The Healthcare Cybersecurity Act of 2025 establishes a coordinated federal effort to strengthen cybersecurity protections for hospitals, clinics, and other healthcare facilities. The bill requires the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services to work together by appointing a liaison to share threat information, coordinate incident response, and provide training to healthcare providers on cybersecurity risks and defenses. Within one year, the agencies must develop a comprehensive risk management plan addressing cybersecurity challenges specific to healthcare, including vulnerabilities in medical devices, staffing shortages, and support needs for rural and smaller healthcare organizations. The bill also directs the agencies to identify high-risk healthcare facilities and use that information to prioritize federal resources, while requiring reports to Congress on assistance provided and available federal support. The legislation contains no new funding authorization and includes protections ensuring the agencies do not exceed their existing legal authorities or violate constitutional rights.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.