not law yet, and it creates no immediate compliance deadlines, but the legislative trajectory is clear enough that security and compliance teams at covered entities and business associates should not wait on the House [1][6].
The catalyst was the 2024 ransomware attack on Change Healthcare, which exposed the personal health information of 190 million people and disrupted pharmacy, billing, and care-coordination systems across the country [1]. Senators cited more than 730 reported healthcare cyber breaches in 2025 affecting over 270 million Americans, with an average breach cost of $10 million [4]. That scale forced a legislative response that had enough bipartisan weight to clear the Senate HELP Committee on a 22-1 vote in February 2026, with Sen. Rand Paul (R-KY) the only dissenter [2][3].
What the Bill Actually Requires
The bill directs HHS to update HIPAA's privacy, security, and breach-notification rules with specific technical controls. Under Section 8, HHS must mandate [5][6]:
- Multifactor authentication for any system that may access protected health information
- Encryption of PHI at rest and in transit
- Regular penetration testing and monitoring
- Alignment with NIST cybersecurity frameworks
- Additional minimum standards determined through threat analysis and consensus-based practices
HHS sets the effective date for each requirement and must provide regulatory guidance. The implementation window, once the bill is enacted, is 36 months [5][8].
For organizations that have used HIPAA's addressability provisions to defer encryption or sidestep MFA, that window is shorter than it looks. Compliance programs built around documented risk-based alternatives will need to be rebuilt around hard technical controls [5].
What Changes About HIPAA's Architecture
For more than two decades, the HIPAA Security Rule was deliberately non-prescriptive. Encryption was addressable, meaning a covered entity could document a reasonable alternative. MFA was not mentioned. Penetration testing had no mandated cadence. The design was intentional, meant to accommodate a sprawling, heterogeneous industry [5].
This bill ends that flexibility in significant areas. MFA, encryption, and penetration testing move from optional-with-justification to mandatory. This change restructures how compliance obligations are framed under HIPAA [5][2].
The HELP Committee's 22-1 vote, and the Senate's unanimous consent passage, reflect a judgment that the risk-based flexibility model has produced inadequate baseline security across the sector. The Change Healthcare incident was the evidence that argument needed [3].
Federal Coordination, Rural Grants, and Workforce Requirements
Beyond the technical controls, the bill has several operational provisions [1][3][6]:
- HHS must develop a cybersecurity incident response plan and submit it to Congress for review
- HHS and CISA must jointly coordinate healthcare sector cybersecurity oversight and create a joint response plan for significant incidents
- The Administration for Strategic Preparedness and Response (ASPR) is designated to lead cybersecurity coordination within HHS
- Federal grants will fund rural hospitals and smaller providers with fewer internal resources
- HHS must develop a plan to grow the healthcare cybersecurity workforce and expand training and best practices
The rural grant provision matters. Small and rural hospitals have been consistent targets precisely because they lack the staff and budget to maintain adequate defenses. Mandating controls without funding the organizations least able to implement them would concentrate risk, not reduce it [4][7].
Breach Notification Changes and Enforcement
The bill adds a specific breach notification requirement: covered entities must include the total number of affected individuals when notifying people of unauthorized access to their health information [1][2].
This has litigation implications. When breach counts were vague or estimated low, plaintiffs had less concrete grounds. Mandatory victim counts in notifications give class-action attorneys precise numbers from the outset [2].
The bill also includes a safe harbor provision. Organizations that can demonstrate 12 continuous months of recognized security practices prior to an incident qualify for reduced enforcement penalties [2]. That is a direct incentive for proactive compliance programs rather than reactive patch efforts after a breach.
Where the Bill Goes From Here
The House Energy and Commerce Subcommittee on Health held a hearing on September 15 that included companion rural hospital legislation, but no markup is scheduled yet [5]. The Senate path is complete. The House is the remaining variable.
Healthcare organizations broadly support the bill, but questions remain about whether federal funding and technical assistance will scale to meet compliance demand across a sector that includes large health systems, small physician practices, rural critical access hospitals, and thousands of business associates [4].
For enterprise-managed healthcare networks, the 36-month clock does not start until enactment. But MFA deployment, PHI encryption, and penetration testing programs all take time to scope, fund, and implement at scale. Starting the gap analysis now against the bill's Section 8 requirements costs nothing and avoids a compressed remediation timeline later.
The bill also signals that Congress views the sector's self-reported HIPAA compliance as insufficient. The next round of HHS enforcement, whatever form the updated Security Rule takes, will have specific technical benchmarks to measure against rather than risk-based narratives to evaluate.
Red Sheep Assessment
The more consequential long-term effect of this bill may not be on large health systems, which already run mature security programs, but on the thousands of business associates that sit in the HIPAA supply chain and have historically escaped meaningful scrutiny. Mandatory MFA and encryption requirements applied to business associates as covered entities closes the exact vector that made the Change Healthcare breach possible at scale. If the House passes this with the business associate provisions intact, expect enforcement action against mid-tier health IT vendors to become the leading edge of HHS's updated posture within two years of enactment. Confidence: moderate, contingent on House passage and HHS rulemaking timelines.
Sources
- Senate passes healthcare cybersecurity bill after 190 million impacted by Change Healthcare breach - https://therecord.media/senate-passes-healthcare-cyber-bill-after-change-breach
- Senate Advances Healthcare Cybersecurity Act 2026: Key Provisions - https://www.kiteworks.com/hipaa-compliance/senate-healthcare-cybersecurity-resiliency-act-2026-hipaa-reform/
- Senate moves one step closer to passing health care cyber reforms - https://cyberscoop.com/senate-passes-health-care-cyber-reforms-cassidy/
- Senate Passes Healthcare Cybersecurity Bill With Grants and Updated Security Requirements - https://mallory.ai/stories/01a1021b-9200-7e37-b05b-f613071bbabd
- Senate Votes to End HIPAA's Risk-Based Cybersecurity Era - https://www.cybrsecmedia.com/senate-votes-to-end-hipaas-risk-based-cybersecurity-era/
- Senate passes healthcare cybersecurity bill: What IT leaders should prepare - https://www.threatlocker.com/blog/senate-passes-healthcare-cybersecurity-bill-what-it-leaders-should-prepare
- Senate Passes Warner Legislation to Strengthen Cybersecurity in Health Care - https://www.warner.senate.gov/newsroom/press-releases/senate-passes-warner-legislation-to-strengthen-cybersecurity-in-health-care/
- U.S. Senate Approves Health Cybersecurity Bill - https://ciberlatam.com/en/news/us-senate-approves-health-care