Referred to the Committee on Homeland Security, and in addition to the Committee on Energy and Commerce, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
This bill strengthens cybersecurity protections for hospitals, health systems, and other healthcare organizations by requiring better coordination between the Department of Health and Human Services and the Cybersecurity and Infrastructure Security Agency. The legislation responds to a significant increase in cyberattacks on healthcare facilities—large cyber breaches of healthcare information systems rose 93 percent between 2018 and 2022, affecting nearly 42 million individuals. The bill requires several actions within specific timelines, including updating a sector-specific cybersecurity risk management plan within one year, establishing training programs for healthcare owners and operators, identifying high-risk healthcare assets, and submitting reports to Congress within 120 days to 18 months. The measure does not authorize any new federal funding and instead requires agencies to work with existing resources to improve information sharing, provide cybersecurity resources and advisors to healthcare entities, and address workforce shortages in the healthcare cybersecurity field.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.