Referred to the Committee on Homeland Security, and in addition to the Committee on Energy and Commerce, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
The Healthcare Cybersecurity Act of 2025 aims to strengthen cybersecurity protections for hospitals, clinics, and other healthcare facilities facing a sharp rise in cyberattacks. The bill requires the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services to work together by appointing a dedicated liaison, sharing threat information, and providing training to healthcare organizations on cybersecurity risks and defenses. Within one year, the agencies must update a sector-wide risk management plan that evaluates cybersecurity challenges facing healthcare providers—particularly rural and small facilities—workforce shortages, and best practices for responding to attacks. The legislation also directs the agencies to identify high-risk healthcare assets and prioritize federal resources to protect them, while requiring reports to Congress on implementation progress and available federal support. Importantly, the bill does not authorize any new federal spending and includes protections to ensure the agencies cannot take unauthorized actions or violate constitutional rights.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.