Warner and Wyden Reintroduce Bill to Set Mandatory Cybersecurity Standards for Hospitals

Hospital atrium protected by integrated physical security technology

Written by

in

, ,

Senators Mark R. Warner (D-VA) and Ron Wyden (D-OR) reintroduced the Health Infrastructure Security and Accountability Act on September 17, 2026, legislation that would establish mandatory minimum cybersecurity standards for hospitals and other covered healthcare entities and their business associates. The bill largely mirrors a 2024 version the senators introduced previously, with its implementation timeline shifted forward by two years.

Under the bill, the Department of Health and Human Services would set, enforce and update the minimum standards at least every two years, with heightened requirements for systemically important entities and those deemed critical to national security. Covered entities would also need continuity and recovery plans covering technical failures, disruptive cyber events and natural disasters. The legislation would direct $1.3 billion toward helping hospitals meet the new standards, including $800 million earmarked for rural hospitals and facilities serving underserved urban communities.

Why it matters

Healthcare has lagged other critical-infrastructure sectors on baseline cybersecurity requirements even as ransomware and data-theft incidents increasingly disrupt patient care rather than just back-office systems — the bill’s dedicated funding for rural and underserved hospitals directly addresses the resource gap that smaller facilities cite as the main reason they can’t meet the same security bar as large health systems.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *