S. 3315119th CongressPlaced on the calendarLatest action Mar 23, 2026Decoded by AI · checked against the record
Official title: Health Care Cybersecurity and Resiliency Act of 2026
Introduced:
Read the official bill on Congress.govThe plain-language version leads. The official text is always the reference.
S 3315 would require healthcare organizations nationwide to meet new cybersecurity standards, including multi-factor authentication and data encryption.
55-second read · 5 questions answered below
S 3315 directs HHS and CISA to coordinate more closely, share cyber threat information, and build a formal response plan for healthcare cyberattacks. The bill sets required security standards for healthcare entities, including multi-factor authentication and encryption of patient health information. It also updates the public breach reporting database to require more detail, such as patient counts affected and corrective actions taken.
Hospitals, rural health clinics, community health centers, academic medical centers, Indian Health Service facilities, and healthcare workers would all be subject to the new rules or affected by related training requirements. Patients nationwide would fall under the expanded protections for personal medical records.
Organizations that already meet strong security standards may receive more favorable treatment when fines are assessed after a breach, creating a compliance incentive. Rural providers, who typically have fewer resources, receive targeted guidance and would be subject to a government study assessing their ability to meet the new requirements.
AI-drafted summary. Verify it against the official text before you act on it. Read the official bill on Congress.gov
Right now: it was placed on the Senate floor calendar, and the official record shows no floor action on it since. If the House changes it, it goes back to the Senate before reaching the President.
Latest action: — Placed on Senate Legislative Calendar under General Orders. Calendar No. 365.