{"check":null,"uid":"7279477d292e99a8","title":"S. 3315, Health Care Cybersecurity and Resiliency Act of 2026","title_generated":false,"country":"США","organ":"Конгресс США","kind":"law","kind_name":"Законодательство","lang":"en","date":"2026-07-07","summary":"Частные организации сферы здравоохранения обяжут применять минимальный набор мер кибербезопасности, в том числе многофакторную аутентификацию. Министерство здравоохранения и социальных служб уточняет стандарты, при соблюдении которых штраф за нарушение приватности и защиты медицинских сведений смягчается, раз в два года обновляет план киберзащиты для собственного персонала, обучает кадры, консультирует сельские учреждения и назначает одного ответственного за координацию этой работы. Вместе с Агентством по кибербезопасности и защите инфраструктуры (CISA) готовится совместный план реагирования на крупные инциденты. Уведомляя пациентов об утечке медицинских данных, поставщики услуг и страховые планы обязаны указывать число пострадавших.","snippet":"","topics":["Кибербезопасность","Цифровое здравоохранение","Персональные данные"],"status":"ok","error":"","text_len":43989,"versions":2,"url":"https://www.congress.gov/bill/119-congress/s/3315","first_seen":"2026-08-19","last_checked":"2026-09-17 01:58","relevance":"hit","score":182,"query":"","source_key":"congress_us","verdict":{"relevance":"hit","score":182,"topics":["Кибербезопасность","Цифровое здравоохранение","Персональные данные"],"need_body":3,"authorities":[{"kind":"орган","name":"Cybersecurity and Infrastructure Security Agency","topic":"Кибербезопасность"},{"kind":"орган","name":"CISA","topic":"Кибербезопасность"}],"evidence":[{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":21,"ctx":"s. 3315, health care cybersecurity and resiliency act of 2026 частные организации сферы здравоохранения обяжут применять мин","zone":"название","weight":3},{"topic":"Кибербезопасность","term":"кибербезопасн","weak":false,"pos":143,"ctx":"of 2026 частные организации сферы здравоохранения обяжут применять минимальный набор мер кибербезопасности, в том числе многофакторную аутентификацию. министерство здравоохранения и социальных слу","zone":"название","weight":3},{"topic":"Персональные данные","term":"приватност","weak":true,"pos":315,"ctx":"хранения и социальных служб уточняет стандарты, при соблюдении которых штраф за нарушение приватности и защиты медицинских сведений смягчается, раз в два года обновляет план киберзащиты для с","zone":"название","weight":1},{"topic":"Кибербезопасность","term":"кибербезопасн","weak":false,"pos":573,"ctx":"ения и назначает одного ответственного за координацию этой работы. вместе с агентством по кибербезопасности и защите инфраструктуры (cisa) готовится совместный план реагирования на крупные инцидент","zone":"название","weight":3},{"topic":"Цифровое здравоохранение","term":"медицинск данн","weak":false,"pos":713,"ctx":"отовится совместный план реагирования на крупные инциденты. уведомляя пациентов об утечке медицинских данных, поставщики услуг и страховые планы обязаны указывать число пострадавших.","zone":"название","weight":3},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":20,"ctx":"summary health care cybersecurity and resiliency act of 2026 this bill expands federal requirements and resources for preve","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":147,"ctx":"026 this bill expands federal requirements and resources for preventing and responding to cybersecurity incidents in the health care and public health sectors. the bill directs the department o","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":349,"ctx":"and human services (hhs) to require private health care-related entities to adopt minimum cybersecurity practices (e.g., multifactor authentication), more specifically identify the standards fo","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":601,"ctx":"ormation privacy and security, expand and update biennially a specified plan that details cybersecurity protocols for hhs personnel, provide training and best practices to support the expansion","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":738,"ctx":"ide training and best practices to support the expansion of the workforce for health care cybersecurity, provide guidance on cybersecurity readiness to rural entities, and designate one represe","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":773,"ctx":"support the expansion of the workforce for health care cybersecurity, provide guidance on cybersecurity readiness to rural entities, and designate one representative to lead oversight and coord","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"Cybersecurity and Infrastructure Security Agency","weak":false,"pos":1748,"ctx":"lead oversight and coordination of cybersecurity activities within HHS. Also, HHS and the Cybersecurity and Infrastructure Security Agency (CISA) must coordinate to improve health care cybersecurity, including by (1) providing r","zone":"орган","weight":3},{"topic":"Кибербезопасность","term":"CISA","weak":false,"pos":616,"ctx":"оординацию этой работы. Вместе с Агентством по кибербезопасности и защите инфраструктуры (CISA) готовится совместный план реагирования на крупные инциденты. Уведомляя пациентов об утеч","zone":"орган","weight":0}],"dropped":[{"topic":"Персональные данные","term":"privacy","weak":true,"pos":520,"ctx":"ntify the standards for mitigating penalties relating to violations of health information privacy and security, expand and update biennially a specified plan that details cybersecurity pr","why":"только многозначные термины"},{"topic":"Персональные данные","term":"privacy","weak":true,"pos":12689,"ctx":"rsecurity standards.</deleted>  <deleted> (a) in general.--the secretary shall update the privacy, security, and breach notification regulations under parts 160 and 164 of title 45, code","why":"только многозначные термины"},{"topic":"Персональные данные","term":"privacy","weak":true,"pos":34245,"ctx":"mework); (c) the national institute of standards and technology sp 800-53 r5 security and privacy controls for information systems and organizations (or a successor special publication),","why":"только многозначные термины"},{"topic":"Персональные данные","term":"privacy","weak":true,"pos":34421,"ctx":"lication), with relevant components of the national institute of standards and technology privacy framework; or (d) the national institute of standards and technology artificial intellige","why":"только многозначные термины"},{"topic":"Искусственный интеллект","term":"artificial intelligence","weak":false,"pos":34498,"ctx":"d technology privacy framework; or (d) the national institute of standards and technology artificial intelligence risk management framework; (2) the health sector coordinating council cybersecurity healt","why":"одиночное упоминание (нужно 3)"},{"topic":"Искусственный интеллект","term":"artificial intelligence","weak":false,"pos":41840,"ctx":"commendations specific to rural facilities; (e) development of best practices to leverage artificial intelligence to support cybersecurity preparedness; (f) opportunities for public-private collaboration","why":"одиночное упоминание (нужно 3)"}]},"last_changed":"2026-09-11","meta":{"congress":"119","billType":"S","number":"3315","policyArea":"Health","subjects":["Administrative law and regulatory procedures","Computer security and identity theft","Computers and information technology","Congressional oversight","Department of Health and Human Services","Employment and training programs","Government information and archives","Government studies and investigations","Health programs administration and funding","Public-private cooperation","Rural conditions and development"],"latestAction":"2026-03-23 Placed on Senate Legislative Calendar under General Orders. Calendar No. 365.","textVersion":"rs"},"source_url":"https://www.congress.gov/bill/119-congress/s/3315","text":"SUMMARY\nHealth Care Cybersecurity and Resiliency Act of 2026\nThis bill expands federal requirements and resources for preventing and responding to cybersecurity incidents in the health care and public health sectors.\nThe bill directs the Department of Health and Human Services (HHS) to\nrequire private health care-related entities to adopt minimum cybersecurity practices (e.g., multifactor authentication),\nmore specifically identify the standards for mitigating penalties relating to violations of health information privacy and security,\nexpand and update biennially a specified plan that details cybersecurity protocols for HHS personnel,\nprovide training and best practices to support the expansion of the workforce for health care cybersecurity,\nprovide guidance on cybersecurity readiness to rural entities, and\ndesignate one representative to lead oversight and coordination of cybersecurity activities within HHS.\nAlso, HHS and the Cybersecurity and Infrastructure Security Agency (CISA) must coordinate to improve health care cybersecurity, including by (1) providing resources for entities receiving information from HHS or CISA programs, and (2) establishing a joint cybersecurity capability plan to coordinate responses to significant incidents.\nAdditionally, the bill requires health care providers and plans to include the number of individuals affected when notifying individuals of unauthorized access to health information (i.e., a breach).\n\nFULL TEXT\n[Congressional Bills 119th Congress]\n[From the U.S. Government Publishing Office]\n[S. 3315 Reported in Senate (RS)]\n\n<DOC>\n\nCalendar No. 365\n119th CONGRESS\n2d Session\nS. 3315\n\nTo require the Secretary of Health and Human Services and the Director\nof the Cybersecurity and Infrastructure Security Agency to coordinate\nto improve cybersecurity in the health care and public health sectors,\nand for other purposes.\n\n_______________________________________________________________________\n\nIN THE SENATE OF THE UNITED STATES\n\nDecember 2, 2025\n\nMr. Cassidy (for himself, Ms. Hassan, Mr. Cornyn, and Mr. Warner)\nintroduced the following bill; which was read twice and referred to the\nCommittee on Health, Education, Labor, and Pensions\n\nMarch 23, 2026\n\nReported by Mr. Cassidy, with an amendment\n[Strike out all after the enacting clause and insert the part printed\nin italic]\n\n_______________________________________________________________________\n\nA BILL\n\nTo require the Secretary of Health and Human Services and the Director\nof the Cybersecurity and Infrastructure Security Agency to coordinate\nto improve cybersecurity in the health care and public health sectors,\nand for other purposes.\n\nBe it enacted by the Senate and House of Representatives of the\nUnited States of America in Congress assembled,\n\n<DELETED>SECTION 1. SHORT TITLE.</DELETED>\n\n<DELETED> This Act may be cited as the ``Health Care Cybersecurity\nand Resiliency Act of 2025''.</DELETED>\n\n<DELETED>SEC. 2. DEFINITIONS.</DELETED>\n\n<DELETED> In this Act:</DELETED>\n<DELETED> (1) Agency.--The term ``Agency'' means the\nCybersecurity and Infrastructure Security Agency.</DELETED>\n<DELETED> (2) Cybersecurity incident.--The term\n``cybersecurity incident'' has the meaning given the term\n``incident'' in section 3552 of title 44, United States\nCode.</DELETED>\n<DELETED> (3) Cybersecurity state coordinator.--The term\n``Cybersecurity State Coordinator'' means a Cybersecurity State\nCoordinator appointed under section 2217(a) of the Homeland\nSecurity Act of 2002 (6 U.S.C. 665c(a)).</DELETED>\n<DELETED> (4) Director.--The term ``Director'' means the\nDirector of the Agency.</DELETED>\n<DELETED> (5) Healthcare and public health sector.--The term\n``Healthcare and Public Health Sector'' means the Healthcare\nand Public Health sector, as identified in Presidential Policy\nDirective 21 (February 12, 2013; relating to critical\ninfrastructure security and resilience).</DELETED>\n<DELETED> (6) Information sharing and analysis\norganization.--The term ``Information Sharing and Analysis\nOrganization'' has the meaning given such term in section 2200\nof the Homeland Security Act of 2002 (6 U.S.C. 650).</DELETED>\n<DELETED> (7) Information system.--The term ``information\nsystem'' has the meaning given such term in section 102 of the\nCybersecurity Information Sharing Act of 2015 (6 U.S.C.\n1501).</DELETED>\n<DELETED> (8) Secretary.--The term ``Secretary'' means the\nSecretary of Health and Human Services.</DELETED>\n\n<DELETED>SEC. 3. DEPARTMENT COORDINATION WITH THE AGENCY.</DELETED>\n\n<DELETED> (a) In General.--The Secretary and the Director shall\ncoordinate, including by entering into a cooperative agreement, as\nappropriate, to improve cybersecurity in the Healthcare and Public\nHealth Sector.</DELETED>\n<DELETED> (b) Assistance.--</DELETED>\n<DELETED> (1) In general.--The Secretary shall coordinate\nwith the Director to make resources available to entities that\nare receiving information shared through programs managed by\nthe Director or the Secretary, including Information Sharing\nand Analysis Organizations, information sharing and analysis\ncenters, and non-Federal entities.</DELETED>\n<DELETED> (2) Scope.--The coordination under paragraph (1)\nshall include--</DELETED>\n<DELETED> (A) developing products specific to the\nneeds of Healthcare and Public Health Sector entities;\nand</DELETED>\n<DELETED> (B) sharing information relating to cyber\nthreat indicators and appropriate defensive\nmeasures.</DELETED>\n\n<DELETED>SEC. 4. CLARIFYING CYBERSECURITY RESPONSIBILITIES AT THE\nDEPARTMENT OF HEALTH AND HUMAN SERVICES.</DELETED>\n\n<DELETED> Part A of title III of the Public Health Service Act (42\nU.S.C. 241 et seq.) is amended by adding at the end the\nfollowing:</DELETED>\n\n<DELETED>``SEC. 310C. OVERSIGHT OF CYBERSECURITY ACTIVITIES.</DELETED>\n\n<DELETED> ``The Secretary, acting through the Assistant Secretary\nfor Preparedness and Response, in coordination with the Director of the\nCybersecurity and Infrastructure Security Agency pursuant to section\n2218 of the Homeland Security Act of 2002, shall lead oversight and\ncoordination of activities within the Department of Health and Human\nServices to support cybersecurity resiliency within the Healthcare and\nPublic Health Sector (as defined in section 2 of the Health Care\nCybersecurity and Resiliency Act of 2025), including coordination and\ncommunication with other public and private entities related to\npreparedness for, and responses to, cybersecurity incidents, consistent\nwith applicable provisions of this Act, other applicable laws, and\nPresidential Policy Directive 21 (February 12, 2013; relating to\ncritical infrastructure security and resilience).''.</DELETED>\n\n<DELETED>SEC. 5. CYBERSECURITY INCIDENT RESPONSE PLAN.</DELETED>\n\n<DELETED> Section 405 of the Cybersecurity Act of 2015 (6 U.S.C.\n1533) is amended--</DELETED>\n<DELETED> (1) in subsection (a)--</DELETED>\n<DELETED> (A) in paragraph (4)--</DELETED>\n<DELETED> (i) in the paragraph heading, by\ninserting ``information system;'' after\n``Federal entity;''; and</DELETED>\n<DELETED> (ii) by inserting ```information\nsystem','' after ```Federal\nentity','';</DELETED>\n<DELETED> (B) by redesignating paragraphs (4)\nthrough (7) as paragraphs (6) through (9),\nrespectively; and</DELETED>\n<DELETED> (C) by inserting after paragraph (3) the\nfollowing:</DELETED>\n<DELETED> ``(4) Cybersecurity incident.--The term\n`cybersecurity incident' has the meaning given the term\n`incident' in section 3552 of title 44, United States\nCode.</DELETED>\n<DELETED> ``(5) Cybersecurity risk.--The term `cybersecurity\nrisk' has the meaning given such term in section 2200 of the\nHomeland Security Act of 2002 (6 U.S.C. 650).''; and</DELETED>\n<DELETED> (2) in subsection (d), by adding at the end the\nfollowing:</DELETED>\n<DELETED> ``(4) Plan.--</DELETED>\n<DELETED> ``(A) In general.--Not later than 1 year\nafter the date of enactment of the Health Care\nCybersecurity and Resiliency Act of 2025, the Secretary\nshall develop and implement a cybersecurity incident\nresponse plan to inform applicable personnel within the\nDepartment of Health and Human Services of processes\nand protocols to prepare for, and respond to,\ncybersecurity incidents involving information,\nincluding hardware, software, databases, and networks,\nused or maintained by, or on behalf of, the Department,\nincluding strategies--</DELETED>\n<DELETED> ``(i) to assess cybersecurity\nrisks;</DELETED>\n<DELETED> ``(ii) to prevent cybersecurity\nincidents;</DELETED>\n<DELETED> ``(iii) to detect and identify\ncybersecurity incidents;</DELETED>\n<DELETED> ``(iv) to minimize damage in the\nevent of a cybersecurity incident;</DELETED>\n<DELETED> ``(v) to protect data;\nand</DELETED>\n<DELETED> ``(vi) to recover from any\ncybersecurity incidents\nexpeditiously.</DELETED>\n<DELETED> ``(B) Consultation.--In developing the\nplan under subparagraph (A), the Secretary shall\nconsult with the Director of the Cybersecurity and\nInfrastructure Security Agency, the Director of the\nOffice of Management and Budget, and the Director of\nthe National Institute of Standards and Technology, and\nrelevant experts, as appropriate.</DELETED>\n<DELETED> ``(C) Report.--Not later than 60 days\nbefore the date on which the Secretary begins\nimplementing the plan under subparagraph (A), the\nSecretary shall submit to the Committee on Health,\nEducation, Labor, and Pensions and the Committee on\nHomeland Security and Governmental Affairs of the\nSenate and the Committee on Energy and Commerce, the\nCommittee on Oversight and Reform, and the Committee on\nHomeland Security of the House of Representatives a\nreport that describes such plan.''.</DELETED>\n\n<DELETED>SEC. 6. BREACH REPORTING PORTAL.</DELETED>\n\n<DELETED> (a) Updates to Breach Reporting Portal.--Section 13402 of\nthe HITECH Act (42 U.S.C. 17932) is amended by adding at the end the\nfollowing:</DELETED>\n<DELETED> ``(k) Updates to Regulations.--Not later than 1 year after\nthe date of enactment of the Health Care Cybersecurity and Resiliency\nAct of 2025, the Secretary shall update the regulations promulgated\npursuant to subsection (j) to require that information required to be\npublicly displayed in the breach reporting portal established pursuant\nto this section includes--</DELETED>\n<DELETED> ``(1) information on any corrective action taken\nagainst a covered entity that provided notification of a breach\nunder this section;</DELETED>\n<DELETED> ``(2) information on whether and to what extent,\nas appropriate, recognized security practices (as defined in\nsection 13412(b)(1)) were considered in the investigation of\nsuch a breach; and</DELETED>\n<DELETED> ``(3) such additional information about such a\nbreach as the Secretary may require.''.</DELETED>\n\n<DELETED>SEC. 7. CLARIFYING BREACH REPORTING OBLIGATIONS.</DELETED>\n\n<DELETED> Section 13402(f) of the HITECH Act (42 U.S.C. 17932(f)) is\namended by adding at the end the following:</DELETED>\n<DELETED> ``(6) The number of individuals affected by the\nbreach.''.</DELETED>\n\n<DELETED>SEC. 8. ENHANCING RECOGNITION OF SECURITY PRACTICES.</DELETED>\n\n<DELETED> (a) Recognized Security Practices.--Section 13412(b)(1) of\nthe HITECH Act (42 U.S.C. 17941(b)(1)) is amended, in the first\nsentence, by inserting ``, investments,'' after ``other\nprograms''.</DELETED>\n<DELETED> (b) Guidance.--Not later than 1 year after the date of\nenactment of this Act, the Secretary shall issue guidance on the\nimplementation of section 13412 of the HITECH Act (42 U.S.C. 17941),\nwhich shall include--</DELETED>\n<DELETED> (1) recognized security practices (as defined in\nsubsection (b)(1) of such section) that the Secretary may\nconsider when determining fines under such section;</DELETED>\n<DELETED> (2) the extent to which such recognized security\npractices should be in place for consideration by the\nSecretary; and</DELETED>\n<DELETED> (3) procedural requirements or information that\nshall be submitted by a covered entity or business associate\n(as such terms are defined in section 13400 of the HITECH Act\n(42 U.S.C. 17921)) to the Secretary for\nconsideration.</DELETED>\n<DELETED> (c) Annual Report.--Not later than 2 years after the date\nof enactment of this Act, and annually thereafter, the Secretary shall\ninclude in the annual report required under section 13424(a) of the\nHITECH Act (42 U.S.C. 17953(a)) information on implementation of\nsection 13412 of such Act (42 U.S.C. 17941), including an accounting of\nevery case in which the Secretary considered recognized security\npractices (as defined in subsection (b)(1) of such section) when\neffectuating audits and assessing fines under such section.</DELETED>\n\n<DELETED>SEC. 9. REQUIRED CYBERSECURITY STANDARDS.</DELETED>\n\n<DELETED> (a) In General.--The Secretary shall update the privacy,\nsecurity, and breach notification regulations under parts 160 and 164\nof title 45, Code of Federal Regulations (or any successor regulation)\nto require covered entities and business associates to adopt the\nfollowing cybersecurity practices:</DELETED>\n<DELETED> (1) Multifactor authentication, or a successor\ntechnology, for access to any information systems that may\ninclude protected health information.</DELETED>\n<DELETED> (2) Safeguards to encrypt protected health\ninformation.</DELETED>\n<DELETED> (3) Requirements to conduct audits, including\npenetration testing, to maintain the protections of information\nsystems.</DELETED>\n<DELETED> (4) Other minimum cybersecurity standards, as\ndetermined by the Secretary, in consultation with private\nsector entities, based on landscape analysis of emerging and\nexisting cybersecurity vulnerabilities and consensus-based best\npractices.</DELETED>\n<DELETED> (b) Effective Dates.--The Secretary shall specify in the\nregulations the effective date for each of the new requirements under\nthe regulations updated in accordance with subsection (a). Each such\neffective date shall provide reasonable time for the entities subject\nto the requirement to come into compliance.</DELETED>\n\n<DELETED>SEC. 10. GUIDANCE ON RURAL CYBERSECURITY READINESS.</DELETED>\n\n<DELETED> Section 405(d) of the Cybersecurity Act of 2015 (6 U.S.C.\n1533(d)) (as amended by section 5(2)) is amended by adding at the end\nthe following:</DELETED>\n<DELETED> ``(5) Rural cybersecurity guidance.--</DELETED>\n<DELETED> ``(A) Definition of rural.--In this\nparagraph, the term `rural' has the meaning given such\nterm by the Health Resources and Services\nAdministration.</DELETED>\n<DELETED> ``(B) Guidance on rural cybersecurity\nreadiness.--Not later than 1 year after the date of\nenactment of the Health Care Cybersecurity and\nResiliency Act of 2025, the Secretary shall issue\nguidance to rural entities on best practices to improve\ncyber readiness, including strategies--</DELETED>\n<DELETED> ``(i) to improve cyber\ninfrastructure, including any technical\nsafeguards to mitigate cybersecurity\nrisk;</DELETED>\n<DELETED> ``(ii) to integrate best practices\nissued by the Secretary to improve\ncybersecurity preparedness;</DELETED>\n<DELETED> ``(iii) to improve employee\npreparation to mitigate any cybersecurity\nrisks, including existing public-private\nprograms to support educational initiatives;\nand</DELETED>\n<DELETED> ``(iv) to implement policies to\nfacilitate mandatory cybersecurity incident\nreporting requirements under law.</DELETED>\n<DELETED> ``(C) GAO study and report.--</DELETED>\n<DELETED> ``(i) In general.--Not later than\n3 years after the date of enactment of the\nHealth Care Cybersecurity and Resiliency Act of\n2025, the Comptroller General of the United\nStates shall conduct, and submit to the\nCommittee on Health, Education, Labor, and\nPensions of the Senate and the Committee on\nEnergy and Commerce of the House of\nRepresentatives a report that describes the\nresults of, a study to examine how rural\nentities have implemented the recommendations\nincluded in the guidance under subparagraph\n(B).</DELETED>\n<DELETED> ``(ii) Requirements.--The study\nunder clause (i) shall assess--</DELETED>\n<DELETED> ``(I) how rural entities\nhave implemented any technical\nsafeguards and any challenges faced by\nsuch rural entities in areas for which\nsafeguards were not\nimplemented;</DELETED>\n<DELETED> ``(II) steps to further\nsupport cyber resilience for rural\nentities;</DELETED>\n<DELETED> ``(III) areas to improve\ncoordination between Federal agencies,\nincluding for the purposes of required\ncyber reporting; and</DELETED>\n<DELETED> ``(IV) any opportunities\nto support public-private collaboration\nin the area of cyber\nreadiness.''.</DELETED>\n\n<DELETED>SEC. 11. GRANTS TO ENHANCE CYBERSECURITY IN THE HEALTH AND\nPUBLIC HEALTH SECTORS.</DELETED>\n\n<DELETED> Part P of title III of the Public Health Service Act (42\nU.S.C. 280g et seq.) is amended by adding at the end the\nfollowing:</DELETED>\n\n<DELETED>``SEC. 399V-8. GRANTS.</DELETED>\n\n<DELETED> ``(a) In General.--The Secretary may award grants to\neligible entities for the adoption and use of cybersecurity best\npractices.</DELETED>\n<DELETED> ``(b) Eligible Entity.--To be eligible to receive a grant\nunder subsection (a) an entity shall be--</DELETED>\n<DELETED> ``(1) a public or nonprofit private health center\n(including a Federally qualified health center (as defined in\nsection 1861(aa)(4) of the Social Security Act));</DELETED>\n<DELETED> ``(2) a health facility operated by or pursuant to\na contract with the Indian Health Service;</DELETED>\n<DELETED> ``(3) a hospital;</DELETED>\n<DELETED> ``(4) a cancer center;</DELETED>\n<DELETED> ``(5) a rural health clinic;</DELETED>\n<DELETED> ``(6) an academic health center; or</DELETED>\n<DELETED> ``(7) a nonprofit entity that enters into a\npartnership or coordinates referrals with an entity described\nin any of paragraphs (1) through (6).</DELETED>\n<DELETED> ``(c) Use of Funds.--In adopting and using cybersecurity\nbest practices pursuant to a grant under subsection (a), an eligible\nentity may use grant funds--</DELETED>\n<DELETED> ``(1) to hire and train personnel in such\ncybersecurity best practices;</DELETED>\n<DELETED> ``(2) to update electronic data systems, such as\nby migrating to cloud based platforms;</DELETED>\n<DELETED> ``(3) to join and participate in health\ncybersecurity threat information sharing\norganizations;</DELETED>\n<DELETED> ``(4) to reduce the use of legacy systems;\nand</DELETED>\n<DELETED> ``(5) to contract with third parties to assist\nwith the activities described in paragraphs (1) through\n(5).</DELETED>\n<DELETED> ``(d) Grant Period.--The Secretary may award a grant under\nthis section for a period of not more than 3 years.</DELETED>\n<DELETED> ``(e) Application.--An eligible entity seeking a grant\nunder subsection (a) shall submit to the Secretary an application at\nsuch time, in such manner, and containing such information as the\nSecretary may require including, at a minimum a description of how the\neligible entity will establish baseline measures and benchmarks that\nmeet the Secretary's requirements to evaluate program\noutcomes.</DELETED>\n<DELETED> ``(f) Authorization of Appropriations.--There are\nauthorized to be appropriated to carry out this section such sums as\nmay be necessary for each of fiscal years 2025 through\n2030.''.</DELETED>\n\n<DELETED>SEC. 12. HEALTHCARE CYBERSECURITY WORKFORCE.</DELETED>\n\n<DELETED> (a) Training for Healthcare Experts.--The Secretary, in\ncoordination with the Cybersecurity State Coordinators of the Agency\nand private sector health care experts, as appropriate, shall provide\ntraining to Healthcare and Public Health Sector asset owners and\noperators on--</DELETED>\n<DELETED> (1) cybersecurity risks to information systems\nwithin the Healthcare and Public Health Sector; and</DELETED>\n<DELETED> (2) ways to mitigate the risks to information\nsystems in the Healthcare and Public Health Sector.</DELETED>\n<DELETED> (b) Cross-Agency Educational Tools.--</DELETED>\n<DELETED> (1) In general.--Not later than 1 year after the\ndate of enactment of this Act, the Secretary, acting through\nthe Administrator of the Health Resources and Services\nAdministration, in coordination with the Agency, shall develop\na strategic plan to support growing the cybersecurity workforce\nfor health care entities.</DELETED>\n<DELETED> (2) Inclusions.--The strategic plan under\nparagraph (1) shall include--</DELETED>\n<DELETED> (A) recommendations for existing\neducational programs that can be used to support\ncybersecurity training;</DELETED>\n<DELETED> (B) dissemination and development of\neducational materials on how to improve cybersecurity\nresilience;</DELETED>\n<DELETED> (C) development of best practices to train\nthe health care workforce on cybersecurity best\npractices; and</DELETED>\n<DELETED> (D) opportunities for public-private\ncollaboration to strengthen the cybersecurity\nworkforce.</DELETED>\n\nSECTION 1. SHORT TITLE.\n\nThis Act may be cited as the ``Health Care Cybersecurity and\nResiliency Act of 2026''.\n\nSEC. 2. DEFINITIONS.\n\nIn this Act:\n(1) Agency.--The term ``Agency'' means the Cybersecurity\nand Infrastructure Security Agency.\n(2) Business associate.--The term ``business associate''\nhas the meaning given such term in section 160.103 of title 45,\nCode of Federal Regulations (or a successor regulation).\n(3) Covered entity.--The term ``covered entity'' has the\nmeaning given such term in section 160.103 of title 45, Code of\nFederal Regulations (or a successor regulation).\n(4) Cybersecurity incident.--The term ``cybersecurity\nincident'' has the meaning given the term ``incident'' in\nsection 3552 of title 44, United States Code.\n(5) Cybersecurity state coordinator.--The term\n``Cybersecurity State Coordinator'' means a Cybersecurity State\nCoordinator appointed under section 2217(a) of the Homeland\nSecurity Act of 2002 (6 U.S.C. 665c(a)).\n(6) Director.--The term ``Director'' means the Director of\nthe Agency.\n(7) Healthcare and public health sector.--The term\n``Healthcare and Public Health Sector'' means the Healthcare\nand Public Health sector, as identified in National Security\nMemorandum-22 (April 30, 2024; relating to critical\ninfrastructure security and resilience).\n(8) Information sharing and analysis organization.--The\nterm ``Information Sharing and Analysis Organization'' has the\nmeaning given such term in section 2200 of the Homeland\nSecurity Act of 2002 (6 U.S.C. 650).\n(9) Information system.--The term ``information system''\nhas the meaning given such term in section 2200 of the Homeland\nSecurity Act of 2002 (6 U.S.C. 650).\n(10) Recognized security practices.--The term ``recognized\nsecurity practices'' has the meaning given such term in section\n13412(b)(1) of the HITECH Act (42 U.S.C. 17941(b)(1)).\n(11) Secretary.--The term ``Secretary'' means the Secretary\nof Health and Human Services.\n\nSEC. 3. DEPARTMENT COORDINATION WITH THE AGENCY.\n\n(a) In General.--The Secretary and the Director shall coordinate,\nincluding by entering into a cooperative agreement, as appropriate, to\nimprove cybersecurity in the Healthcare and Public Health Sector.\n(b) Assistance.--\n(1) In general.--The Secretary shall coordinate with the\nDirector to make resources available to entities that are\nreceiving information shared through programs managed by the\nDirector or the Secretary, including Information Sharing and\nAnalysis Organizations, sector coordinating councils, and non-\nFederal entities.\n(2) Scope.--The coordination under paragraph (1) shall\ninclude--\n(A) developing products specific to the needs of\nHealthcare and Public Health Sector entities;\n(B) sharing information relating to cyber threat\nindicators and appropriate defensive measures,\nincluding automating cyber threat information sharing,\nin a manner that adequately protects against\nunauthorized access or disclosure; and\n(C) providing technical assistance to covered\nentities and business associates to improve\ncybersecurity preparedness.\n(c) Joint Cybersecurity Planning.--\n(1) In general.--Not later than 1 year after the date of\nenactment of this Act, the Secretary and the Director shall\nestablish a joint cybersecurity capability plan to coordinate\nresponses to significant cybersecurity incidents affecting the\nHealthcare and Public Health Sector.\n(2) Elements.--The joint cybersecurity capability plan\nestablished under paragraph (1) shall include--\n(A) protocols for rapid information sharing during\nsector-wide cybersecurity incidents;\n(B) coordination mechanisms with the sector\ncoordinating council for the Healthcare and Public\nHealth Sector; and\n(C) coordination with Cybersecurity State\nCoordinators for incidents affecting multiple States.\n(3) Submission to congress.--\n(A) In general.--Not later than 1 year after the\ndate of enactment of this Act, the Secretary shall\nsubmit to the Committee on Health, Education, Labor,\nand Pensions of the Senate and the Committee on Energy\nand Commerce of the House of Representatives the final\njoint cybersecurity capability plan prepared under\nparagraph (1) and a description of how such plan\nimplements the elements required under paragraph (2).\n(B) Updates.--If the Secretary and the Director\nupdate the joint cybersecurity capability plan required\nunder this subsection, the Secretary shall submit to\nthe Committee on Health, Education, Labor, and Pensions\nof the Senate and the Committee on Energy and Commerce\nof the House of Representatives such updated plan and a\ndescription of how such plan implements the elements\nrequired under paragraph (2).\n\nSEC. 4. CLARIFYING CYBERSECURITY RESPONSIBILITIES AT THE DEPARTMENT OF\nHEALTH AND HUMAN SERVICES.\n\n(a) In General.--The Secretary shall delegate a representative to\nlead oversight and coordination of activities within the Department of\nHealth and Human Services to support internal and external\ncybersecurity resilience within the Healthcare and Public Health\nSector, including coordination and communication with other public and\nprivate entities related to preparedness for, and responses to,\ncybersecurity incidents, consistent with applicable provisions of the\nPublic Health Service Act (42 U.S.C. 201 et seq.), other applicable\nlaws, and National Security Memorandum-22 (April 30, 2024; relating to\ncritical infrastructure security and resilience). Such activities shall\nnot include implementation or enforcement of part 160 and subparts A\nand C of part 164 of title 45, Code of Federal Regulations (or\nsuccessor regulations) (commonly known as the ``HIPAA Security Rule'').\n(b) Reports.--\n(1) Report on delegation.--Not later than 60 days after\ndelegating a representative under subsection (a), and any time\na new representative is delegated under such subsection, the\nSecretary shall submit to the Committee on Health, Education,\nLabor, and Pensions of the Senate and the Committee on Energy\nand Commerce of the House of Representatives a report that\ndescribes how such representative will implement steps to\nimprove internal and external cybersecurity resilience within\nthe Healthcare and Public Health Sector.\n(2) Annual report.--Not later than 1 year after the date of\nenactment of this Act, and annually thereafter, the Secretary\nshall submit to the Committee on Health, Education, Labor, and\nPensions of the Senate and the Committee on Energy and Commerce\nof the House of Representatives a report on the state of\ncybersecurity in the Healthcare and Public Health Sector,\nincluding--\n(A) an assessment of the most significant\ncybersecurity threats and vulnerabilities facing the\nHealthcare and Public Health Sector;\n(B) a summary of major cybersecurity incidents\naffecting the Healthcare and Public Health Sector\nduring the preceding year;\n(C) an assessment of the overall cybersecurity\nposture of the Healthcare and Public Health Sector;\n(D) a description of actions taken by the\nDepartment of Health and Human Services to improve\ncybersecurity; and\n(E) recommendations to improve Healthcare and\nPublic Health Sector cybersecurity.\n\nSEC. 5. CYBERSECURITY INCIDENT RESPONSE PLAN.\n\nSection 405 of the Cybersecurity Act of 2015 (6 U.S.C. 1533) is\namended--\n(1) in subsection (a)--\n(A) in paragraph (4)--\n(i) in the paragraph heading, by inserting\n``information system;'' after ``federal\nentity;''; and\n(ii) by inserting ```information system',''\nafter ```Federal entity','';\n(B) by redesignating paragraphs (4) through (7) as\nparagraphs (6) through (9), respectively; and\n(C) by inserting after paragraph (3) the following:\n``(4) Cybersecurity incident.--The term `cybersecurity\nincident' has the meaning given the term `incident' in section\n3552 of title 44, United States Code.\n``(5) Cybersecurity risk.--The term `cybersecurity risk'\nhas the meaning given such term in section 2200 of the Homeland\nSecurity Act of 2002 (6 U.S.C. 650).''; and\n(2) in subsection (d), by adding at the end the following:\n``(4) Plan.--\n``(A) In general.--Not later than 1 year after the\ndate of enactment of the Health Care Cybersecurity and\nResiliency Act of 2026, the Secretary shall expand and\nimplement the Cyber Annex of the All Hazards Plan of\nthe Department of Health and Human Services to inform\napplicable personnel within the Department of Health\nand Human Services of processes and protocols to\nprepare for, and respond to, cybersecurity incidents.\n``(B) Scope.--The plan under subparagraph (A) shall\naddress cybersecurity incidents involving information\nsystems, including hardware, software, databases, and\nnetworks, used or maintained by, or on behalf of, the\nDepartment.\n``(C) Elements.--The plan under subparagraph (A)\nshall include strategies--\n``(i) to assess cybersecurity risks;\n``(ii) to prevent cybersecurity incidents;\n``(iii) to detect and identify\ncybersecurity incidents;\n``(iv) to minimize damage in the event of a\ncybersecurity incident;\n``(v) to protect data;\n``(vi) to recover from any cybersecurity\nincidents expeditiously; and\n``(vii) to communicate and share non-\nsensitive information about cybersecurity\nincidents with entities in the Healthcare and\nPublic Health Sector (as defined in section 2\nof the Health Care Cybersecurity and Resiliency\nAct of 2026).\n``(D) Consultation.--In developing the plan under\nsubparagraph (A), the Secretary shall consult with the\nDirector of the Cybersecurity and Infrastructure\nSecurity Agency, the Director of the Office of\nManagement and Budget, the Director of the National\nInstitute of Standards and Technology, and relevant\nexperts, as appropriate.\n``(E) Updates.--The Secretary shall review and\nupdate the plan under subparagraph (A)--\n``(i) not less frequently than once every 2\nyears; and\n``(ii) after any significant cybersecurity\nincident affecting the Department of Health and\nHuman Services or a Federal health program.\n``(F) Report.--Not later than 60 days before the\ndate on which the Secretary begins implementing the\nplan under subparagraph (A), the Secretary shall submit\nto the Committee on Health, Education, Labor, and\nPensions and the Committee on Homeland Security and\nGovernmental Affairs of the Senate and the Committee on\nEnergy and Commerce, the Committee on Oversight and\nReform, and the Committee on Homeland Security of the\nHouse of Representatives a report that describes such\nplan.''.\n\nSEC. 6. CLARIFYING BREACH REPORTING OBLIGATIONS.\n\nSection 13402(f) of the HITECH Act (42 U.S.C. 17932(f)) is amended\nby adding at the end the following:\n``(6) The number of individuals affected by the breach.''.\n\nSEC. 7. ENHANCING RECOGNITION OF SECURITY PRACTICES.\n\n(a) Recognized Security Practices.--Section 13412(b)(1) of the\nHITECH Act (42 U.S.C. 17941(b)(1)) is amended, in the first sentence,\nby inserting ``, investments,'' after ``other programs''.\n(b) Regulation.--Not later than 1 year after the date of enactment\nof this Act, the Secretary shall promulgate regulations implementing\nsection 13412 of the HITECH Act (42 U.S.C. 17941), which shall\ninclude--\n(1) recognized security practices that the Secretary may\nconsider when determining fines under such section;\n(2) the extent to which such recognized security practices\nshould be in place for consideration by the Secretary;\n(3) procedural requirements or information that shall be\nsubmitted by a covered entity or business associate to the\nSecretary for consideration; and\n(4) how the Secretary will take into account such\nrecognized security practices when determining fines, earlier\nfavorable termination of audits, or mitigating remedies that\nwould otherwise be agreed to in any agreement with respect to\nresolving potential violations of part 160 and subparts A and C\nof part 164 of title 45, Code of Federal Regulations (or\nsuccessor regulations) (commonly known as the ``HIPAA Security\nRule'') between the covered entity or business associate and\nthe Department of Health and Human Services.\n(c) Annual Report.--Not later than 2 years after the date of\nenactment of this Act, and annually thereafter, the Secretary shall\ninclude in the annual report required under section 13424(a) of the\nHITECH Act (42 U.S.C. 17953(a)) information on implementation of\nsection 13412 of such Act (42 U.S.C. 17941), including an accounting of\nevery case in which the Secretary considered recognized security\npractices when effectuating audits and assessing fines under such\nsection.\n\nSEC. 8. REQUIRED CYBERSECURITY STANDARDS.\n\n(a) In General.--The Secretary shall update the security\nregulations under part 160 and subparts A and C of part 164 of title\n45, Code of Federal Regulations (or any successor regulation), to\nrequire non-governmental entities in the Healthcare and Public Health\nSector and covered entities and business associates to adopt minimum\nrisk-based cybersecurity practices, including--\n(1) multifactor authentication, or a successor technology;\n(2) encryption of protected health information, or a\nsuccessor technology;\n(3) requirements to conduct monitoring, including\npenetration testing, to maintain the protections of information\nsystems; and\n(4) other minimum cybersecurity standards, as reflected in\nnational cybersecurity frameworks.\n(b) Requirements.--The minimum risk-based cybersecurity practices\nadopted pursuant to subsection (a) shall be based on--\n(1) national cybersecurity frameworks, as appropriate, such\nas--\n(A) the National Institute of Standards and\nTechnology Risk Management Framework (or a successor\nframework);\n(B) the National Institute of Standards and\nTechnology Cybersecurity Framework (or a successor\nframework);\n(C) the National Institute of Standards and\nTechnology SP 800-53 r5 Security and Privacy Controls\nfor Information Systems and Organizations (or a\nsuccessor special publication), with relevant\ncomponents of the National Institute of Standards and\nTechnology Privacy Framework; or\n(D) the National Institute of Standards and\nTechnology Artificial Intelligence Risk Management\nFramework;\n(2) the Health Sector Coordinating Council Cybersecurity\nHealthcare and Public Health Cybersecurity Performance Goals;\nand\n(3) the health care-specific cybersecurity performance\ngoals of the Cybersecurity and Infrastructure Security Agency.\n(c) Effective Dates.--The regulations updated in accordance with\nsubsection (a), including each new requirement established, shall take\neffect on the date that is 36 months after the date of enactment of\nthis Act.\n(d) Enforcement.--The Secretary may exercise enforcement discretion\nfor entities experiencing extraordinary circumstances in complying with\nthe requirements of subsection (a).\n\nSEC. 9. GUIDANCE ON RURAL CYBERSECURITY READINESS.\n\nSection 405(d) of the Cybersecurity Act of 2015 (6 U.S.C. 1533(d))\n(as amended by section 5(2)) is amended by adding at the end the\nfollowing:\n``(5) Rural cybersecurity guidance.--\n``(A) Definition of rural.--In this paragraph, the\nterm `rural' has the meaning given such term by the\nFederal Office of Rural Health Policy.\n``(B) Guidance on rural cybersecurity readiness.--\nNot later than 1 year after the date of enactment of\nthe Health Care Cybersecurity and Resiliency Act of\n2026, the Secretary shall issue guidance to rural\nentities on best practices to improve cybersecurity\nreadiness, including strategies--\n``(i) to improve cybersecurity\ninfrastructure, including any technical\nsafeguards to mitigate cybersecurity risk;\n``(ii) to integrate best practices issued\nby the Secretary to improve cybersecurity\npreparedness;\n``(iii) to improve workforce preparation to\nmitigate any cybersecurity risks, including\nexisting public-private programs to support\neducational initiatives;\n``(iv) to implement policies to facilitate\nmandatory cybersecurity incident reporting\nrequirements under law; and\n``(v) to explore and recommend best\npractices, including--\n``(I) outsourcing information\ntechnology and chief information\nsecurity officer functions to third\nparties on a part-time basis;\n``(II) participating in regional\nrural health care information\ntechnology management sharing programs;\nand\n``(III) migrating data to secure\ncloud-based platforms.\n``(C) Technical assistance.--The Secretary shall\nprovide technical assistance to rural entities to\nimplement the recommendations included in the guidance\nunder subparagraph (B).\n``(D) GAO study and report.--\n``(i) In general.--Not later than 3 years\nafter the date of enactment of the Health Care\nCybersecurity and Resiliency Act of 2026, the\nComptroller General of the United States shall\nconduct a study, and submit to the Committee on\nHealth, Education, Labor, and Pensions of the\nSenate and the Committee on Energy and Commerce\nof the House of Representatives a report, on\nhow rural entities have implemented the\nrecommendations included in the guidance under\nsubparagraph (B).\n``(ii) Contents.--The study under clause\n(i) shall assess--\n``(I) how rural entities have\nimplemented any technical safeguards\nand any challenges faced by such rural\nentities in areas for which safeguards\nwere not implemented;\n``(II) steps to further support\ncybersecurity resilience for rural\nentities;\n``(III) areas to improve\ncoordination between Federal agencies,\nincluding for the purposes of required\ncyber reporting; and\n``(IV) any opportunities to support\npublic-private collaboration in the\narea of cybersecurity readiness.''.\n\nSEC. 10. GRANTS TO ENHANCE CYBERSECURITY IN THE HEALTH AND PUBLIC\nHEALTH SECTORS.\n\n(a) In General.--The Secretary may award grants to eligible\nentities for the adoption and implementation of cybersecurity best\npractices.\n(b) Eligible Entity.--To be eligible to receive a grant under\nsubsection (a), an entity shall be--\n(1) a Federally qualified health center (as defined in\nsection 1861(aa)(4) of the Social Security Act (42 U.S.C.\n1395x(aa)(4)));\n(2) a health facility operated by or pursuant to a contract\nwith the Indian Health Service;\n(3) a nonprofit hospital;\n(4) a rural health clinic (as defined in section\n1861(aa)(2) of the Social Security Act (42 U.S.C.\n1395x(aa)(2))); or\n(5) a nonprofit entity that enters into a partnership or\ncoordinates referrals with an entity described in any of\nparagraphs (1) through (4).\n(c) Use of Funds.--In adopting and implementing cybersecurity best\npractices pursuant to a grant under subsection (a), an eligible entity\nmay use grant funds--\n(1) to hire individuals with demonstrated cybersecurity\nexpertise and train personnel in such cybersecurity best\npractices;\n(2) to update electronic data systems, such as by migrating\nto cloud-based platforms;\n(3) to join and participate in health cybersecurity threat\ninformation sharing organizations;\n(4) to contract with third parties to assist the eligible\nentity in carrying out the activities described in this\nsubsection;\n(5) to conduct cybersecurity risk assessments and\nvulnerability assessments; and\n(6) to develop or improve cybersecurity incident response\nplans.\n(d) Grant Period.--A grant awarded under this section shall be for\na period of not more than 3 years.\n(e) Priority.--In awarding grants under this section, the Secretary\nmay give consideration to the demonstrated need of eligible entities.\n(f) Application.--An eligible entity seeking a grant under\nsubsection (a) shall submit to the Secretary an application at such\ntime, in such manner, and containing such information as the Secretary\nmay require, including--\n(1) a description of how the eligible entity will establish\nbaseline measures and benchmarks that meet the Secretary's\nrequirements to evaluate performance outcomes; and\n(2) a strategic plan for how, after the end of the grant\nperiod, the eligible entity will sustain the activities funded\nunder the grant and continue to adopt cybersecurity best\npractices.\n(g) Authorization of Appropriations.--There are authorized to be\nappropriated to carry out this section such sums as may be necessary\nfor each of fiscal years 2026 through 2030.\n\nSEC. 11. HEALTHCARE CYBERSECURITY WORKFORCE.\n\n(a) Training for Healthcare Experts.--The Secretary, in\ncoordination with the Cybersecurity State Coordinators of the Agency,\nthe Office of the National Cyber Director, and private sector health\ncare experts, as appropriate, shall provide training to Healthcare and\nPublic Health Sector entities on--\n(1) cybersecurity risks to information systems within the\nHealthcare and Public Health Sector; and\n(2) ways to mitigate the risks to information systems in\nthe Healthcare and Public Health Sector.\n(b) Strategic Plan.--\n(1) In general.--Not later than 1 year after the date of\nenactment of this Act, the Secretary, acting through the\nAdministrator of the Health Resources and Services\nAdministration, in coordination with the Agency, shall develop\na strategic plan to support growing the cybersecurity workforce\nfor health care entities.\n(2) Contents.--The strategic plan under paragraph (1) shall\ninclude--\n(A) recommendations for existing educational\nprograms that can be used to support cybersecurity\ntraining;\n(B) dissemination and development of educational\nmaterials on how to improve cybersecurity resilience;\n(C) development of best practices to train the\nhealth care workforce on cybersecurity best practices;\n(D) development of recommendations specific to\nrural facilities;\n(E) development of best practices to leverage\nartificial intelligence to support cybersecurity\npreparedness;\n(F) opportunities for public-private collaboration\nto strengthen the cybersecurity workforce; and\n(G) alignment with the National Initiative for\nCybersecurity Education Workforce Framework.\n\nSEC. 12. CYBERSECURITY INCIDENT REPORTING COORDINATION WORKING GROUP.\n\n(a) Working Group.--\n(1) In general.--Not later than 1 year after the date of\nenactment of this Act, the Secretary shall convene a working\ngroup to examine how to streamline and reduce duplicative\nreporting for cybersecurity incidents.\n(2) Membership.--The working group described in paragraph\n(1) shall include representatives of--\n(A) the Cybersecurity and Infrastructure Security\nAgency;\n(B) the Securities and Exchange Commission;\n(C) the Office of the National Cyber Director;\n(D) the Federal Bureau of Investigation;\n(E) the Federal Trade Commission;\n(F) State attorneys general;\n(G) State health departments; and\n(H) private sector health care entities.\n(3) Conclusion.--The working group shall conclude not later\nthan 18 months after the date of the first meeting of the\nworking group.\n(b) Report.--Not later than 1 year after the conclusion of the\nworking group under subsection (a)(3), the Secretary shall submit to\nthe Committee on Health, Education, Labor, and Pensions of the Senate\nand the Committee on Energy and Commerce of the House of\nRepresentatives a report that--\n(1) identifies areas the working group has identified to\nstreamline and reduce duplicative reporting;\n(2) includes recommendations to Congress on further\nstreamlining such reporting; and\n(3) addresses coordination with State breach notification\nlaws.\nCalendar No. 365\n\n119th CONGRESS\n\n2d Session\n\nS. 3315\n\n_______________________________________________________________________\n\nA BILL\n\nTo require the Secretary of Health and Human Services and the Director\nof the Cybersecurity and Infrastructure Security Agency to coordinate\nto improve cybersecurity in the health care and public health sectors,\nand for other purposes.\n\n_______________________________________________________________________\n\nMarch 23, 2026\n\nReported with an amendment","changes":[{"id":591,"doc_id":188,"v_from":290,"v_to":13675,"detected_at":"2026-09-11 02:51:44","added":964,"removed":11,"summary":"--- \n+++ \n-Error occurred. The page you requested cannot be found.\n-\n-Please report this error to askGPO.\n-\n-Provide the following information to help us resolve this problem: the URL of the page you were trying to access, the steps you followed to produce the error, specific search or browse terms, and/or a screenshot of the page where the error occurred.\n-\n-Thank you for your patience.\n-\n-Homepage\n-\n-Search Tips\n+[Congressional Bills 119th Congress]\n+[From the U.S. Government Publishing Office]\n+[S. 3315 Reported in Senate (RS)]\n+\n+<DOC>\n+\n+Calendar No. 365\n+119th CONGRESS\n+2d Session\n+S. 3315\n+\n+To require the Secretary of Health and Human Services and the Director\n+of the Cybersecurity and Infrastructure Security Agency to coordinate\n+to improve cybersecurity in the health care and public health sectors,\n+and for other purposes.\n+\n+_______________________________________________________________________\n+\n+IN THE SENATE OF THE UNITED STATES\n+\n+December 2, 2025\n+\n+Mr. Cassidy (for himself, Ms. Hassan, Mr. Cornyn, and Mr. Warner)\n+introduced the following bill; which was read twice and referred to the\n+Committee on Health, Education, Labor, and Pensions\n+\n+March 23, 2026\n+\n+Reported by Mr. Cassidy, with an amendment\n+[Strike out all after the enacting clause and insert the part printed\n+in italic]\n+\n+_______________________________________________________________________\n+\n+A BILL\n+\n+To require the Secretary of Health and Human Services and the Director\n+of the Cybersecurity and Infrastructure Security Agency to coordinate\n+to improve cybersecurity in the health care and public health sectors,\n+and for other purposes.\n+\n+Be it enacted by the Senate and House of Representatives of the\n+United States of America in Congress assembled,\n+\n+<DELETED>SECTION 1. SHORT TITLE.</DELETED>\n+"}],"passport":{"data":{"act":{"jurisdiction":"США","title_official":"Health Care Cybersecurity and Resiliency Act of 2026","title_short":"S. 3315, Health Care Cybersecurity and Resiliency Act of 2026","level":"законопроект (сенатский билль)","date_adopted":"2025-12-02","date_in_force":"не вступил в силу","date_version":"на рассмотрении; текст с поправками от 2026-03-23","phased":"план реагирования HHS — до истечения 1 года после вступления в силу; обновление плана — не реже чем раз в 2 года; руководство по сельским организациям — до истечения 1 года; стандарты кибербезопасности вступают в силу через 36 месяцев после даты вступления закона в силу; портал уведомлений об утечках обновить до истечения 1 года; рабочая группа по отчетности — создать до истечения 1 года, завершить работу группы — не позднее 18 месяцев с первого заседания, отчет Секретаря — до истечения 1 года после завершения работы группы.","status":"законопроект: принят Сенатом (отчет комитета), ожидает дальнейших действий Конгресса","sunset":"","regulator":"Министерство здравоохранения и социальных служб США (HHS); Агентство по кибербезопасности и защите инфраструктуры (CISA) как соисполнитель координации и совместного планирования","related":"Public Health Service Act; HITECH Act (42 U.S.C. 17932, 17941, 17953); часть 160 и подразделы A и C части 164 title 45 CFR; раздел 405 Cybersecurity Act of 2015 (6 U.S.C. 1533); National Security Memorandum-22"},"goal":{"problem":"рост числа и тяжести инцидентов ИБ в здравоохранении, недостаточная готовность субъектов сектора, фрагментарность требований и отчетности","goal":"повысить устойчивость к киберрискам в здравоохранении за счет минимальных стандартов для частных организаций, смягчения штрафов при соблюдении признанных практик, подготовки персонала, поддержки сельских учреждений и межведомственной координации крупных инцидентов","targets":"внедрение MFA, шифрования PHI, аудитов/тестов на проникновение; наличие планов реагирования у федерального ведомства; регулярная актуализация каждые 2 года; публикация числа пострадавших при уведомлениях пациентов","scope":"частные организации сферы здравоохранения (covered entities и business associates), федеральные программы HHS; отдельно выделены сельские субъекты","exclusions":"требования о стандартах допускают дискрецию правоприменения для лиц в чрезвычайных обстоятельствах; внутренние процедуры HIPAA Security Rule исключены из делегируемых координационных функций представителя согласно Sec. 4(a)"},"subjects_note":{"protected":"пациенты/субъекты данных посредством более информативных уведомлений об утечках (указание числа пострадавших); сельские учреждения здравоохранения через отдельное руководство и техпомощь"},"subjects":[{"role":"регулятор","who":"Министр здравоохранения и социальных служб США (Secretary of HHS)","criteria":"федеральный орган исполнительной власти","count":"нет данных"},{"role":"разработчик","who":"частная организация сферы здравоохранения (covered entity или business associate)","criteria":"определения part 160 и §160.103 title 45 CFR","count":"нет данных"}],"norms":[{"address":"Sec. 3(c)(1)","addressee":"регулятор","essence":"Секретарь совместно с Директором CISA обязан установить совместный план возможностей по кибербезопасности для координации реагирования на значимые инциденты в секторе здравоохранения и общественного здоровья.","type":"обязанность","mechanism":"операционные издержки","cost_channel":"административные","cost_kind":"регулярные","trigger":"постоянно","sanction":"","refs":"да; взаимодействие программ обмена информацией HHS/CISA","form":"смешанная","in_force":"не позднее 1 года после вступления закона в силу","ru_analog":"требует проверки"},{"address":"Sec. 8(a)(1)","addressee":"разработчик","essence":"Должна внедрить многофакторную аутентификацию или эквивалентную технологию для доступа к информационным системам, содержащим защищенную медицинскую информацию.","type":"обязанность","mechanism":"барьер входа; операционные издержки","cost_channel":"капитальные; содержательные","cost_kind":"разовые; регулярные","trigger":"до начала деятельности; постоянно","sanction":"предусмотрена правом HHS применять меры принуждения по правилам parts 160–164 title 45 CFR","refs":"yes; national cybersecurity frameworks; NIST CSF/RMF; HHCC CHPH Performance Goals; CISA health care goals","form":"цифровая","in_force":"через 36 месяцев после вступления закона в силу","ru_analog":"ФЗ-152 подзаконные акты ФСТЭК/ФСБ предусматривают МФА для значимых объектов КИИ; отличается отраслевой детализацией и единым федеральным сроком внедрения «через 36 месяцев»"},{"address":"Sec. 8(a)(2)","addressee":"разработчик","essence":"Должна обеспечить шифрование защищенной медицинской информации или использовать эквивалентную технологию.","type":"обязанность","mechanism":"операционные издержки","cost_channel":"капитальные; содержательные","cost_kind":"разовые; регулярные","trigger":"до начала обработки; постоянно","sanction":"предусмотрено принудительное применение по действующим правилам приватности и безопасности медицинских сведений","refs":"yes; referenced frameworks above","form":"цифровая","in_force":"через 36 месяцев после вступления закона в силу","ru_analog":"требование криптографической защиты ПДн установлено законодательством РФ; отличие — привязка к PHI и конкретизация технологий актом Минздрава/HHS"},{"address":"Sec. 8(a)(3)","addressee":"разработчик","essence":"Обязана проводить мониторинг, включая тесты на проникновение, для поддержания защитных мер информационных систем.","type":"обязанность","mechanism":"операционные издержки","cost_channel":"содержательные","cost_kind":"регулярные","trigger":"постоянно","sanction":"см. общие санкции по privacy/security rules","refs":"yes; same as above","form":"цифровая","in_force":"через 36 месяцев после вступления закона в силу","ru_analog":"тестирование уязвимостей требуется для значимых объектов КИИ; отличия — охват всех covered entities/business associates без порога значимости объекта"},{"address":"Sec. 8(a)(4)","addressee":"разработчик","essence":"Должна соблюдать иные минимальные стандарты кибербезопасности, отраженные в национальных фреймворках, установленные Секретарем.","type":"обязанность","mechanism":"операционные издержки","cost_channel":"содержательные; административные","cost_kind":"регулярные","trigger":"постоянно","sanction":"предусмотренные действующими правилами enforcement measures","refs":"yes; to-be-promulgated regulations by HHS","form":"цифровая","in_force":"через 36 месяцев после вступления закона в силу","ru_analog":"требует проверки"},{"address":"Sec. 6","addressee":"разработчик","essence":"При уведомлении физических лиц об несанкционированном доступе к медицинской информации обязана указать число затронутых лиц.","type":"обязанность","mechanism":"информирование","cost_channel":"административные","cost_kind":"по событию","trigger":"по инциденту","sanction":"предусмотрены существующими нормами HITECH/HIPAA","refs":"yes; amendment to section 13402(f) HITECH Act","form":"смешанная","in_force":"по общим срокам вступления закона в силу","ru_analog":"ст. 19 ч. 7 ФЗ-152 предусматривает уведомление Роскомнадзора; прямое указание числа пострадавших пациентам в законе не закреплено единообразно — требует проверки"},{"address":"Sec. 7(b)","addressee":"разработчик","essence":"Для учета признанных практик безопасности при определении размера штрафа должна представить Секретарю требуемые сведения и подтверждения соблюдения таких практик.","type":"обязанность","mechanism":"распределение риска; операционные издержки","cost_channel":"административные; содержательные","cost_kind":"по событию","trigger":"по запросу органа/доследственная проверка","sanction":"влияет на размер санкций по existing authorities","refs":"yes; amendments to sections 13412 and 13424 HITECH Act","form":"смешанная","in_force":"регламент должен быть издан до истечения 1 года после вступления закона в силу","ru_analog":"учет добровольного устранения нарушений и принятых мер предусмотрен практикой надзора; формализованный перечень «признанных практик» с процедурной подачей документов менее типичен — требует проверки"},{"address":"Sec. 5(d)(4)(A)","addressee":"оператор\nКто именно: Секретарь HHS","essence":"Обязан разработать и реализовать расширенный план реагирования на инциденты кибербезопасности для информирования соответствующего персонала HHS о процессах и протоколах подготовки и реагирования.","type":"обязанность","mechanism":"операционные издержки","cost_channel":"административные; содержательные","cost_kind":"разовые; регулярные","trigger":"до истечения 1 года после вступления закона в силу; далее обновления не реже раза в 2 года и после значительных инцидентов","sanction":"","refs":"yes; coordination with CISA per HS Act provisions","form":"смешанная","in_force":"до истечения 1 года после вступления закона в силу","ru_analog":"планы реагирования операторов персональных данных и субъектов КИИ требуются нормативными актами РФ; отличие — фиксированная двухлетняя периодичность публичного отчета комитетам Конгресса"},{"address":"Sec. 9(B)","addressee":"оператор\nКто именно: Секретарь HHS","essence":"Обязан выпустить руководство по готовности к кибербезопасности для сельских организаций, включающее стратегии улучшения инфраструктуры, интеграции лучших практик, подготовки кадров и политик обязательной отчетности.","type":"обязанность","mechanism":"операционные издержки; информирование","cost_channel":"административные; содержательные","cost_kind":"разовые; регулярные","trigger":"до истечения 1 года после вступления закона в силу","sanction":"","refs":"yes; опирается на определение rural Федерального офиса сельской политики здравоохранения","form":"смешанная","in_force":"до истечения 1 года после вступления закона в силу","ru_analog":"методические рекомендации для медорганизаций выпускаются профильными ведомствами; отдельного акцента на сельские учреждения сопоставимого уровня нет — требует проверки"},{"address":"Sec. 10(a)–(f)","addressee":"оператор\nКто именно: Секретарь HHS","essence":"Вправо предоставлять гранты соответствующим некоммерческим и государственным медицинским организациям на внедрение лучших практик кибербезопасности при условии подачи заявки с показателями результативности и стратегией устойчивости после окончания гранта.","type":"право","mechanism":"снижение барьера входа через финансирование","cost_channel":"прямой платёж (бюджетные ассигнования)","cost_kind":"по событию","trigger":"конкурс заявок","sanction":"","refs":"yes; Social Security Act definitions for FQHCs/rural clinics","form":"смешанная\nВступление в сила: по общим срокам; ассигнования FY2026–FY2030","in_force":"","ru_analog":"субсидии и гранты Минцифры/Минздрава существуют; обязательная стратегия постгрантовой устойчивости детально прописана редко — требует проверки"},{"address":"Sec. 11(a)–(b)","addressee":"оператор\nКто именно: Секретарь HHS","essence":"Обязан организовать обучение владельцев и операторов активов сектора рискам и мерам их снижения, а также разработать стратегический план наращивания кадрового потенциала с рекомендациями по образованию, материалам, специфике сельских учреждений, применению ИИ и государственно-частному партнерству.","type":"обязанность","mechanism":"операционные издержки","cost_channel":"административные; содержательные","cost_kind":"разовые; регулярные","trigger":"план — до истечения 1 года после вступления закона в силу","sanction":"","refs":"alignment with NICE Workforce Framework","form":"смешанная","in_force":"до истечения 1 года после вступления закона в силу","ru_analog":"мероприятия нацпрограммы «Цифровая экономика» включают подготовку кадров ИБ; столь детальный секторный план с указанием тем вроде ИИ редок — требует проверки"},{"address":"Sec. 12(a)–(b)","addressee":"оператор\nКто именно: Секретарь HHS","essence":"Обязан созвать рабочую группу для анализа дублирующей отчетности по киберинцидентам и представить Конгрессу рекомендации по ее упрощению и согласованию с законами штатов.","type":"обязанность","mechanism":"операционные издержки","cost_channel":"административные","cost_kind":"разовые","trigger":"создание — до истечения 1 года; завершение работы группы — не позднее 18 месяцев с первого заседания; доклад — до истечения 1 года после завершения","sanction":"","refs":"interagency membership including SEC, FBI, FTC, State AGs","form":"смешанная","in_force":"указанные выше сроки","ru_analog":"работа по снижению дублирования отчетности ведется регуляторами; постоянной рабочей группы такого состава законом не предусмотрено — требует проверки"}]},"made_by":"GigaChat-3-Ultra","made_at":"2026-09-16 08:06:21","edited_at":null,"edited_by":null}}