Legis Daily

Healthcare Cybersecurity Act of 2025

USA119th CongressHR-3841| House 
| Updated: 6/9/2025
Jason Crow

Jason Crow

Democratic Representative

Colorado

Cosponsors (2)
Zachary Nunn (Republican)Brian K. Fitzpatrick (Republican)

Homeland Security Committee, Energy and Commerce Committee

  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted
This bill addresses the increasing threat of malicious cyberattacks targeting the Healthcare and Public Health Sector, which have led to significant data breaches, increased healthcare delivery costs, and potential negative impacts on patient health outcomes. To counter these threats, the legislation mandates enhanced coordination between the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) . A dedicated CISA liaison will be appointed to HHS to serve as a primary contact, facilitate information sharing, support the sector's risk management plan, and coordinate during cybersecurity incidents. The bill requires the Secretary of HHS, in coordination with the CISA Director, to update the Healthcare and Public Health Sector-specific Risk Management Plan within one year. This updated plan must analyze cybersecurity risks, evaluate challenges faced by asset owners in securing systems and medical devices, assess best practices for utilizing CISA resources, and address cybersecurity workforce shortages, particularly in rural and small-to-medium facilities. Furthermore, CISA is directed to provide training to healthcare owners and operators on cybersecurity risks and mitigation strategies, while HHS may establish criteria to identify and notify owners of high-risk covered assets to prioritize resource allocation and bolster cyber resilience. The legislation also mandates reports to Congress on CISA's support to the sector and on federal critical infrastructure resources, clarifying that no additional funds are authorized for its implementation.
View Full Text

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline

Bill from Previous Congress

HR 117-8806
Healthcare Cybersecurity Act of 2022

Bill from Previous Congress

HR 118-9412
Healthcare Cybersecurity Act of 2024
May 21, 2025

Latest Companion Bill Action

S 119-1851
Introduced in Senate
Jun 9, 2025
Introduced in House
Jun 9, 2025
Referred to the Committee on Homeland Security, and in addition to the Committee on Energy and Commerce, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
  • Bill from Previous Congress

    HR 117-8806
    Healthcare Cybersecurity Act of 2022


  • Bill from Previous Congress

    HR 118-9412
    Healthcare Cybersecurity Act of 2024


  • May 21, 2025

    Latest Companion Bill Action

    S 119-1851
    Introduced in Senate


  • June 9, 2025
    Introduced in House


  • June 9, 2025
    Referred to the Committee on Homeland Security, and in addition to the Committee on Energy and Commerce, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.

Health

Related Bills

  • S 119-1851: Healthcare Cybersecurity Act of 2025

Healthcare Cybersecurity Act of 2025

USA119th CongressHR-3841| House 
| Updated: 6/9/2025
This bill addresses the increasing threat of malicious cyberattacks targeting the Healthcare and Public Health Sector, which have led to significant data breaches, increased healthcare delivery costs, and potential negative impacts on patient health outcomes. To counter these threats, the legislation mandates enhanced coordination between the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) . A dedicated CISA liaison will be appointed to HHS to serve as a primary contact, facilitate information sharing, support the sector's risk management plan, and coordinate during cybersecurity incidents. The bill requires the Secretary of HHS, in coordination with the CISA Director, to update the Healthcare and Public Health Sector-specific Risk Management Plan within one year. This updated plan must analyze cybersecurity risks, evaluate challenges faced by asset owners in securing systems and medical devices, assess best practices for utilizing CISA resources, and address cybersecurity workforce shortages, particularly in rural and small-to-medium facilities. Furthermore, CISA is directed to provide training to healthcare owners and operators on cybersecurity risks and mitigation strategies, while HHS may establish criteria to identify and notify owners of high-risk covered assets to prioritize resource allocation and bolster cyber resilience. The legislation also mandates reports to Congress on CISA's support to the sector and on federal critical infrastructure resources, clarifying that no additional funds are authorized for its implementation.
View Full Text

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline

Bill from Previous Congress

HR 117-8806
Healthcare Cybersecurity Act of 2022

Bill from Previous Congress

HR 118-9412
Healthcare Cybersecurity Act of 2024
May 21, 2025

Latest Companion Bill Action

S 119-1851
Introduced in Senate
Jun 9, 2025
Introduced in House
Jun 9, 2025
Referred to the Committee on Homeland Security, and in addition to the Committee on Energy and Commerce, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
  • Bill from Previous Congress

    HR 117-8806
    Healthcare Cybersecurity Act of 2022


  • Bill from Previous Congress

    HR 118-9412
    Healthcare Cybersecurity Act of 2024


  • May 21, 2025

    Latest Companion Bill Action

    S 119-1851
    Introduced in Senate


  • June 9, 2025
    Introduced in House


  • June 9, 2025
    Referred to the Committee on Homeland Security, and in addition to the Committee on Energy and Commerce, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
Jason Crow

Jason Crow

Democratic Representative

Colorado

Cosponsors (2)
Zachary Nunn (Republican)Brian K. Fitzpatrick (Republican)

Homeland Security Committee, Energy and Commerce Committee

Health

Related Bills

  • S 119-1851: Healthcare Cybersecurity Act of 2025
  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted