Two Democratic senators are making another run at forcing minimum cybersecurity standards onto the U.S. healthcare sector – and pairing them with money for hospitals that cannot afford the upgrade.
Sens. Mark Warner of Virginia and Ron Wyden of Oregon reintroduced the Health Infrastructure Security and Accountability Act on September 17. The bill first surfaced in September 2024, when OCR had logged 394 hacking-related breaches involving 43 million people. The picture has worsened: the agency’s breach portal counted 426 hacking-related incidents and 73 million affected individuals between January 1 and August 31, 2026 – an 8% rise in incidents and a 70% jump in people exposed.
The measure would set baseline security requirements for health providers and their business associates, and direct funding toward rural and underserved hospitals that struggle to pay for basic defenses. It lands against a stalled regulatory backdrop. OCR’s voluntary cybersecurity performance goals, published in January 2024, produced uneven adoption, and the proposed HIPAA Security Rule overhaul has drawn heavy industry opposition, with a final rule pushed out to July 2027 at the earliest.
“As cybercriminals ramp up their attacks on hospitals and health care providers, it’s becoming increasingly clear that voluntary standards are not enough,” Warner said.
The bill has no Republican co-sponsor yet, so its path through a divided Congress is uncertain. For now, healthcare CISOs should treat the reintroduction as a signal that mandatory federal standards remain firmly on the table.