Senate passes healthcare cybersecurity bill after 190 million hit by Change Healthcare breach
The U.S. Senate unanimously passed the Health Care Cybersecurity and Resiliency Act of 2026, introduced after the Change Healthcare ransomware attack exposed data on 190 million people. The bill directs HHS to set minimum cybersecurity standards, including multifactor authentication, for private healthcare entities and to require breach notices to state the total number of victims.
- Bill passed by unanimous consent after Change Healthcare breach hit 190 million people
- HHS would require MFA and minimum cybersecurity standards for private healthcare entities
- Breach notifications must include the total number of victims
- American Hospital Association wants rules extended to third-party vendors
Read next
Policy