Senators Reintroduced Hospital Cybersecurity Legislation
The proposed Health Infrastructure Security and Accountability Act aims to bolster digital defenses across U.S. hospitals.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Should hospitals be required by federal law to meet specific cybersecurity standards?
Democratic senators have reintroduced the Health Infrastructure Security and Accountability Act to improve cybersecurity in the healthcare sector. The legislation proposes $1.3 billion in total federal funding to help hospitals defend against increasingly frequent and sophisticated cyberattacks.
Why it matters
Voluntary cybersecurity standards have proven insufficient to protect patient health, safety, and privacy in an era of rising digital threats. This bill seeks to formalize federal requirements and provide financial support for system upgrades.
The bill allocates $800 million in upfront payments to 2,000 safety net hospitals and $500 million to complying Medicare facilities. It mandates that HHS adopt minimum cybersecurity standards for covered entities within two years.
The players
Mark Warner
Mark Warner is a Democratic U.S. Senator representing Virginia who serves on the Senate Select Committee on Intelligence.
Ron Wyden
Ron Wyden is a Democratic U.S. Senator representing Oregon who serves as the chairman of the Senate Finance Committee.
The details
The legislation requires healthcare entities to perform and document a security risk analysis within three years of adoption. It also establishes a framework for civil penalties regarding noncompliance and introduces a capped user fee for healthcare providers.
Timeline
September 2026: Senators reintroduced the Health Infrastructure Security and Accountability Act.
2024: Senators introduced an earlier version of the bill.
Within two years: HHS must adopt new minimum cybersecurity standards.
Within three years: Entities must document compliance and security risk analysis.
Early December 2026: Earliest expected window for new federal legislation passage.
The Tech Race
This legislation marks a transition from voluntary guidance to a mandatory federal regulatory regime for hospital digital security. It parallels broader efforts to modernize the Health Insurance Portability and Accountability Act of 1996 to address contemporary digital vulnerabilities.
Patients may see improved stability and data protection for their medical records as hospitals implement these mandatory security standards. The bill also provides funding to safety net hospitals to ensure services remain accessible while systems are upgraded.
The takeaway
The proposed shift to mandatory cybersecurity protocols underscores that basic data hygiene is now a critical component of medical infrastructure. Hospitals should prepare to undergo security risk assessments to remain compliant with the coming regulatory changes.
Further reading
Learn more about evolving digital threats to medical facilities in our Cybersecurity section.
Live Poll
Should hospitals be required by federal law to meet specific cybersecurity standards?










