A bipartisan push to give rural hospitals cybersecurity help moved through a House subcommittee this week, attached to a broader Medicare payment package.
The Energy and Commerce Subcommittee on Health, chaired by Representative Morgan Griffith of Virginia, held a September 15 hearing on Medicare provider payment reform and health care cybersecurity. Among the bills on the table was H.R. 9908, the Rural Hospital Cybersecurity Enhancement Act, led by Representative Erin Houchin of Indiana and Representative Kim Schrier of Washington.
The bill would direct HHS to build a rural hospital cybersecurity workforce strategy, expand training resources, and improve preparedness. Houchin told the panel that HHS has logged 329 breaches this year tied to hacking or IT incidents at providers and health plans, and noted the figure only covers incidents affecting 500 or more people. Smaller rural intrusions never appear in that count.
She framed the stakes in care terms: recent attacks in her district canceled surgeries and appointments, knocked payment systems offline, and in some cases blocked emergency care. Rural facilities are often the only source of care for miles and run on the thinnest staffing and budgets, which is exactly the profile ransomware crews have favored this year.
For hospital security leaders, the hearing matters less for what passes than for the signal it sends. Workforce and training money is where Congress is willing to move, and grant-funded help for small facilities remains the likeliest near-term outcome.