Image: securityweek.com · rights & removal
Executive Summary
Facts Only
* The US Senate passed the Health Care Cybersecurity and Resilience Act.
* The bill was introduced in 2024 and reintroduced in December 2025.
* The Act proceeded to the House of Representatives after passing the Senate by unanimous consent.
* Cyberattacks on the healthcare sector risk patient data and delayed care.
* Over 730 cyber breaches affected over 270 million Americans last year, with an average cost of $10 million per breach.
* Major incidents include the Anthem breach in 2015 and the Ascension ransomware attack in 2024.
* The primary criminal tactic is ransomware coupled with double-extortion or data-extortion.
* Key elements of the Act include grants for cyberattack prevention/response training, support for rural health clinics, improved coordination between HHS and CISA, regulatory updates, and a required incident response plan for the HHS Secretary.
Full Take
From the original · SecurityWeek
The US Senate has passed the bipartisan Health Care Cybersecurity and Resilience Act, introduced by Senators Bill Cassidy, Maggie Hassan, Jon Cornyn, and Mark Warner. The bill was first introduced in 2024, but failed to pass before the end of that congressional term.Read the full story at securityweek.com
