Health Infrastructure Security and Accountability Act Reintroduced With Cybersecurity Requirements

On September 17, 2026, Sens. Mark R. Warner (D-VA) and Ron Wyden (D-OR) reintroduced the Health Infrastructure Security and Accountability Act suggesting obligatory cybersecurity criteria for healthcare organizations and federal financing for rural and underserved hospitals.

The legislation was first introduced in the 118th Congress 2D Session on September 25, 2024. The 2026 version stays mostly the same as the 2024 legislation, but the timeline moved forward by two years.

During the first introduction of the bill, there were 394 big healthcare data breach reports that involve hacking submitted to the Department of Health and Human Services Office for Civil Rights. Those breaches affected the protected health information (PHI) of 43 million Americans.

The Office for Civil Rights breach portal posted 426 hacking-related breaches from January 1 to August 31, 2026, resulting in the compromise of the PHI of 73 million Americans. Compared with the statistics cited when the bill was first introduced, hacking-related breaches increased by 8%, and affected individuals increased by 70%.

Proposed Cybersecurity Standards

The legislation would set compulsory minimum cybersecurity criteria for covered entities and business associates. The HHS would establish, implement, and improve those standards every two years.

The bill would likewise set higher cybersecurity standards for systemically essential entities and entities regarded as very important to national security.

Covered entities will need to sustain continuity and recovery plans responding to technical problems, troublesome cyber incidents, and natural disasters. The plans will consist of stress tests to gauge whether organizations could restore important functions.

The legislation would call for yearly written statements signed by the CEO and chief information security officer confirming compliance with pertinent security standards.

It would likewise require yearly security risk analyses including assessments of risks that come through business associates. Third-party audits would evaluate covered entities’ security measures against the HHS cybersecurity performance goals.

The legislation would require the HHS to do yearly audits on about 20 HIPAA-regulated entities, with a focus on entities with systemic importance.

Suggested HIPAA Penalties

The bill would entail higher financial penalties under HIPAA for violations of the security requirements.

The suggested minimum penalties are the following:

  • $500 for violations involving no knowledge
  • $5,000 for reasonable cause
  • $50,000 for willful neglect that is corrected
  • $250,000 for willful neglect that is not corrected

Suggested Federal Cybersecurity Funding

The legislation would set aside $1.3 billion in government funding for hospitals to reinforce cybersecurity.

Of that sum, $800 million would provide up-front money for hospitals in rural and underserved urban communities to address the cybersecurity performance goals determined as important by the legislation.

Another $500 million would give incentives to hospitals that follow the enhanced cybersecurity performance goals.

The bill would likewise give Medicare-accelerated and advanced payments to hospitals to enable them to respond to cybersecurity events.

Relationship to HIPAA Cybersecurity Requirements

The legislation follows voluntary cybersecurity performance goals publicized by the Office for Civil Rights on January 24, 2024. The goals contained two sets of guidance for the healthcare and public health sector, which are Essential and Enhanced.

The voluntary goals were adopted by a proposed revision to the HIPAA Security Rule that would enforce extra cybersecurity requirements. Industry groups and health systems have called for the withdrawal of the proposed revision.

A final rule has been postponed until July 2027. The Trump administration has not yet made a final decision about the issuance of a final rule.

The Health Infrastructure Security and Accountability Act includes funding for rural and other low-resource healthcare providers to adopt the proposed cybersecurity requirements.

About the Author

Elizabeth Hernandez
Elizabeth Hernandez is the editor of HIPAA News. Elizabeth is an experienced journalist who has worked in the healthcare sector for several years. Her expertise is not limited to general healthcare reporting but extends to specialized areas of healthcare compliance and HIPAA compliance. Elizabeth's knowledge in these areas has made her a reliable source for information on the complexities of healthcare regulations. Elizabeth's contribution to the field extends to helping readers understand the importance of patient privacy and secure handling of health information. Elizabeth holds a postgraduate degree in journalism. You can follow Elizabeth on twitter at https://twitter.com/ElizabethHzone