Menu

New Bipartisan Healthcare Cybersecurity Act Aims to Improve Protection Efforts

The News: A bipartisan healthcare cybersecurity act is underway, recently introduced by U.S. Senators Bill Cassidy, M.D. (R-LA) and Jacky Rosen (D-NV). The bill would require the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) to collaborate on improving cybersecurity measures across hospitals and healthcare networks. Read the Press Release from Senator Cassidy’s office here.

New Bipartisan Healthcare Cybersecurity Act Aims to Improve Protection Efforts

Analyst Take: The new bipartisan healthcare cybersecurity act is something I don’t find it all difficult to get excited about. Think about it for a moment: How would you feel if strangers were able to access the inside of your medicine cabinet or even worse, your medical records? Healthcare data is delicate and highly personal, which is why there are many measures in place to protect its confidentiality. However, now that healthcare information is primarily digitized, it is also increasingly vulnerable to cyberattacks.

Research shows that healthcare-related cyber crimes are rising at an alarming rate. Patient information is some of the most sensitive data that exists, making it a hot target for cyber criminals and a significant risk for healthcare organizations. Think it’s not a problem or that it’s not something you need to be worried about? Not the case. In fact, Politico recently reported that nearly 50 million Americans experienced breaches in their health data in 2021 alone, a threefold increase over three years.

That’s why a bipartisan healthcare cybersecurity act is, to my way of thinking, welcome news. In an effort to reverse this trend, U.S. Senators Cassidy and Rosen introduced the Healthcare Cybersecurity Act on March 23rd. The bill directs the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) to collaborate on improving cybersecurity measures across hospitals and healthcare networks. It also would authorize cybersecurity risk and mitigation training for Healthcare and Public Health sector asset owners and operators, and direct CISA to study the specific risks and challenges currently faced by organizations in the healthcare sector.

Why is Cybersecurity a Concern for Healthcare Agencies?

Healthcare data is covered by specific protections for good reason. The HIPAA Security Rule requires healthcare providers to observe data security practices for the storage and transfer of protected health information (PHI) because, in addition to sensitive information about people’s health, it includes names, addresses, dates of birth, billing information, and other data that is very valuable to cyber criminals. The depth of information contained in health records offers increased potential for fraud and identity theft, which can be much harder to detect and manage than simple credit card data leaks. Steal credit card info, rack up charges — irritating and inconvenient. Steal healthcare PHI and an ill-intentioned criminal now has the keys to someone’s entire identity.

This is a concern for healthcare agencies, not only due to their desire and mandate to protect consumer’s PHI, but because the nature of the cyber crimes they are vulnerable to in pursuit of this information poses other serious risks as well. Between ransomware extortion threats, data breaches, and DDoS attacks (which disrupt network functionality), healthcare agencies are impacted financially, organizationally, and personally. Cyber attacks have an incredibly high cost in lost revenue opportunities, productivity and time-management among personnel, and potentially enduring damage to an institution’s reputation. Still, healthcare agencies are currently fighting an uphill battle to identify and eliminate these threats.

What the Healthcare Cybersecurity Act Requires of Healthcare Agencies

In the face of mounting cybersecurity threats and evidence that Russia in particular continues to target the U.S., the Healthcare Cybersecurity Act aims to improve protection efforts through collaboration, training, and research. Senators Rosen and Cassidy note that “collaboration and information sharing between the public and private sectors is essential to increasing cyber resilience for health-focused entities.” What might this mean for the entities in question?

If the bill is passed, healthcare organizations will likely see the bar raised when it comes to the secure storage and transmission of protected health information. That’s a good thing. To meet this mandate, they will benefit from the increased availability of cybersecurity risk and mitigation training opportunities for personnel. In addition, as CISA studies relevant cybersecurity workforce shortages and proposes solutions, healthcare agencies should see results that include a growing talent pool of qualified cybersecurity professionals — which I is very much needed. Deeper understanding of the challenges healthcare agencies face in securing updated information systems should likewise result in greater availability of smarter, more effective solutions.

While holding cybersecurity efforts to a higher standard, the proposed Healthcare Cybersecurity Act proposed also aims to strengthen the affected entities’ ability to meet or exceed them.

Healthcare Cybersecurity Protections are Critical to Our Future

Both higher cybersecurity standards and better tools for reaching them are critical not only to our personal privacy but to national security. The impacts of cyber crime in healthcare and other sectors are both destabilizing and potentially debilitating. Our healthcare organizations in particular are a vital part of our national infrastructure and must not remain vulnerable to domestic or foreign threats. The costs of cyber crime to both our financial and physical health are simply too high to be sustained.

I applaud Senators Rosen and Cassidy for taking initiative toward improving protection efforts through the Healthcare Cybersecurity Act. Collaboration between the public and private sector is essential to progress in this area, as are bipartisan efforts — I hope to see continued collaboration and momentum in advancing cybersecurity protections wherever they are needed. Let’s keep those medicine cabinets closed and empower our healthcare institutions to protect themselves and their patients.

Disclosure: Futurum Research is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum Research as a whole.

Other insights from Futurum Research:

Nike’s Metaverse Store Paves a Pathway into the Future

ServiceNow Publishes 2022 Global Impact Report Detailing ESG Progress

New Oracle Cloud Infrastructure E4 Dense Compute Inferences to be Powered by AMD EPYC Processors for VMware Users Running Hybrid Cloud Environments

Image Credit: Healthcare Innovation

Author Information

Shelly Kramer is a serial entrepreneur with a technology-centric focus. She has worked alongside some of the world’s largest brands to embrace disruption and spur innovation, understand and address the realities of the connected customer, and help navigate the process of digital transformation.

Related Insights
Micron Technology Q1 FY 2026 Sets Records; Strong Q2 Outlook
December 18, 2025

Micron Technology Q1 FY 2026 Sets Records; Strong Q2 Outlook

Futurum Research analyzes Micron’s Q1 FY 2026, focusing on AI-led demand, HBM commitments, and a pulled-forward capacity roadmap, with guidance signaling continued strength into FY 2026 amid persistent industry supply...
NVIDIA Bolsters AI/HPC Ecosystem with Nemotron 3 Models and SchedMD Buy
December 16, 2025

NVIDIA Bolsters AI/HPC Ecosystem with Nemotron 3 Models and SchedMD Buy

Nick Patience, AI Platforms Practice Lead at Futurum, shares his insights on NVIDIA's release of its Nemotron 3 family of open-source models and the acquisition of SchedMD, the developer of...
Broadcom Q4 FY 2025 Earnings AI And Software Drive Beat
December 15, 2025

Broadcom Q4 FY 2025 Earnings: AI And Software Drive Beat

Futurum Research analyzes Broadcom’s Q4 FY 2025 results, highlighting accelerating AI semiconductor momentum, Ethernet AI switching backlog, and VMware Cloud Foundation gains, alongside system-level deliveries....
Synopsys Q4 FY 2025 Earnings Highlight Resilient Demand, Ansys Integration
December 12, 2025

Synopsys Q4 FY 2025 Earnings Highlight Resilient Demand, Ansys Integration

Futurum Research analyzes Synopsys’ Q4 FY 2025 results, highlighting AI-era EDA demand, Ansys integration momentum, and the NVIDIA partnership....
Hewlett Packard Enterprise Q4 FY 2025 ARR Surges as AI Orders Build
December 8, 2025

Hewlett Packard Enterprise Q4 FY 2025: ARR Surges as AI Orders Build

Futurum Research analyzes HPE’s Q4 FY 2025 results, highlighting networking-led margin resiliency, AI server order momentum, and GreenLake ARR growth....
AWS re:Invent 2025: Wrestling Back AI Leadership
December 5, 2025

AWS re:Invent 2025: Wrestling Back AI Leadership

Futurum analysts share their insights on how AWS re:Invent 2025 redefines the cloud giant as an AI manufacturer. We analyze Nova models, Trainium silicon, and AI Factories as AWS moves...

Book a Demo

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.