S 3315 119th Congress
Health Care Cybersecurity and Resiliency Act of 2026
A bill to require the Secretary of Health and Human Services and the Director of the Cybersecurity and Infrastructure Security Agency to coordinate to improve cybersecurity in the health care and public health sectors, and for other purposes.
Official Title as Introduced Congress.gov
Open official Congress.gov recordSource-linked procedural record
Bill journey
This is a chronology, not a progress score. Politically.com does not classify stages or infer what comes next. Records sharing a date are grouped because not every source field supplies a time.
-
Introduction Congress.gov
Introduced
Introduced in the Senate.
Open bill recordOfficial action Congress.gov
Read twice and referred to the Committee on Health, Education, Labor, and Pensions.
Open bill recordOfficial action Congress.gov
Introduced in Senate
Open bill recordText version Congress.gov
Introduced in Senate
A dated text-version record is available.
Open text record -
Official action Congress.gov
Committee on Health, Education, Labor, and Pensions. Ordered to be reported with an amendment in the nature of a substitute favorably.
Open bill record -
Official action Congress.gov
Placed on Senate Legislative Calendar under General Orders. Calendar No. 365.
Open bill recordOfficial action Congress.gov
Committee on Health, Education, Labor, and Pensions. Reported by Senator Cassidy with an amendment in the nature of a substitute. Without written report.
Open bill recordOfficial action Congress.gov
Committee on Health, Education, Labor, and Pensions. Reported by Senator Cassidy with an amendment in the nature of a substitute. Without written report.
Open bill recordText version Congress.gov
Reported to Senate
A dated text-version record is available.
Open text record
View the complete bill journey as an accessible table
| Date and time | Record | Official detail | Source |
|---|---|---|---|
| IntroductionIntroduced | Introduced in the Senate. | Congress.gov | |
| Official actionRead twice and referred to the Committee on Health, Education, Labor, and Pensions. | No additional detail supplied.IntroReferral · Senate | Congress.gov | |
| Official actionIntroduced in Senate | No additional detail supplied.IntroReferral · Library of Congress · Code 10000 | Congress.gov | |
| Text versionIntroduced in Senate | A dated text-version record is available. | Congress.gov | |
| Official actionCommittee on Health, Education, Labor, and Pensions. Ordered to be reported with an amendment in the nature of a substitute favorably. | No additional detail supplied.Committee · Senate | Congress.gov | |
| Official actionPlaced on Senate Legislative Calendar under General Orders. Calendar No. 365. | No additional detail supplied.Calendars · Senate | Congress.gov | |
| Official actionCommittee on Health, Education, Labor, and Pensions. Reported by Senator Cassidy with an amendment in the nature of a substitute. Without written report. | No additional detail supplied.Committee · Senate | Congress.gov | |
| Official actionCommittee on Health, Education, Labor, and Pensions. Reported by Senator Cassidy with an amendment in the nature of a substitute. Without written report. | No additional detail supplied.Committee · Library of Congress · Code 14000 | Congress.gov | |
| Text versionReported to Senate | A dated text-version record is available. | Congress.gov |
House roll calls join only on matching Congress, legislation type, and number. Senate roll calls join only on matching source-supplied document type and number, not question text. Committee and related-measure relationships have no date in their relationship records and therefore are counted above but never placed on the chronology.
Congressional Research Service
CRS summary
Health Care Cybersecurity and Resiliency Act of 2026This bill expands federal requirements and resources for preventing and responding to cybersecurity incidents in the health care and public health sectors.The bill directs the Department of Health and Human Services (HHS) to require private health care-related entities to adopt minimum cybersecurity practices (e.g., multifactor authentication),more specifically identify the standards for mitigating penalties relating to violations of health information privacy and security,expand and update biennially a specified plan that details cybersecurity protocols for HHS personnel,provide training and best practices to support the expansion of the workforce for health care cybersecurity, provide guidance on cybersecurity readiness to rural entities, anddesignate one representative to lead oversight and coordination of cybersecurity activities within HHS.Also, HHS and the Cybersecurity and Infrastructure Security Agency (CISA) must coordinate to improve health care cybersecurity, including by (1) providing resources for entities receiving information from HHS or CISA programs, and (2) establishing a joint cybersecurity capability plan to coordinate responses to significant incidents.Additionally, the bill requires health care providers and plans to include the number of individuals affected when notifying individuals of unauthorized access to health information (i.e., a breach).
Official documents
Text versions
- Reported to SenateMar 23, 2026
- Introduced in SenateDec 2, 2025