For more than two decades, the Health Insurance Portability and Accountability Act (HIPAA) Security Rule was a risk-based framework, not a prescriptive one. The rule required organizations to protect health information but left them flexibility in how to do it: encryption was only "addressable," meaning an organization could document a reasonable alternative; the rule didn't mention multifactor authentication; and penetration testing had no mandated cadence. That design was deliberate, meant to accommodate a sprawling, heterogeneous industry. On September 30, the Senate took a step that could end much of that flexibility.
The Health Care Cybersecurity and Resiliency Act of 2026 passed the Senate by unanimous consent, after clearing the Senate HELP Committee on a 22–1 vote in February. Senator Rand Paul cast the lone dissenting vote. The bill now goes to the House, where the Energy and Commerce Subcommittee on Health held a hearing on September 15 that also considered companion rural hospital legislation. No markup is scheduled yet.
Section 8 of the bill directs HHS to mandate multifactor authentication across systems accessing personal health information, encryption of PHI at rest and in transit, regular penetration testing, monitoring, and alignment with NIST cybersecurity frameworks. The implementation window is 36 months post-enactment. For organizations that used HIPAA's addressability provisions to defer certain controls, the window may prove tighter than it appears.
The cost picture is also uneven. HHS estimated that its December 2024 HIPAA Security Rule update, which would also move HIPAA away from its risk-based heritage to more prescriptive controls, would cost the industry roughly $9 billion in the first year, a figure tied to that broader regulatory rewrite, not to S. 3315. The Congressional Budget Office, scoring only the Senate bill, projected $421 million in total implementation costs from 2026 to 2031. These figures do measure different things and should not be read as competing estimates.
S. 3315 authorizes grants for rural health clinics, federally qualified health centers, Indian Health Service facilities, and nonprofit hospitals; for-profit hospitals are not eligible. The bill does not set a fixed grant amount, leaving that to appropriators. That weighs on rural and under-resourced nonprofit providers with a statutory compliance obligation, a 36-month clock,36-month clock and no guaranteed funding.
Greg Garcia, executive director for cybersecurity at the Health Sector Coordinating Council, made that case at the September 15 House subcommittee hearing. He warned that rural and resource-constrained providers face exceptional exposure and need sustained, coordinated government support. He cautioned Congress against embedding specific technology requirements, such as multifactor authentication and encryption, in statute. Technical guidance, he argued, belongs in industry frameworks that can be updated as threats evolve.
However, under the risk-based rules, the healthcare sector has been repeatedly hit by breaches: Change Healthcare, Kaiser Foundation Health Plan, Ascension, and a string of lesser-known hospital systems have all disclosed major incidents over the past few years. Change Healthcare was a critical moment. The breaches exposed gaps in implementation and oversight across the ecosystem.
The third-party gap and credits for good behavior
Does S. 3315 give third-party healthcare data holders a pass? The American Hospital Association's September 15 testimony thinks so, and urged Congress to add a definition for third parties in Sections 2 and 8. The AHA argued that vendors handling health information should face the same compliance obligations as covered entities and business associates. For instance, the Change Healthcare ransomware attack affected approximately 190 million individuals.
Separately, many contend that regulations too heavily weighted toward prescriptive controls are unworkable in healthcare delivery environments. Sahan Fernando, CISO at Rady Children's Hospital–San Diego, told HealthSystemCIO that "It's great to say 'have MFA everywhere,' but that should also be informed by people who've actually had to put in MFA everywhere, and what that actually means." He also told the publication affordability will also be an issue for many organizations.
The Senate bill isn't all stick. Section 7 expands an existing HITECH Act safe harbor by requiring HHS to issue regulations on recognized security practices, now explicitly including investments, and to report annually on how it applies them. Organizations that document those practices for at least 12 consecutive months before an incident can already qualify for reduced penalties, shorter audits, or mitigated remedies; S. 3315 would make that process concrete. The documentation clock starts at implementation, not enactment, so organizations that begin building that audit record now are better positioned regardless of how long the House takes.
The Senate bill isn't all stick. Section 7 of the bill includes a carrot: an enforcement-credit mechanism that lets organizations document recognized security practices implemented and maintained for at least 12 consecutive months before an incident and then qualify for reduced HHS enforcement penalties, including potential mitigation of fines and early termination of audits. The documentation clock starts at implementation, not at enactment. Organizations that begin building that audit record now, before the House acts, are better positioned regardless of how long the legislative process takes.
If passed, a regulatory reconciliation may be needed. The pending HIPAA Security Rule update, proposed by HHS in December 2024, already moved toward more prescriptive requirements. However, that rulemaking has since been delayed to at least July 2027; whether HHS reconciles the two tracks or allows them to run in parallel remains unresolved.
Regardless, CISOs and executive leadership at covered organizations must read the regulatory room. A unanimous Senate vote with bipartisan sponsors, Cassidy and Cornyn on the Republican side, Hassan and Warner on the Democratic side, is not a passing political signal. The named controls in this bill are where federal healthcare cybersecurity policy is heading: The question for covered organizations is whether they can afford to wait to get moving.
