United States
S. 3315
Health Care Cybersecurity and Resiliency Act of 2026
The bill would require private health care organizations to adopt minimum cybersecurity protections like multifactor authentication and would direct federal health agencies to provide training, guidance, and resources to strengthen cybersecurity across the health care sector. It would also require HHS and the Cybersecurity and Infrastructure Security Agency to coordinate their efforts to prevent and respond to cyberattacks, and would mandate that health care providers notify patients about the number of people affected when their personal health information is breached.[AI-Generated]
Record as of 30 September 2026 — the most recent action in the official record. Status can lag; each step below carries its own date.
- 30 September 2026 Passed Senate with amendment (unanimous consent)
What's next: To the House (if and when it takes it up)
- 23 March 2026 Reported by committee
- 23 March 2026 Placed on calendar (Senate)
1 more action
- 26 February 2026 Committee on Health, Education, Labor, and Pensions. Ordered to be reported with an amendment in the nature of a substitute favorably.
- 2 December 2025 Referred to committee
- 2 December 2025 Introduced in Senate
Read the live feed — on the site or in the app Look up S. 3315 on Congress.gov All US bills