Senate passes healthcare cybersecurity bill after 190 million impacted by Change Healthcare breach
What happened
Senate passed a healthcare cybersecurity bill that was introduced in the wake of the ransomware (software that locks up files and demands payment) attack on Change Healthcare, which exposed the sensitive healthcare information of 190 million people. The bill was introduced by Senator Bill Cassidy (R-LA) but had bipartisan backing from Sens.
“Cyberattacks can shut down hospitals and expose patients' private medical records,” Cassidy said. The Health Care Cybersecurity and Resiliency Act of 2026 was passed by unanimous consent last week, potentially expanding federal cyber requirements for healthcare organizations.
The bill also orders HHS to work with the Cybersecurity and Infrastructure Security Agency (CISA) to provide cybersecurity information for healthcare entities and create a joint cyber plan to coordinate responses to significant incidents. Healthcare companies will also be forced to include the total number of data breach (an incident in which data leaves an organisation without permission) victims when notifying people about unauthorized access to their health information.
Key facts
- Senate passed a healthcare cybersecurity bill that was — introduced: in the wake of the ransomware attack on Change Healthcare, which exposed the sensitive healthcare information of 190 million people
- The bill was — introduced: by Senator Bill Cassidy (R-LA) but had bipartisan backing from Sens
Sources & evidence
- The Record Reporting source
Senate passes healthcare cybersecurity bill after 190 million impacted by Change Healthcare breach ↗
https://therecord.media/senate-passes-healthcare-cyber-bill-after-change-breach