Two U.S. senators reintroduced legislation that would establish and enforce minimum cybersecurity standards across the American health care system, including healthcare providers, health plans, clearinghouses and business associates. The Health Infrastructure Security and Accountability Act would require covered entities to conduct security risk analyses, develop plans for responding to cyber incidents, natural disasters and technology failures, conduct stress tests of their ability to recover essential functions, and undergo independent security audits. The bill would impose enhanced cybersecurity requirements on entities deemed systemically important or critical to national security.
Introduced by Mark Warner, a Virginia Democrat, and Ron Wyden, an Oregon Democrat, the legislation would provide US$1.3 billion in funding to strengthen health care cybersecurity, including $800 million in upfront payments over two years for 2,000 rural and urban safety-net hospitals to adopt essential cybersecurity standards. Another $500 million would be available to incentivize hospitals to implement enhanced cybersecurity practices addressing known vulnerabilities in data infrastructure and patient health information.
The bill would also require the Department of Health and Human Services to update cybersecurity standards at least every two years and conduct annual audits of at least 20 covered entities or business associates.
“Cyberattacks on our health care system compromise Americans’ most sensitive personal information, delay essential medical care, and put lives at risk,” Warner said in a media statement. “As cybercriminals ramp up their attacks on hospitals and health care providers, it’s becoming increasingly clear that voluntary standards are not enough to protect Americans’ health, safety, and privacy. This legislation would establish strong, commonsense cybersecurity protocols for health care entities, while also getting resources to rural and underserved hospitals to strengthen their defenses and protect the patients who depend on them.”
“Americans share their most sensitive personal information with their health care providers, and in return they expect every effort to be made to keep it secure,” said Wyden. “The frequency and sophistication of cyberattacks has dramatically increased in every part of the health care system, and will only grow.”
He added, “Our bill creates national cybersecurity standards for health care providers and devotes resources, especially in rural and underserved areas, to ensure every American’s medical information is secure. Congress cannot wait to act until another catastrophic cyberattack compromises the safety and privacy of American families’ most personal information.”
The Health Infrastructure Security and Accountability Act prescribes security risk management, reporting requirements, and audits for covered entities and business associates. Not later than three years after enactment, covered entities and business associates would be required to, at a minimum, conduct and document a security risk analysis that includes the manner and extent to which the entity or associate is exposed to risk through its business associates.
They would also be required to document a plan for the rapid and orderly resolution of a natural disaster, disruptive cyber incident or other technological failure affecting their information systems or those of their business associates; conduct a stress test to evaluate whether they have the capabilities and planning needed to recover essential functions; document any changes made to the resolution plan based on the stress test; and provide a written statement signed by the chief executive officer and chief information security officer attesting that the company complies with applicable security standards and requirements.
The Secretary would be required to establish at least two conditions for the stress test. Entities and associates subject to enhanced security requirements would have to submit the required documentation to the Secretary annually, while all other entities would provide requested documentation. Covered entities and business associates would also be required to post their written compliance statements on a public website. The Secretary could waive the reporting requirements if the burden significantly outweighs the benefits, taking into consideration the entity or associate’s revenue, the volume of protected health information retained, or volume of healthcare transactions processed.
Not later than six months after enactment, covered entities and business associates would be required to contract with an independent auditor that meets requirements established by the Inspector General to assess compliance with security requirements. Before the minimum security requirements take effect, covered entities and business associates would also have to assess their compliance with the HHS cybersecurity performance goals. Entities and business associates subject to enhanced standards would be required to submit their audit findings to the Secretary, who could waive this requirement if the burden significantly outweighs the benefits.
The Secretary would be required to annually audit the data security practices of at least 20 covered entities or business associates. In selecting entities for audit, the Secretary would consider whether an entity is of systemic importance, complaints concerning its data security practices and its history of previous violations. The Secretary would submit reports to Congress every two years for 10 years summarizing the audit results. The Secretary could waive this requirement if the burden on the covered entity or business associate significantly outweighs the benefits.
Failure to comply with these requirements, as well as the responsibilities of covered entities and business associates, would be subject to fines of no more than $5,000 per day. Individuals who knowingly submit a report containing false information would also face criminal penalties.
The legislation also calls for increased civil penalties for failure to comply with security standards and requirements for health information. It would establish civil monetary penalties for violations of the security standards and requirements, including a minimum of $500 for violations committed without knowledge, $5,000 for reasonable cause, $50,000 for willful neglect that is corrected, and $250,000 for willful neglect that remains uncorrected. In determining penalties, the Secretary may consider an entity’s size, compliance history and good-faith efforts to comply with security requirements.
Section 104 of the Health Infrastructure Security and Accountability Act would establish a user fee to support data security oversight and enforcement activities. It authorizes the Secretary to charge each covered entity and business associate a fee equal to its pro rata share of national health expenditures. The aggregate fees could not exceed the lesser of the estimated cost of carrying out oversight and enforcement activities under Section 1173(d) or $40 million in fiscal year 2026 and $50 million in fiscal year 2027, with the cap increasing in subsequent years based on the Consumer Price Index.
The Health Infrastructure Security and Accountability Act also addressed medicare assistance to address cybersecurity incidents. It proposed a Medicare safe cybersecurity practices adoption program for eligible hospitals and critical access hospitals. The section would provide $800 million in upfront investment payments over two years for 2,000 rural and urban safety-net hospitals to adopt essential cybersecurity standards addressing high-risk vulnerabilities to data infrastructure and patient health information.
It would also provide $500 million to incentivize all hospitals to adopt enhanced cybersecurity practices addressing known vulnerabilities to data infrastructure and patient health information. The funding would become available after the two-year period during which rural and urban safety-net hospitals receive upfront payments. Hospitals that fail to adopt the enhanced practices after two years would be subject to a payment penalty.
Section 202 would codify the Secretary’s authority to provide accelerated and advance payments to Part A and Part B providers when they experience a significant cash-flow problem resulting from the operations of their Medicare Administrative Contractor or unusual circumstances affecting their operations, including significant disruptions to Medicare claims processing caused by a cybersecurity incident.


