The U.S. Senate Health, Education, and Labor (HELP) Committee advanced the bipartisan Health Care Cybersecurity and Resiliency Act, legislation aimed at revamping cybersecurity practices at the Department of Health and Human Services (HHS). The bill would require the HHS Secretary to develop a comprehensive cybersecurity incident response plan and submit it to Congress for review, and it would direct HHS to coordinate with CISA on oversight of cybersecurity across the public health and healthcare sectors. Additional provisions include developing cybersecurity guidance for rural healthcare providers and initiatives to improve cybersecurity literacy across the healthcare workforce.
Lawmakers cited the 2024 Change Healthcare incident as a key catalyst, arguing it demonstrated the sector’s exposure to ransomware and other cyber threats and the systemic risk created by concentrated third-party dependencies. The measure would also designate HHS’ Administration for Strategic Preparedness and Response (ASPR) as the Sector Risk Management Agency for the Healthcare and Public Health sectors. CyberScoop reported the bill passed committee on a 22–1 vote, with Sen. Rand Paul as the lone dissenter, and sponsors including Sen. Bill Cassidy along with Sens. Maggie Hassan, Mark Warner, and John Cornyn.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The U.S. Senate Health, Education, Labor and Pensions Committee advanced the bipartisan Health Care Cybersecurity and Resiliency Act on a 22-1 vote. The bill would require HHS to develop an incident response plan, coordinate with CISA, update HIPAA cybersecurity requirements, support rural providers, improve workforce cyber literacy, and create grants for healthcare entities.
Lawmakers cited the 2024 Change Healthcare cyberattack as a key catalyst for federal healthcare cybersecurity reform, pointing to ransomware, cybercriminal, nation-state threats, and third-party concentration risk in the sector.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.