CiberLATAMbywhalemate

U.S. Senate Approves Health Cybersecurity Bill

S.3315 cleared the Senate unanimously and heads to the House. The bill adds rural hospital grants and security upgrades.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

The U.S. Senate approved S.3315, the Health Care Cybersecurity and Resiliency Act of 2026, with an amendment and by unanimous consent. The bill now moves to the House of Representatives and is not yet law. Separately, Senator Kirsten Gillibrand reintroduced S.5594, the Data Protection Act, to create a federal data protection agency and set new privacy measures.

Update October 8, 2026: The note also adds that S.3315 would authorize grants for rural hospitals and smaller providers, and that the Senate path followed a 22-1 vote in the HELP Committee. A sector analysis also noted that Senate approval does not make the bill law, and that the 36-month clock would begin at enactment.

The U.S. Senate approved S.3315, the Health Care Cybersecurity and Resiliency Act of 2026, with an amendment and by unanimous consent. The bill has been sent to the House of Representatives, so it is not yet law. At the same time, Senator Kirsten Gillibrand reintroduced S.5594, the Data Protection Act, to create a federal data protection agency and establish new privacy measures.

What did the Senate approve on health care?

The Senate gave S.3315 final passage in engrossed form, and the measure now moves to the House of Representatives. According to Congress.gov and GovInfo.gov, the proposal expands federal requirements and resources to prevent and respond to cybersecurity incidents in the health care and public health sectors, and it coordinates actions between the secretary of Health and Human Services and the director of CISA.

The American Hospital Association said the Senate approved S.3315 by unanimous consent on Sept. 30 and said the bill would require the HHS secretary to develop a cybersecurity incident response plan. The group also said third parties that handle health information should be held to the same privacy and security standards as covered entities and their business associates.

The measure also directs the Department of Health and Human Services to require minimum cybersecurity practices from private entities tied to health care. The requirements cited include encryption, multifactor authentication and security monitoring, all on a risk-based basis for covered organizations and their business associates, according to the legislative record and the Govly signal.

HIPAA Journal added that S.3315 would authorize grants for rural hospitals and health providers with limited resources to fund cybersecurity improvements. The same source said the HELP Committee advanced the bill by a 22-1 vote.

What else does S.3315 include if it becomes law?

The bill includes grants, training, added support for rural providers and an HHS incident response plan, along with tighter coordination between HHS and CISA. A Senate Health Committee statement from the office of Senator Bill Cassidy framed the proposal as a tool to improve interagency coordination and prevent care disruptions or compromises from cyberattacks.

SecurityWeek said the measure was originally introduced in 2024, did not advance before that congressional session ended and was reintroduced in December 2025. It also described the bill as an effort to centralize federal cybersecurity guidance across existing frameworks.

Becker's Hospital Review reported that lower-resource rural organizations would be a particular focus of the measure and quoted lawmakers who linked cyberattacks to hospital service disruptions and exposure of private medical records.

The Senate HELP Committee statement said S.3315 is co-sponsored by Bill Cassidy, Maggie Hassan, John Cornyn and Mark Warner, along with Cindy Hyde-Smith and Angus King, and it identified interagency coordination and support for rural providers as core goals.

Tempest Healthcare IT clarified that Senate approval does not make the bill law and that the 36-month period for the updated requirements would be counted from enactment, not from Senate passage.

What does the new privacy bill propose?

S.5594 was introduced by Kirsten Gillibrand and sent to the Senate Committee on Commerce, Science and Transportation after its first and second readings. The bill seeks to create a federal Data Protection Agency and set measures to protect individual privacy, according to Congress.gov and the senator's statement.

Gillibrand also said the agency would have authority to limit the collection, use and disclosure of personal data, oversee high-risk practices, maintain a public data broker registry, impose civil penalties and injunctive relief, and develop model privacy standards. GovInfo identifies S.5594 as a 119th Congress measure titled Data Protection Agency and does not show a confirmed vote schedule or implementation timeline.

The proposal comes at a time when, according to Route Fifty, federal privacy legislation stalled after a House subcommittee hearing in early June, while states continued passing their own laws.

Sources

View all