Requires healthcare providers to boost cybersecurity, protecting patient data from cyberattacks.
This bill would strengthen cybersecurity for hospitals, clinics, and other healthcare providers across the country. It would require them to adopt new security measures and improve how they report data breaches, aiming to better protect your personal health information. The bill also sets aside money for healthcare groups to upgrade their systems and train staff.
Today, cybersecurity coordination between the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA) for healthcare is not explicitly mandated. Also, HHS's lead role is not clearly defined. Breach reporting regulations may lack specific details on corrective actions or the number of affected individuals. Additionally, there are no explicit federal grants for healthcare cybersecurity adoption or specific guidance for rural entities. After this bill, HHS and CISA would be required to formally coordinate. HHS would also have a clarified lead role in healthcare cybersecurity and would develop a comprehensive cybersecurity incident response plan. Breach reporting regulations would be updated to include more detailed information. Mandatory cybersecurity standards would be established for healthcare entities, and grants would be authorized for cybersecurity adoption. Additionally, specific guidance for rural entities and a strategic plan for the healthcare cybersecurity workforce would be required.
S 3315 · 119th Congress · December 2, 2025 · AI Summary by gemini-2.5-flash · 8/10
Sign in to see your representatives' phone numbers
12 filings mentioned this bill
Amounts reflect total quarterly lobbying spend reported to the Senate, not bill-specific spending. Source: Senate LDA filings.