Health Care Cybersecurity and Resiliency Act of 2025
A BILL
To require the Secretary of Health and Human Services and the Director of the Cybersecurity and Infrastructure Security Agency to coordinate to improve cybersecurity in the health care and public health sectors, and for other purposes.
Sec. 2 Definitions
Sec. 3 Department coordination with the Agency
Sec. 4 Clarifying cybersecurity responsibilities at the Department of Health and Human Services
“310C. Oversight of cybersecurity activities
“The Secretary, acting through the Assistant Secretary for Preparedness and Response, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency pursuant to section 2218 of the Homeland Security Act of 2002, shall lead oversight and coordination of activities within the Department of Health and Human Services to support cybersecurity resiliency within the Healthcare and Public Health Sector (as defined in section 2 of the Health Care Cybersecurity and Resiliency Act of 2025), including coordination and communication with other public and private entities related to preparedness for, and responses to, cybersecurity incidents, consistent with applicable provisions of this Act, other applicable laws, and Presidential Policy Directive 21 (February 12, 2013; relating to critical infrastructure security and resilience).”
Sec. 5 Cybersecurity incident response plan
“(4) Cybersecurity incident—The term cybersecurity incident has the meaning given the term incident in section 3552 of title 44, United States Code.
“(5) Cybersecurity risk—The term cybersecurity risk has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).”
“(4) Plan
“(A) In general—Not later than 1 year after the date of enactment of the Health Care Cybersecurity and Resiliency Act of 2025, the Secretary shall develop and implement a cybersecurity incident response plan to inform applicable personnel within the Department of Health and Human Services of processes and protocols to prepare for, and respond to, cybersecurity incidents involving information, including hardware, software, databases, and networks, used or maintained by, or on behalf of, the Department, including strategies—
“(i) to assess cybersecurity risks;
“(ii) to prevent cybersecurity incidents;
“(iii) to detect and identify cybersecurity incidents;
“(iv) to minimize damage in the event of a cybersecurity incident;
“(v) to protect data; and
“(vi) to recover from any cybersecurity incidents expeditiously.
“(B) Consultation—In developing the plan under subparagraph (A), the Secretary shall consult with the Director of the Cybersecurity and Infrastructure Security Agency, the Director of the Office of Management and Budget, and the Director of the National Institute of Standards and Technology, and relevant experts, as appropriate.
“(C) Report—Not later than 60 days before the date on which the Secretary begins implementing the plan under subparagraph (A), the Secretary shall submit to the Committee on Health, Education, Labor, and Pensions and the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Energy and Commerce, the Committee on Oversight and Reform, and the Committee on Homeland Security of the House of Representatives a report that describes such plan.”
Sec. 6 Breach reporting portal
“(k) Updates to regulations—Not later than 1 year after the date of enactment of the Health Care Cybersecurity and Resiliency Act of 2025, the Secretary shall update the regulations promulgated pursuant to subsection (j) to require that information required to be publicly displayed in the breach reporting portal established pursuant to this section includes—
“(1) information on any corrective action taken against a covered entity that provided notification of a breach under this section;
“(2) information on whether and to what extent, as appropriate, recognized security practices (as defined in section 13412(b)(1)) were considered in the investigation of such a breach; and
“(3) such additional information about such a breach as the Secretary may require.”
Sec. 7 Clarifying breach reporting obligations
“(6) The number of individuals affected by the breach.”
Sec. 8 Enhancing recognition of security practices
Sec. 9 Required cybersecurity standards
Sec. 10 Guidance on rural cybersecurity readiness
“(5) Rural cybersecurity guidance
“(A) Definition of rural—In this paragraph, the term rural has the meaning given such term by the Health Resources and Services Administration.
“(B) Guidance on rural cybersecurity readiness—Not later than 1 year after the date of enactment of the Health Care Cybersecurity and Resiliency Act of 2025, the Secretary shall issue guidance to rural entities on best practices to improve cyber readiness, including strategies—
“(i) to improve cyber infrastructure, including any technical safeguards to mitigate cybersecurity risk;
“(ii) to integrate best practices issued by the Secretary to improve cybersecurity preparedness;
“(iii) to improve employee preparation to mitigate any cybersecurity risks, including existing public-private programs to support educational initiatives; and
“(iv) to implement policies to facilitate mandatory cybersecurity incident reporting requirements under law.
“(C) GAO study and report
“(i) In general—Not later than 3 years after the date of enactment of the Health Care Cybersecurity and Resiliency Act of 2025, the Comptroller General of the United States shall conduct, and submit to the Committee on Health, Education, Labor, and Pensions of the Senate and the Committee on Energy and Commerce of the House of Representatives a report that describes the results of, a study to examine how rural entities have implemented the recommendations included in the guidance under subparagraph (B).
“(ii) Requirements—The study under clause (i) shall assess—
“(I) how rural entities have implemented any technical safeguards and any challenges faced by such rural entities in areas for which safeguards were not implemented;
“(II) steps to further support cyber resilience for rural entities;
“(III) areas to improve coordination between Federal agencies, including for the purposes of required cyber reporting; and
“(IV) any opportunities to support public-private collaboration in the area of cyber readiness.”
Sec. 11 Grants to enhance cybersecurity in the health and public health sectors
“399V–8. Grants
“(a) In general—The Secretary may award grants to eligible entities for the adoption and use of cybersecurity best practices.
“(b) Eligible entity—To be eligible to receive a grant under subsection (a) an entity shall be—
“(1) a public or nonprofit private health center (including a Federally qualified health center (as defined in section 1861(aa)(4) of the Social Security Act));
“(2) a health facility operated by or pursuant to a contract with the Indian Health Service;
“(3) a hospital;
“(4) a cancer center;
“(5) a rural health clinic;
“(6) an academic health center; or
“(7) a nonprofit entity that enters into a partnership or coordinates referrals with an entity described in any of paragraphs (1) through (6).
“(c) Use of funds—In adopting and using cybersecurity best practices pursuant to a grant under subsection (a), an eligible entity may use grant funds—
“(1) to hire and train personnel in such cybersecurity best practices;
“(2) to update electronic data systems, such as by migrating to cloud based platforms;
“(3) to join and participate in health cybersecurity threat information sharing organizations;
“(4) to reduce the use of legacy systems; and
“(5) to contract with third parties to assist with the activities described in paragraphs (1) through (5).
“(d) Grant period—The Secretary may award a grant under this section for a period of not more than 3 years.
“(e) Application—An eligible entity seeking a grant under subsection (a) shall submit to the Secretary an application at such time, in such manner, and containing such information as the Secretary may require including, at a minimum a description of how the eligible entity will establish baseline measures and benchmarks that meet the Secretary’s requirements to evaluate program outcomes.
“(f) Authorization of appropriations—There are authorized to be appropriated to carry out this section such sums as may be necessary for each of fiscal years 2025 through 2030.”