Insight · Policy Watch

The Senate's new healthcare cybersecurity bill: what small and rural hospitals should do now

By Thomas J. Johnson, Founder, EHR Resources LLC · October 9, 2026 · 6 min read

On September 30, 2026, the United States Senate passed the Health Care Cybersecurity and Resiliency Act of 2026 (S. 3315) with an amendment, by unanimous consent. Unanimous votes are rare in Washington, and this one sends a clear message: both parties now treat hospital cybersecurity as a patient safety issue, not just an IT issue. The bill is not law yet. It moves to the House next, and no one can promise it will pass there. But its direction matters, and small and rural hospitals sit squarely at the center of it.

The short version

  • The Senate passed S. 3315 by unanimous consent on September 30, 2026. It still needs House passage and the President's signature before any of it becomes law.
  • The bill would authorize grants for nonprofit hospitals, rural health clinics, federally qualified health centers, and their nonprofit partners to pay for risk assessments, staff training, system upgrades, and incident response planning.
  • It would direct HHS to publish rural-specific cybersecurity guidance within a year of enactment, including guidance on outsourcing part-time IT and security leadership.
  • It would require HHS to set minimum security standards, including multifactor authentication, encryption, and penetration testing, taking effect about three years after enactment.
  • Nothing in the bill changes your obligations today. The current HIPAA Security Rule, including an accurate and thorough security risk analysis, is still the standard you are measured against.

What the bill actually does

The bill runs twelve sections, and most of them assign homework to the federal government rather than to hospitals. HHS and CISA would have one year to build a joint plan for responding to major sector-wide incidents, and HHS would have to expand and maintain its own healthcare incident response plan. A working group would be charged with streamlining the overlapping breach reporting requirements that today can have one hospital reporting the same incident to half a dozen agencies.

Three sections reach providers directly. First, the grants: HHS could award up to three years of funding to eligible organizations for exactly the work most small hospitals struggle to budget, including risk and vulnerability assessments, hiring and training staff, updating systems, joining threat-sharing organizations, and developing incident response plans. Congress has not yet attached a dollar amount, so the money is a possibility, not a promise.

Second, rural guidance: within a year of enactment, HHS would have to publish cybersecurity guidance written for rural facilities specifically. The topics Congress listed are telling, because they describe rural reality: outsourcing part-time IT and security leadership, regional health IT sharing arrangements, and cloud migration. Washington is acknowledging that a 15-bed critical access hospital cannot staff a security department, and that the answer is shared and outsourced expertise.

Third, minimum standards: the bill would direct HHS to update its security regulations to require baseline practices, naming multifactor authentication, encryption of protected health information, and monitoring that includes penetration testing. Those requirements would take effect roughly 36 months after enactment, with room for enforcement discretion when a facility faces extraordinary circumstances.

What is required today, and what is not

It is worth being precise here, because vendors sometimes blur this line. Even the date gets reported inconsistently: several outlets have placed Senate passage on October 1, 2, or 5. The congressional record shows September 30, 2026, and that is the date we use. As of today, none of the following are law: S. 3315, its grant program, and its minimum standards. Separately, the proposed update to the HIPAA Security Rule that HHS published in January 2025, which would add requirements like annual penetration testing and regular vulnerability scanning, is still a proposed rule, with final action currently projected for mid-2027. If someone tells you penetration testing is already a HIPAA requirement, they are misstating the rule.

What is required today is the Security Rule that has been in force for two decades, and at its foundation an accurate and thorough risk analysis of the threats and vulnerabilities to your electronic protected health information. That is not a technicality. In every one of the ransomware settlements the HHS Office for Civil Rights announced in April 2026, the finding was the same: the organization had failed to conduct an adequate risk analysis before the attack.

One more piece of current law deserves attention, because the bill strengthens it. Since 2021, federal law has required regulators to consider an organization's "recognized security practices," documented for the prior twelve months, when deciding fines and audits after a breach. S. 3315 would sharpen how that credit works, and would make clear that security investments count. The lesson holds whether or not the bill passes: documented, consistent security practices are worth real money if you ever face an investigation.

What small and rural hospitals should do now

  1. Get your security risk analysis current. It is the one thing required today, it is the first thing investigators ask for, and it is also the foundation for everything else on this list. A current risk analysis tells you, in writing, where your real gaps are and in what order to close them.
  2. Start your twelve-month evidence file. The recognized security practices credit rewards organizations that can document what they were doing for the year before an incident. Keep dated records of training, patching, access reviews, and risk analysis updates. If the worst happens, that file changes the conversation with regulators.
  3. Close the gaps the standards keep naming. Multifactor authentication, encryption, and monitoring appear in S. 3315, in the proposed Security Rule, and in nearly every OCR enforcement action. Whatever happens in the House, this is the direction. Work from your risk analysis and close these first.
  4. Put an incident response plan on paper and practice it once. The bill treats incident response planning as a fundable, expected practice. A plan that exists only in someone's head does not count, and a tabletop exercise costs an afternoon.
  5. Position yourself for the grants. If funding is appropriated, applications will require performance benchmarks and a plan to sustain the work after the grant ends. A current risk analysis gives you both: a documented baseline and a prioritized list of what the money should buy. Facilities that can show demonstrated need and a credible plan will be first in line.

A note on timing

Bills do stall in the House, and there is no guarantee this one becomes law this session. But notice that nothing on the list above is wasted effort if it does not. Every step is either required under current law, directly reduces your breach risk, or earns credit that already exists in federal law today. That is the practical way to read this bill: not as a new mandate to fear, but as confirmation of where healthcare security requirements are heading, and a head start for the facilities that act early.

Not sure where your facility stands?

A short conversation about where you stand is free and confidential. You will speak with Thomas directly, and there is no obligation on the other side.