Bill Would Force U.S. Hospitals to Take Cybersecurity Seriously
12:45
Fri | Sep 18, 2026 | 1:04 PM PDT

Two years after the Change Healthcare ransomware attack froze claims processing at pharmacies and hospitals nationwide, Congress is trying again to write mandatory cybersecurity rules into federal health law. On September 17, U.S. Senators Mark R. Warner (D-VA) and Ron Wyden (D-OR) reintroduced the Health Infrastructure Security and Accountability Act, a bill that would replace the healthcare sector's long-standing reliance on voluntary cybersecurity guidance with enforceable minimum standards, mandatory audits, and steep new penalties for executives who lie about compliance.

The bill first surfaced in September 2024, months after the Change Healthcare breach exposed roughly 192.7 million patient records and disrupted billing operations across the industry for weeks. It didn't advance at the time. Now, with breach volumes still near record highs and a new Congress in session, Warner and Wyden are betting that the argument for mandatory standards has only gotten stronger.

The senators' pitch rests on a simple claim: asking the healthcare industry nicely to secure itself hasn't worked, and won't. "As cybercriminals ramp up their attacks on hospitals and healthcare providers, it's becoming increasingly clear that voluntary standards are not enough to protect Americans' health, safety, and privacy," Warner said in the bill's rollout.

Wyden was more blunt, pointing directly at the industry's largest players: "Megacorporations like UnitedHealth are flunking Cybersecurity 101, and American families are suffering as a result."

The data back up the frustration, even if the exact numbers depend on who's counting. The U.S. Health and Human Services (HHS) Office for Civil Rights logged 772 large healthcare data breaches (those affecting 500 or more individuals) in 2025—a record—following 742 in 2024 and 746 in 2023, according to HIPAA Journal's tracking of the OCR breach portal. Comparitech's separate count of confirmed ransomware attacks on U.S. healthcare providers shows a similar trajectory: 84 in 2022, 143 in 2023, and 181 in 2024, exposing 25.6 million patient records in that final year alone.

And the shift in how organizations are being breached is arguably more telling than the raw counts; a mid-2026 review of the OCR portal found that 92% of large healthcare breaches reported in the first half of the year stemmed from hacking or IT incidents, versus lost laptops or misdirected mail, a category that made up a much larger share of breaches a decade ago.

The stakes go beyond exposed records. Research published in the American Economic Journal: Economic Policy in February 2026 found that in-hospital mortality for Medicare patients already admitted when a ransomware attack hits rises by 34% to 38%. That statistic is doing a lot of work in Warner's and Wyden's framing: this isn't a privacy bill dressed up as a safety bill—it's an attempt to legislate emergency-room downtime and delayed care as a cybersecurity failure with a body count.

What the legislation actually does

Strip away the press release rhetoric and the Health Infrastructure Security and Accountability Act is a two-title bill that pairs new mandates with new money.

Title I overhauls HIPAA security enforcement

Within two years of enactment, HHS would have to establish minimum cybersecurity requirements for covered entities and business associates—providers, health plans, clearinghouses, and their vendors—with enhanced requirements layered on top for organizations of "systemic importance," meaning entities whose failure would have a debilitating impact on access to care or the stability of the health system nationally. Notably, HHS's methodology for designating an entity as systemically important would not be subject to judicial review, a provision likely to draw pushback from larger health systems and vendors wary of being placed in a stricter compliance tier with no legal recourse to contest it.

Covered entities would face a growing compliance checklist: security risk analyses that account for business associate exposure, documented incident-recovery plans, annual stress tests, and—starting six months after enactment—independent third-party audits. Entities under the enhanced standard would report annually to HHS and publicly post signed attestations of compliance from their CEO and CISO. HHS itself would be required to audit at least 20 covered entities or business associates every year and report the results to Congress biennially for a decade.

The accountability piece is where the bill gets teeth. Civil penalties for violations of security standards would scale from $500 for no-fault violations up to $250,000 for uncorrected willful neglect, and separately, knowingly submitting a false compliance attestation would carry criminal penalties—the "jail time for CEOs that lie to the government," as Wyden put it. HHS would also gain authority to charge covered entities a user fee, capped at $40 million in FY2026 and $50 million in FY2027 (rising with inflation), to fund the oversight apparatus the bill creates.

Title II tries to answer the industry's oldest objection to mandates: who pays for compliance?

The bill would direct $1.3 billion through Medicare to help hospitals meet the new standards, front-loading $800 million as up-front investment payments to roughly 2,000 rural and urban safety net hospitals over an initial two-year window. A separate $500 million would follow to incentivize broader adoption of enhanced practices across all hospitals, with payment penalties kicking in for hospitals that haven't adopted enhanced practices once that two-year runway ends. The bill would also codify HHS's authority to issue accelerated and advance Medicare payments to providers when a cybersecurity incident disrupts claims processing—a direct response to the cash-flow crisis hospitals faced when Change Healthcare went down and providers went weeks without reimbursement.

The fight ahead: mandates versus 'blaming the victim'

This is the third or fourth run at mandatory federal cybersecurity standards for healthcare since 2023, and the fight lines are already well established. When HHS first floated mandatory standards and financial penalties in a December 2023 concept paper, American Hospital Association President and CEO Rick Pollack drew a line that the industry has held to ever since: "The AHA cannot support proposals for mandatory cybersecurity requirements being levied on hospitals as if they were at fault for the success of hackers in perpetrating a crime." Pollack's argument—reiterated in AHA's FY2025 HHS budget statement—is that most high-profile breaches, including Change Healthcare, trace back to third-party vendor vulnerabilities rather than hospitals' own systems, making fines and Medicare payment cuts a punishment for the victim rather than a fix for the vulnerability.

That tension hasn't gone away, and this bill doesn't fully resolve it. The enhanced-standards tier and systemic importance designation are clearly aimed at large, well-resourced entities like national payers and hospital systems rather than the rural facilities Title II's funding targets, but AHA and similar trade groups are likely to argue that the audit burden, the CEO/CISO attestation requirement, and the user-fee funding mechanism still fall hardest on providers rather than the vendors and third parties AHA has consistently pointed to as the actual point of failure.

On the other side, HHS itself has previously signaled openness to this direction: when the bill was first introduced in 2024, then-Deputy HHS Secretary Andrea Palm said "funding and voluntary goals alone will not drive the cyber-related behavioral change needed across the healthcare sector"—an unusually direct acknowledgment from within the agency that its own voluntary performance goals haven't been enough.

What it means for the healthcare security community

For CISOs and security leaders in health systems, health plans, and business associate organizations, the bill is worth tracking closely regardless of whether it clears this Congress; the direction of travel matters as much as any single bill's odds.

  • The compliance clock, if this passes, starts fast. Security risk analyses and incident recovery documentation would be due within three years of enactment; independent audit contracts within six months. Organizations that have treated HHS's current cybersecurity performance goals as aspirational should expect that grace period to shrink.

  • Third-party and business-associate risk is now explicitly in scope. The requirement to document "the manner and extent" of business-associate risk exposure formalizes what Change Healthcare made obvious: vendor risk management is no longer a side conversation from core HIPAA security compliance.

  • CEO/CISO attestation raises the personal stakes for security leadership. A signed, public compliance statement—backed by criminal penalties for knowing falsehoods—puts CISOs in a position much closer to a CFO's under Sarbanes-Oxley than most have occupied under HIPAA to date.

  • Funding timing matters for under-resourced hospitals. The $800 million safety net tranche is structured as an up-front investment before enhanced-practice penalties apply, a sequencing choice clearly designed to answer the "unfunded mandate" critique that sank momentum on this issue in 2023 and 2024.

Whether this version of the bill fares better than its 2024 predecessor will depend on the same variables that have stalled it before: whether AHA and hospital lobbyists can be brought to the table on funding mechanics, and whether Congress treats healthcare cybersecurity as urgent enough to move outside of a broader HIPAA modernization package. But with breach volumes flat-to-record and a peer-reviewed mortality link now in the public record, the political cover for continued inaction is getting thinner.

The bill's case study just kept writing itself

The same day Warner's and Wyden's office put out the bill text, HIPAA Journal published a roundup of three more healthcare hacking incidents—and one of them reads almost like a stress test of exactly the gap Title II is designed to close.

Cedar County Memorial Hospital, a small facility in El Dorado Springs, Missouri, disclosed on August 23, 2026, that a cyberattack had forced it to take its IT systems offline. The fallout was immediate and severe for a rural hospital: the patient portal and electronic health record system went down entirely, taking Medical Mall Clinic services with it, and the emergency department had to go on partial diversion because medical imaging couldn't transmit scans to radiologists. The EHR system stayed offline for two weeks before the hospital returned to routine operations on August 28, with staff manually re-entering records that had been kept on paper in the interim. A cyber extortion group calling itself Wallstreet has claimed responsibility and listed the hospital on its dark web leak site. The hospital's investigation into how much patient data were actually exposed is still ongoing as of mid-September.

Two other incidents in the same article round out the picture of where the sector's exposure actually sits. Next Level Medical, a Texas primary and urgent care operator with more than 45 clinics, disclosed that a threat group had copied files containing names, Social Security numbers, and health and insurance information after gaining network access in July. And Grafton City Hospital—a critical access hospital in West Virginia, now part of the Vandalia Health system—notified 1,215 people that a May phishing attack had compromised similar categories of data.

None of these three is a mega-breach on the scale of Change Healthcare. That's precisely why they're useful evidence for the bill's supporters and its critics alike. Cedar County Memorial is a small, resource-constrained facility—the exact profile Title II's $800 million safety net tranche is aimed at—and it still lost two weeks of EHR access and had to divert emergency patients. That's a real-world illustration of the "voluntary standards aren't enough" argument Warner and Wyden are making. But it's just as easily read as evidence for the American Hospital Association's counter-argument: a critical access hospital with limited IT staff and budget is not obviously the party best positioned to absorb new audit, attestation, and stress-testing requirements without the funding arriving first—and on the timeline the bill proposes, that funding wouldn't be guaranteed to arrive before the compliance obligations do.

Comments