POLISCOPE
Back to feed
FEDERALcongressional record
High Impact

Health Care Cybersecurity and Resiliency Act of 2026

Original title: Text of Senate Amendment 6445

June 24, 2026

Track this bill to get notified when it advances a stage. One tap to stop, anytime.

The Frame

What this does

If enacted, this bill would require all non-governmental healthcare entities to implement mandatory cybersecurity standards by 2029, while providing new federal grant funding to assist rural and nonprofit facilities with the costs of these upgrades.

Who is mentioned in the record

Potentially affected actors named in the source documents. Mention is not a position.

Non-governmental healthcare entities

These entities must adopt new minimum risk-based cybersecurity standards and comply with updated reporting requirements.

Rural health clinics

These facilities are eligible for new federal grants and will receive specific guidance on cybersecurity readiness.

Department of Health and Human Services

The agency is tasked with creating new regulations, managing grant programs, and coordinating with other federal agencies on cybersecurity.

What changed

Last recorded activity June 24, 2026.

What's next

Next step not available in the current record.

Summary

This proposed legislation mandates new cybersecurity standards for the healthcare industry, requiring hospitals and health providers to adopt specific risk-based protections like and data encryption. It also establishes federal grant programs to help rural and nonprofit health facilities upgrade their digital infrastructure and creates new coordination protocols between the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA).

Key Facts

You don't have to trust us. Each fact below is taken straight from the official document - click any one to see the exact passage, highlighted in the original.

Frequently Asked Questions

Will my doctor's office be required to change their computer security?
Yes, if they are a non-governmental healthcare entity, they will be required to adopt minimum risk-based cybersecurity practices, such as and data encryption, within 36 months of the bill's enactment.
Is there financial help available for small or rural clinics to meet these new rules?
Yes, the bill authorizes the Secretary of HHS to award grants to eligible entities, including rural health clinics and nonprofit hospitals, to help cover the costs of hiring experts, updating data systems, and conducting risk assessments.

Why It Matters

If enacted, this bill would require all non-governmental healthcare entities to implement mandatory cybersecurity standards by 2029, while providing new federal grant funding to assist rural and nonprofit facilities with the costs of these upgrades.

News Coverage

No news coverage found yet. Articles are indexed twice daily.

Sponsors

Discoveries

Patterns POLISCOPE noticed across the record. These are observations to investigate, not conclusions.

policy shift100% confidence

Mandatory Cybersecurity Standards

The bill shifts from voluntary cybersecurity guidance to mandatory risk-based standards for the healthcare sector, enforced by HHS.

Connected Entities

personComptroller General of the United StatesOfficial responsible for conducting a study on rural cybersecurity implementatioMap →
organizationCommittee on Energy and Commerce of the House of RepresentativesCongressional committee receiving reports and plans.Map →
organizationDepartment of Health and Human ServicesPrimary federal agency responsible for implementing the new cybersecurity regulaMap →
personMr. CassidySenator who submitted the amendment.Map →
organizationCommittee on Health, Education, Labor, and Pensions of the SenateCongressional committee receiving reports and plans.Map →
organizationCybersecurity and Infrastructure Security AgencyFederal agency tasked with coordinating cybersecurity efforts with HHS.Map →

Sources

Open source document

www.govinfo.gov

Analysis Score

0–100
  • Significance85
    How much this matters to a regular citizen
  • Controversy20
    Intensity of disagreement among stakeholders
  • Entertainment5
    Compellingness for a non-policy-wonk reader
  • Buzz30
    Current news / social attention level

Publisher tools

Share or embed this record

POLISCOPE publisher tools

Share or embed this record