This bill requires the Department of Health and Human Services and the Cybersecurity and Infrastructure Security Agency to coordinate efforts to improve cybersecurity protections in the health care and public health sectors. Key provisions include developing a cybersecurity incident response plan within one year, updating breach notification requirements to include more detailed information about data breaches and corrective actions taken, and establishing mandatory cybersecurity standards such as multifactor authentication and data encryption for health care entities. The bill also authorizes grants through fiscal year 2030 to help health centers, hospitals, rural clinics, and other eligible health care organizations adopt cybersecurity best practices, and directs the creation of training programs and a workforce development plan to build cybersecurity expertise in the health care industry. Additionally, the legislation requires guidance specifically for rural health entities to help them improve cyber readiness and establish a Government Accountability Office study to assess rural implementation efforts.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.