Health-ISAC Hacking Healthcare 3-5-2026
Health-ISAC Hacking Healthcare 3-5-2026
https://health-isac.org/health-isac-hacking-healthcare-3-5-2026/
Publish Date: 2026-03-05 12:33:00
Source Domain: health-isac.org
This week, Health-ISAC®‘s Hacking Healthcare® examines a legislative bill in the United States Senate that may have the congressional support to significantly change numerous aspects of health sector cybersecurity and resiliency. Join us as we assess what the bill would do, the progress it appears to be making, and what it could mean for health sector entities in the United States if it is passed.
As a reminder, this is the public version of the Hacking Healthcare blog. For additional in-depth analysis and opinion, become a member of H-ISAC and receive the TLP Amber version of this blog (available in the Member Portal.)
Welcome back to Hacking Healthcare® !
The Health Care Cybersecurity and Resiliency Act of 2025 Makes Progress
Congressional gridlock, stymying the passage of needed legislation, has been a common lament in the United States, with recent congressional sessions seeming to be particularly ineffectual. The inability to find a path forward on the Cybersecurity Information Sharing Act of 2015 (CISA 2015) is a frustrating example of how even broadly supported legislation can become bogged down. However, recent progress on a consequential sector cybersecurity and resiliency bill is a reason for some optimism.
What Is the Health Care Cybersecurity and Resiliency Act of 2025[i]?
Previously introduced last Congress in November 2024 and reintroduced in early December 2025, the Health Care Cybersecurity and Resiliency Act of 2025 would drive numerous changes to policies, processes, and regulations for both the public and private sectors. The United States Senate Committee on Health, Education, Labor and Pensions press release[ii] from December provides a brief breakdown of some of the most important aspects of the bill, including its intent to:
- Strengthen cybersecurity in the health care sector by providing grants to health entities to improve cyberattack prevention and response.
- Provide training to health entities on cybersecurity best…