The Health Care Cybersecurity and Resiliency Act Advances: What Clinics Should Do Next

Health Care Cybersecurity and Resiliency Act

The Health Care Cybersecurity and Resiliency Act has reached an important milestone for U.S. healthcare cybersecurity. On September 30, 2026, the Senate passed S. 3315 with an amendment by unanimous consent, advancing legislation designed to strengthen cybersecurity across the Healthcare and Public Health Sector. As of October 6, 2026, Senate passage does not make the bill law, so healthcare organizations should distinguish between what Congress is proposing and what is currently required.

For physician practices, outpatient clinics, federally qualified health centers, rural providers, hospitals, and healthcare business associates, the development is still worth watching closely. The legislation points toward a cybersecurity environment increasingly focused on risk-based safeguards, multifactor authentication, encryption, security monitoring, penetration testing, incident response, and resilience. Rather than waiting for another regulatory deadline, healthcare leaders can use these priorities to evaluate whether their current security program can protect patient care during a real cyber incident.

What the Senate Passed

S. 3315, the Health Care Cybersecurity and Resiliency Act of 2026, would strengthen coordination between the Department of Health and Human Services and the Cybersecurity and Infrastructure Security Agency. The legislation also addresses cybersecurity training, rural healthcare assistance, incident-response planning, workforce development, grants for certain healthcare organizations, and recognition of established security practices. Importantly, the Senate-passed version contains specific provisions addressing future minimum cybersecurity practices.

Section 8 would direct HHS to update applicable security regulations so covered organizations adopt minimum risk-based cybersecurity practices. The Senate-passed text specifically identifies multifactor authentication, encryption of protected health information, monitoring that includes penetration testing, and other standards reflected in national cybersecurity frameworks. Under the current bill language, those updated requirements would take effect 36 months after enactment—not 36 months after Senate passage.

That distinction matters because the legislation has not completed the federal legislative process. There is no new 36-month compliance countdown for clinics simply because the Senate passed S. 3315. Healthcare organizations should track the legislation while continuing to follow their existing legal, regulatory, contractual, and cybersecurity obligations.

Why Clinics Should Pay Attention Now

The value of the bill for healthcare leaders is not limited to predicting future compliance requirements. Its cybersecurity priorities provide a useful framework for examining weaknesses that already affect operational resilience. MFA, encryption, vulnerability management, penetration testing, incident response, and recovery are practical security issues regardless of what happens next in Congress.

For a small or medium-sized medical practice, the question is not simply whether it can eventually demonstrate compliance with a new rule. A more immediate question is whether the practice can continue scheduling patients, accessing essential information, communicating with clinicians, processing prescriptions, and collecting revenue when a critical system becomes unavailable. That operational perspective turns cybersecurity from an abstract technical exercise into business and patient-care resilience.

The same approach is useful for larger physician groups and health networks operating across multiple sites. More locations often mean more endpoints, vendors, remote connections, identities, cloud services, and inherited systems to manage. Preparing early gives healthcare organizations time to improve these controls methodically rather than responding to a future mandate under deadline pressure.

Start With the Systems That Keep Patient Care Moving

For a practice administrator, COO, or IT manager, a productive first question is: Which systems would cause the greatest disruption if they became unavailable tomorrow? The answer may include the EHR, scheduling platform, electronic prescribing, laboratory interfaces, billing applications, phones, email, imaging systems, or cloud identity infrastructure. Critical vendors and connections supporting those systems should also be considered.

Create an inventory showing each important system, its business or clinical owner, how employees access it, which vendors support it, and what fallback process exists during an outage. Identify dependencies such as a single administrator account, unsupported device, internet connection, external provider, or cloud identity platform. The objective is to understand what the organization needs in order to continue operating.

This gives cybersecurity investments a clearer purpose. A vulnerability is easier for leadership to prioritize when it can be connected to canceled appointments, unavailable prescriptions, interrupted billing, delayed laboratory results, or loss of communication. Risk becomes more meaningful when expressed in terms of healthcare operations.

Make Multifactor Authentication Work in Practice

Multifactor authentication in healthcare is already a major security priority, and S. 3315 places MFA directly among the minimum risk-based practices contemplated in the Senate-passed legislation. Healthcare organizations should use this opportunity to review MFA coverage across email, remote access, administrative tools, cloud platforms, and applications handling sensitive information. The goal is not simply to report that MFA has been “deployed.”

Coverage is what matters. IT teams should identify privileged accounts, remote vendor accounts, shared or generic identities, service accounts, and other exceptions that may operate differently from ordinary employee accounts. Each exception should have an owner, documented reason, and appropriate alternative safeguards where standard MFA cannot be applied.

Healthcare organizations should also review account recovery and MFA-reset procedures. An attacker who cannot bypass MFA technically may attempt to convince a help desk or employee to reset it. Strong authentication therefore requires secure enrollment, recovery, administration, and monitoring—not merely enabling another authentication prompt.

Do Not Forget Vendors and Non-Human Identities

Third-party access can remain active long after its original business purpose changes. A vendor may receive remote access for a project, integration, or support requirement and retain that access after the engagement ends. Regular access reviews should verify that outside organizations can reach only the resources necessary for their current role.

Service accounts and other non-human identities deserve similar scrutiny. Automated accounts may support EHR integrations, billing, ERP synchronization, backups, interface engines, databases, and cloud services without anyone logging into them interactively. Because they do not leave the company like employees do, these identities can accumulate unnecessary privilege.

Assign ownership and document the purpose of important machine identities. Determine what systems they can access and whether those permissions remain necessary. Identity governance should cover employees, vendors, administrators, applications, and automated services rather than treating workforce accounts as the entire identity attack surface.

Encryption Should Be More Than a Checkbox

The Senate-passed legislation also specifically identifies encryption of protected health information or successor technology among the proposed minimum practices. For healthcare organizations, encryption should be evaluated in the context of where sensitive information actually exists and how it moves. Simply stating that an organization “uses encryption” provides little insight into coverage.

Healthcare teams should understand whether ePHI is protected on endpoints, servers, backups, removable media, cloud storage, and during transmission where appropriate. They should also understand how encryption keys are managed and whether legacy systems create exceptions. Documentation should distinguish between expected controls and verified implementation.

This becomes particularly important as healthcare data moves through multiple vendors and cloud environments. Encryption is strongest when combined with access control, identity security, monitoring, segmentation, and good configuration management. No single safeguard should be expected to compensate for weaknesses everywhere else.

Vulnerability Scanning and Penetration Testing Are Not the Same

S. 3315 specifically references monitoring that includes penetration testing, making the distinction between scanning and testing increasingly relevant to healthcare leadership. Vulnerability scanning helps identify potential weaknesses based on known vulnerabilities, configurations, software versions, and other indicators. Penetration testing goes further by determining, within an authorized scope, whether selected weaknesses can actually be exploited.

Both activities can contribute useful information, but they answer different questions. A scanner may identify hundreds of potential findings, while a penetration tester can help determine which weaknesses create meaningful attack paths. Healthcare organizations benefit when technical findings are translated into business and clinical consequences.

Testing must also respect healthcare availability requirements. A penetration test involving production clinical infrastructure should have defined scope, authorization, communication procedures, and safety boundaries. Testing should increase confidence in security without unnecessarily jeopardizing patient-care systems.

Validate Weaknesses and Confirm Repairs

A cybersecurity assessment becomes valuable when its findings lead to decisions and measurable remediation. A long technical report can be difficult for healthcare leadership to use if findings lack context, ownership, priorities, and clear remediation steps. Security teams should be able to explain both what is wrong and why it matters.

An effective process starts with authorized testing, evidence validation, and confirmation of affected assets. Each important finding should identify the likely impact, recommended correction, responsible party, and any operational dependencies that affect remediation. Critical weaknesses should be prioritized according to actual exposure rather than report length.

The process should not end when someone marks the ticket “patched.” Retesting can confirm whether the vulnerability was actually resolved and whether compensating controls work as intended. Evidence of remediation also provides useful documentation for risk management, audits, partner questionnaires, and leadership reviews.

Test Recovery Before Ransomware Tests It for You

Healthcare ransomware resilience depends on more than having backup software. Ask the IT team to demonstrate restoration of a critical system and record how long recovery takes, what information returns, and which dependencies must be restored before employees can resume normal operations. A successful nightly backup job does not prove that an entire clinical workflow can be recovered.

Identity infrastructure, networking, DNS, cloud access, scheduling systems, vendor services, and application dependencies can all affect recovery. A restored server may technically be online while the workflow it supports remains unusable. Recovery testing should therefore evaluate services from the perspective of the people who depend on them.

Healthcare organizations should also protect backups from the same compromise affecting production systems. Administrative separation, access restrictions, immutable or otherwise resilient backup strategies where appropriate, and regular restoration testing can reduce recovery uncertainty. The objective is not merely to preserve data but to restore healthcare operations.

Turn Downtime Plans Into Exercises

A written incident-response plan is useful, but healthcare leaders should know whether employees can execute it under pressure. Conduct a short tabletop exercise involving clinical, administrative, IT, compliance, communications, and leadership personnel appropriate to the organization’s size. Simulate an outage affecting a system employees depend on every day.

Ask how appointments will be managed, how patients will be contacted, how clinicians will document care, who can authorize emergency decisions, and how vendors will be contacted. Include uncertainty rather than assuming the organization immediately understands what caused the outage. Real cyber incidents rarely arrive with a clean technical diagnosis.

End the exercise with a small number of actionable improvements. Assign an owner and target completion date to each item, then revisit the plan after meaningful technology or staffing changes. A tabletop exercise should improve the next response rather than simply demonstrate that a meeting occurred.

Rural Healthcare Gets Specific Attention

Rural cybersecurity is a notable component of the Senate-passed legislation. S. 3315 would require guidance on rural cybersecurity readiness and addresses technical assistance, workforce preparation, incident reporting, shared IT resources, third-party support, and secure cloud migration. That reflects the reality that rural providers may face different staffing and resource constraints than large health systems.

The legislation also proposes cybersecurity grants for specified eligible organizations. The current Senate-passed categories include federally qualified health centers, certain Indian Health Service facilities, nonprofit hospitals, rural health clinics, and certain nonprofit entities partnering or coordinating referrals with those organizations. Grant funds could support activities such as cybersecurity expertise, system modernization, risk and vulnerability assessments, incident-response planning, and threat-information sharing.

Private practices should not assume that Senate passage creates a grant program available to every clinic. Eligibility is defined in the bill, and implementation would depend on the legislation becoming law and the resulting federal processes. Organizations should follow the final legislation rather than planning around funding that does not yet exist.

Do Not Treat 36 Months as Permission to Wait

One detail in the Senate-passed bill deserves careful interpretation. If S. 3315 becomes law in its current form, Section 8 states that the updated cybersecurity requirements described there would take effect 36 months after enactment. That is not a current compliance deadline, and the bill can still change before becoming law.

Even if a future implementation period is measured in years, healthcare organizations should not assume meaningful cybersecurity improvements can be completed at the end of that period. MFA deployment, encryption coverage, network modernization, penetration testing, remediation, vendor governance, and recovery improvements can expose dependencies that take time to resolve. Starting with an accurate baseline makes future decisions easier.

This is especially relevant for small and medium-sized healthcare organizations with limited IT resources. A gradual, risk-based program is generally more manageable than a large compliance project launched shortly before a deadline. The goal should be sustainable improvement rather than last-minute documentation.

How Tempest Healthcare IT Can Help

Tempest Healthcare IT helps U.S. healthcare organizations evaluate cybersecurity risk through healthcare-focused security assessments, vulnerability management, penetration testing, HIPAA readiness, identity and access reviews, remediation planning, and resilience testing. For small and medium-sized clinics, the objective is to translate technical findings into practical priorities that leadership can understand and IT teams can act on.

A healthcare cybersecurity program should strengthen both security and operational reliability. Organizations preparing for evolving HIPAA cybersecurity expectations can start by identifying their most important systems, validating existing controls, documenting gaps, and creating a prioritized remediation roadmap. Book a free healthcare cybersecurity consultation with Tempest Healthcare IT to discuss your clinic’s current security priorities and next steps.

Final Thoughts

The Senate’s passage of the Health Care Cybersecurity and Resiliency Act is a meaningful development, but it is not the end of the legislative process and does not create a new compliance deadline today. What it does provide is another clear signal that healthcare cybersecurity, HIPAA Security Rule modernization, MFA, encryption, penetration testing, incident response, and cyber resilience are increasingly connected in the U.S. healthcare security conversation. GovInfo

Clinics do not need to wait for a final law to improve the controls that keep care moving. Start with critical-system visibility, strengthen identity protection, validate vulnerabilities, confirm remediation, test recovery, and build evidence that demonstrates what the organization can actually do during an incident. For ongoing insights on healthcare cybersecurity, HIPAA readiness, vulnerability management, penetration testing, ransomware resilience, and emerging U.S. healthcare security developments, follow Tempest Healthcare IT on LinkedIn.

References

  1. U.S. Government Publishing Office — S. 3315, Health Care Cybersecurity and Resiliency Act of 2026, Engrossed in Senate
    Read the Senate-passed bill text GovInfo
  2. U.S. Government Publishing Office — Congressional Record, September 30, 2026
    Confirms Senate passage of S. 3315 following agreement to the Cassidy substitute amendment. GovInfo
  3. Office of U.S. Senator Mark R. Warner — Senate Passes Warner Legislation to Strengthen Cybersecurity in Health Care, October 2, 2026
    Read the Senate announcement Senator Warner