Legis Daily

Healthcare Cybersecurity Act of 2025

USA119th CongressS-1851| Senate 
| Updated: 5/21/2025
Jacky Rosen

Jacky Rosen

Democratic Senator

Nevada

Cosponsors (3)
Thomas Tillis (Republican)Todd Young (Republican)Angus S. King (Independent)

Homeland Security and Governmental Affairs Committee

  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted
This legislation, known as the Healthcare Cybersecurity Act of 2025, seeks to significantly enhance the cybersecurity posture of the Healthcare and Public Health Sector . It addresses the growing threat of malicious cyberattacks, which have led to substantial data breaches, increased healthcare costs, and adverse impacts on patient health outcomes, as highlighted by recent findings of Congress. A core provision establishes a formal coordination mechanism between the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS). This includes the appointment of a dedicated CISA liaison to HHS , tasked with facilitating threat information sharing, supporting the sector's risk management plan, and coordinating incident response. CISA is also directed to provide essential cybersecurity training to owners and operators of healthcare assets, covering risks and mitigation strategies. Furthermore, the bill mandates that HHS, in coordination with CISA, update the Healthcare and Public Health Sector-specific Risk Management Plan within one year. This updated plan must analyze cyber risks, evaluate challenges faced by healthcare entities in securing systems and medical devices, assess workforce shortages, and recommend best practices for utilizing CISA resources. The Secretary of HHS may also establish criteria to identify and list high-risk covered assets , enabling prioritized resource allocation to bolster their cyber resilience. Importantly, the bill specifies that no additional funds are authorized for its implementation.
View Full Text

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline

Bill from Previous Congress

S 117-3904
Healthcare Cybersecurity Act of 2022

Bill from Previous Congress

S 118-4697
Healthcare Cybersecurity Act of 2024
May 21, 2025
Introduced in Senate
May 21, 2025
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Jun 9, 2025

Latest Companion Bill Action

HR 119-3841
Introduced in House
  • Bill from Previous Congress

    S 117-3904
    Healthcare Cybersecurity Act of 2022


  • Bill from Previous Congress

    S 118-4697
    Healthcare Cybersecurity Act of 2024


  • May 21, 2025
    Introduced in Senate


  • May 21, 2025
    Read twice and referred to the Committee on Homeland Security and Governmental Affairs.


  • June 9, 2025

    Latest Companion Bill Action

    HR 119-3841
    Introduced in House

Health

Related Bills

  • HR 119-3841: Healthcare Cybersecurity Act of 2025

Healthcare Cybersecurity Act of 2025

USA119th CongressS-1851| Senate 
| Updated: 5/21/2025
This legislation, known as the Healthcare Cybersecurity Act of 2025, seeks to significantly enhance the cybersecurity posture of the Healthcare and Public Health Sector . It addresses the growing threat of malicious cyberattacks, which have led to substantial data breaches, increased healthcare costs, and adverse impacts on patient health outcomes, as highlighted by recent findings of Congress. A core provision establishes a formal coordination mechanism between the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS). This includes the appointment of a dedicated CISA liaison to HHS , tasked with facilitating threat information sharing, supporting the sector's risk management plan, and coordinating incident response. CISA is also directed to provide essential cybersecurity training to owners and operators of healthcare assets, covering risks and mitigation strategies. Furthermore, the bill mandates that HHS, in coordination with CISA, update the Healthcare and Public Health Sector-specific Risk Management Plan within one year. This updated plan must analyze cyber risks, evaluate challenges faced by healthcare entities in securing systems and medical devices, assess workforce shortages, and recommend best practices for utilizing CISA resources. The Secretary of HHS may also establish criteria to identify and list high-risk covered assets , enabling prioritized resource allocation to bolster their cyber resilience. Importantly, the bill specifies that no additional funds are authorized for its implementation.
View Full Text

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline

Bill from Previous Congress

S 117-3904
Healthcare Cybersecurity Act of 2022

Bill from Previous Congress

S 118-4697
Healthcare Cybersecurity Act of 2024
May 21, 2025
Introduced in Senate
May 21, 2025
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Jun 9, 2025

Latest Companion Bill Action

HR 119-3841
Introduced in House
  • Bill from Previous Congress

    S 117-3904
    Healthcare Cybersecurity Act of 2022


  • Bill from Previous Congress

    S 118-4697
    Healthcare Cybersecurity Act of 2024


  • May 21, 2025
    Introduced in Senate


  • May 21, 2025
    Read twice and referred to the Committee on Homeland Security and Governmental Affairs.


  • June 9, 2025

    Latest Companion Bill Action

    HR 119-3841
    Introduced in House
Jacky Rosen

Jacky Rosen

Democratic Senator

Nevada

Cosponsors (3)
Thomas Tillis (Republican)Todd Young (Republican)Angus S. King (Independent)

Homeland Security and Governmental Affairs Committee

Health

Related Bills

  • HR 119-3841: Healthcare Cybersecurity Act of 2025
  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted