All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
The Senate has unanimously passed a new healthcare cybersecurity bill that would require hospitals, insurers, and their vendors to meet stricter, mandatory security standards.[1]
Healthcare has long been a lucrative target for cybercriminals because it contains detailed and highly sensitive records belonging to millions of people.
Imagine your private information, including your Social Security number, healthcare records, and Medicaid details, falling into the hands of cybercriminals. They could use it to steal your medical identity, commit financial fraud, or even trick you into handing over your login credentials through convincing phishing messages that reference your medical history.
Here's what the new bill covers, and how it can protect you moving forward.
Why does the US need better healthcare cybersecurity
The privacy risks of a healthcare data breach
The bottom line
What the new healthcare cybersecurity bill would change
The Senate passed the Health Care Cybersecurity and Resilience Act by unanimous consent on September 30. The bipartisan bill aims to strengthen the healthcare sector’s response to cyberattacks by improving coordination between the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency.
Sen. Bill Cassidy (R-LA), the bill’s lead sponsor, worked with Sen. Mark Warner (D-VA), John Cornyn (R-TX), and Maggie Hassan (D-NH) to steer it through the Senate. It now heads to the House of Representatives for consideration.
Here are the main provisions of the bill.
- Mandatory security minimums for healthcare organizations: HHS would have to rewrite the HIPAA security rules to include multi-factor authentication (MFA), encryption of health information, and ongoing monitoring, including penetration testing. This would apply to insurers, providers, vendors, and private health sector entities. However, these security requirements wouldn’t take effect until 36 months after enactment.
- Credit for good security: HHS would have to write rules explaining how an organization’s existing security practices and investments could reduce fines or shorten audits after a breach.
- Help for smaller providers: The proposed act would allow HHS to award grants of up to three years to community health centers, nonprofit hospitals, rural clinics, and Indian Health Service facilities for staff, system upgrades, and risk assessments.
- Coordination between agencies: The proposed act lays down various coordination efforts between HHS and CISA to build a joint plan for responding to major cybersecurity attacks. HHS must also name a lead official for health cybersecurity and report to Congress annually. Besides this, HHS must expand its own incident response plan and provide adequate workforce training for handling cybersecurity cases.
- Disclosure of affected people: Under current law, a data breach notification letter must tell you what happened, what information was exposed, and the steps you should take. It doesn’t currently have to tell you how many people the breach affected. This bill changes that by requiring every notice to state the number of people affected. This would help victims judge how serious an incident is and is also one of the few changes in the bill that patients would see directly.
Why does the US need better healthcare cybersecurity?
The four senators first formed their healthcare cybersecurity working group in November 2023, after HHS recorded 89 million Americans having their health data breached that year. Soon after, in February 2024, the U.S. witnessed one of the largest ransomware attacks on the healthcare sector.
The BlackCat group got into Change Healthcare’s database using stolen credentials on a remote access portal that didn’t have multi-factor authentication. The attackers spent nine days stealing data before deploying ransomware on February 21, 2024.
Following the attack, pharmacies couldn’t verify insurance, forcing patients to pay out of pocket. Hospitals and medical practices couldn’t submit claims or get paid, while UnitedHealth advanced billions of dollars in emergency loans to keep providers afloat. The company also paid around $22 million in Bitcoin, although the ransomware group kept the money without paying the affiliate that carried out the attack.
The Change Healthcare incident seems to have shaped the new bill, as is evident from its inclusion of multi-factor authentication, one of the main security measures that could have prevented the attack.
During the same year, Conduent, a back-office service vendor used by health insurers and state agencies to process claims and run program administration, was also breached. The SafePay ransomware group claimed to have stolen 8.5 TB of data.
First reported in October 2025, the breach was believed to have affected at least 10.5 million people. However, as investigations continued, that figure kept growing. As of June 2026, HHS believes that at least 62 million records were affected, making it the third-largest healthcare breach in history.
In 2026 alone, there have been several major data breaches.
- DentaQuest, the country’s second-largest dental benefits administrator, was breached in May, exposing details such as Social Security numbers, diagnoses, treatments, and Medicaid and Medicare IDs of patients. The ShinyHunters group published around 234 GB of data, affecting around 15 million Americans and making it one of the largest data breaches this year.
- Aesto, an Alabama business associate, and Lumexa Imaging, a North Carolina imaging provider, were also hit by hacking incidents this year, affecting around 9.5 million and 5.8 million patients, respectively.
- NYC Health, the nation’s largest public-sector health system, said an intruder had access to its system from late November 2025 through February 2026. The stolen data included sensitive information such as fingerprints, government IDs, and detailed patient medical records.
The privacy risks of a healthcare data breach
Repeated breaches of healthcare information increase the risk of medical identity theft. Healthcare organizations often have access to your personally identifiable information, including your name, date of birth, Social Security number, health insurance number, and Medicare number.
In the event of a breach, malicious third parties could use these details to assume your medical identity and receive medical procedures, medications, or insurance benefits in your name.
Your stolen information could also help criminals launch highly personalized phishing attacks. For example, a scammer could use your name, Medicaid number, or details from your medical records to make an email appear as though it came from your insurer, perhaps asking you to review a medical report or verify information about a recent prescription. The link could then take you to a fake website designed to steal your credentials or install malware on your device.
Such stolen details could also be sold on the dark web or used by threat actors to falsify medical insurance claims, alter your medical records, or stockpile prescription drugs for resale. Medical identity theft can also leave fake diagnoses and treatments in your medical file, potentially complicating your care and coverage for years.
If you believe that your data has already been compromised in a previous breach, it’s wise to get an identity theft protection service. These tools can scan known breached databases as well as the dark web to find your leaked information. They can even help you restore your identity through professional restoration specialists.
The bottom line
The Health Care Cybersecurity and Resilience Act has passed the Senate by unanimous consent. Led by Senator Bill Cassidy, the bill would add safeguards such as MFA and encryption of health information to better protect Americans’ personal health data from cyberattackers.
The law would also require hospitals and other associated vendors to strengthen their security protocols, while requiring HHS to expand its own incident response plan and improve coordination with CISA.
Overall, this is a welcome move that could help prevent future healthcare data breaches and protect millions of Americans from medical identity theft, phishing, financial fraud, and other threats stemming from stolen health data.