Warner, Wyden Introduce Bill to Strengthen Cybersecurity Standards for American Health Care System

Washington, D.C. – U.S. Sens. Ron Wyden (D-OR) and Mark R. Warner (D-VA) today reintroduced the Health Infrastructure Security and Accountability Act, legislation to improve cybersecurity in our health care system amid a growing wave of cyberattacks that are compromising Americans’ sensitive information and disrupting access to critical care across the country.

“Americans share their most sensitive personal information with their health care providers, and in return they expect every effort to be made to keep it secure,” said Sen. Wyden. “The frequency and sophistication of cyberattacks has dramatically increased in every part of the health care system, and will only grow.

“Cyberattacks on our health care system compromise Americans’ most sensitive personal information, delay essential medical care, and put lives at risk,” said Sen. Warner. “As cybercriminals ramp up their attacks on hospitals and health care providers, it’s becoming increasingly clear that voluntary standards are not enough to protect Americans’ health, safety, and privacy. This legislation would establish strong, commonsense cybersecurity protocols for health care entities, while also getting resources to rural and underserved hospitals to strengthen their defenses and protect the patients who depend on them.”

Our bill creates national cybersecurity standards for health care providers and devotes resources, especially in rural and underserved areas, to ensure every Americans’ medical information is secure. Congress cannot wait to act until another catastrophic cyberattack compromises the safety and privacy of American families’ most personal information.”

The American health care system is particularly at risk for cyberattacks due to its size, technological dependence, collection of sensitive personal information, and unique vulnerability to disruptions.

Specifically, the Health Infrastructure Security and Accountability Act would require the Department of Health and Human Services (HHS) to establish, enforce, and regularly update strong minimum cybersecurity standards for health care providers, health plans, clearinghouses, and business associates, with heightened standards for systemically important entities and entities critical to national security. The legislation would also require covered entities to develop continuity plans describing how it would resolve a tech failure or intrusion, conduct annual cybersecurity tests, and undergo independent security audits, while increasing fines for failure to meet security requirements and strengthening HHS oversight through annual cybersecurity audits. Additionally, this legislation would provide $1.3 billion to help hospitals strengthen their cybersecurity, including $800 million for hospitals in rural and underserved urban communities.

Full text of the bill is here. A summary of the bill is here.


A web version of this bill is here.

###