Utopia Tech
Healthcare4 min read

Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act

On September 17, 2026, two Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act, which seeks to improve cybersecurity standards for the U.S. healthcare system and make funds available to help rural and underserved hospitals invest in essential cybersecurity measures. The bill was reintroduced by Sens. Mark R. Warner (D-VA) and Ron Wyden (D-

UT

Utopia Tech

September 18, 2026 · 4 min read

Share

On September 17, 2026, two Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act, which seeks to improve cybersecurity standards for the U. S. healthcare system and make funds available to help rural and underserved hospitals invest in essential cybersecurity measures.

The bill was reintroduced by Sens. Mark R. Warner (D-VA) and Ron Wyden (D-OR), following its initial introduction in the 118 th Congress 2D Session on September 25, 2024.

When the bill was first introduced, 394 large hacking-related healthcare data breaches had been reported to the Department of Health and Human Services Office for Civil Rights (OCR), involving the protected health information of 43 million Americans. At the time, the senators explained that cyberattacks are delaying and disrupting patient care, harming patient health and national security, and putting Americans at risk of identity theft and fraud.

“These hacks are entirely preventable and are the direct result of lax cybersecurity practices by health care providers and their business partners,” explained the Senators. The situation has only worsened in the two years since the bill was first introduced. The OCR breach portal lists year-to-date figures (Jan 1 – Aug 31) of 426 hacking-related breaches, involving the protected health information of 73 million Americans.

That’s an 8% increase in hacking-related data breaches and a 70% increase in affected individuals. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy On January 24, 2024, OCR published two sets of voluntary cybersecurity performance goals (CPGs) for the healthcare and public health (HPH) sector – Essential and Enhanced – that consist of high-impact measures that should be adopted by healthcare organizations to strengthen and mature their cybersecurity programs.

As predicted by OCR at the time, voluntary goals alone would not be enough to drive the behavioral changes needed across the sector to improve cybersecurity. The CPGs were followed by a proposed update to the HIPAA Security Rule, which mandates significant additional cybersecurity requirements. The proposed update has proven hugely unpopular, with industry groups and health systems calling for the proposed rule to be scrapped.

A final rule has been delayed until July 2027, although a final decision about whether a final rule will actually be released has yet to be made by the Trump administration. Part of the problem, especially for rural and other low-resource healthcare providers, is a lack of funding to make the necessary cybersecurity improvements, which is something that the Health Infrastructure Security and Accountability Act seeks to address.

“As cybercriminals ramp up their attacks on hospitals and health care providers, it’s becoming increasingly clear that voluntary standards are not enough to protect Americans’ health, safety, and privacy,” explained Sen. Warner. “This legislation would establish strong, commonsense cybersecurity protocols for health care entities, while also getting resources to rural and underserved hospitals to strengthen their defenses and protect the patients who depend on them.”

As the Senators explained, the U. S. health care system is particularly at risk for cyberattacks due to its size, technological dependence, collection of sensitive personal information, and unique vulnerability to disruptions.

Healthcare organizations are viewed as low-hanging fruit, and attacks can be highly profitable for cybercriminals. “The frequency and sophistication of cyberattacks has dramatically increased in every part of the health care system, and will only grow,” said Sen. Wyden.

“Our bill creates national cybersecurity standards for health care providers and devotes resources, especially in rural and underserved areas, to ensure every American’s medical information is secure. Congress cannot wait to act until another catastrophic cyberattack compromises the safety and privacy of American families’ most personal information.” The 2026 Health Infrastructure Security and Accountability Act remains largely unchanged from the 2024 version, other than shifting the timeline forward by two years.

The key requirements of the bill are: Mandatory minimum cybersecurity standards for covered entities and business associates, established, enforced, and updated by the HHS. Updates are required at least every two years. Heightened cybersecurity standards for systemically important entities and entities critical to national security.

Continuity/recovery plans for all covered entities for technical failures, disruptive cyber events, and natural disasters, and stress tests to evaluate whether the entity has the capabilities to recover essential functions. Written annual statements signed by the chief executive officer and chief information security officer attesting that the company is compliant with applicable security standards.

Mandatory annual security risk analyses, including specific assessments of the extent to which the entity is exposed to risk through its business associates. Independent audits of covered entities’ security measures to assess compliance with the HHS’s CPGs. Annual HHS audits of at least 20 HIPAA-regulated entities to assess data security practices, focused on those of systemic importance.

Increased financial penalties under HIPAA for failing to meet security requirements – A minimum $500 penalty for no knowledge; $5,000 for reasonable cause; $50,000 for willful neglect (corrected); and $250,000 for willful neglect (uncorrected). A government investment of $1.

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content