Strengthening Healthcare Cybersecurity: Mandatory Standards to Protect Patient Data and Services.
This Act mandates minimum cybersecurity standards for hospitals, clinics, and entities handling medical data, including data encryption and multifactor authentication. The goal is to better protect citizens' private health information and ensure the continuous operation of healthcare facilities against cyberattacks. The law also authorizes grants to help facilities, especially rural ones, upgrade their security systems.
Key points
Mandatory encryption of protected health information (PHI) and use of multifactor authentication (MFA) to secure patient records.
Authorization of grants for healthcare providers to hire staff, update IT systems, and reduce reliance on outdated technology to enhance security.
Requirement for healthcare entities to conduct security audits, including penetration testing, to identify and fix vulnerabilities.
Improved coordination between government agencies (HHS and CISA) to quickly respond to cyber incidents threatening healthcare services.
Introduced
Additional Information
Print number: 119_S_3315
Sponsor: Sen. Cassidy, Bill [R-LA]