Health Care Cybersecurity and Resiliency

Summary#

The bill directs the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency to work together to improve cybersecurity in the health care and public health sectors. It requires HHS to create a plan for responding to cyber incidents involving its systems and to update the public breach reporting portal with information about corrective actions and security practices. Breach notices would also have to state how many people were affected.

The bill directs HHS to set cybersecurity requirements for covered health care entities and business associates, including multifactor authentication, encryption of protected health information, and audits such as penetration testing. It also calls for guidance on cybersecurity readiness for rural entities, grants for eligible health care organizations, training, and a plan to support the health care cybersecurity workforce. The bill passed the Senate, according to the provided metadata.

What it means for you#

Health care organizations covered by the rules may need to adopt required security practices once HHS sets their effective dates. Eligible organizations may apply for grants to support cybersecurity work. The bill also calls for more information about breaches to be made public. It does not specify how these changes would affect any individual patient.

Expenses#

The bill authorizes appropriations for grants for fiscal years 2025 through 2030, but does not state a total amount. No publicly available information on total expenses.

Proponents' View#

No publicly available information.

Opponents' View#

No publicly available information.