A bipartisan group of U.S. senators has reintroduced the Health Care Cybersecurity and Resiliency Act of 2025, which aims to enhance cybersecurity protections in the healthcare sector. The proposed legislation includes provisions for updating HIPAA privacy and security regulations, increasing cyber grant funding, expanding workforce training, and improving breach notification requirements. The bill directs the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA) to coordinate efforts to bolster the sector's cyber resilience, reflecting growing concern over the frequency and impact of healthcare data breaches.
In parallel, healthcare organizations are reviewing their password management practices to ensure compliance with existing HIPAA Security Rule requirements. While HIPAA does not mandate specific password policies, it expects organizations to implement reasonable procedures for password creation, changes, and protection, as outlined in 45 CFR 164.308(a)(5)(ii)(D). Guidance from HHS and NIST, particularly NIST SP 800-66r2, provides technical recommendations for authentication management and credential safeguarding, underscoring the importance of robust password management in protecting protected health information (PHI).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Four bipartisan U.S. senators reintroduced the Health Care Cybersecurity and Resiliency Act of 2025 to strengthen cybersecurity and resiliency across the healthcare and public health sectors. The bill calls for HHS-CISA coordination, HIPAA rule updates, grants, rural-provider guidance, workforce training, and more detailed public breach-reporting disclosures.
By December 2025, reporting on the Change Healthcare incident said the February 2024 attack had affected 193 million people. This quantified the scale of the breach and was cited in support of new healthcare cybersecurity legislation.
During 2024, 730 major health data breaches were reported, affecting more than 270 million Americans. These breach figures were cited by lawmakers as evidence of escalating cyber risk in the healthcare sector.
A ransomware attack struck Change Healthcare in February 2024, causing widespread disruption to care delivery and business processes. The incident was later described as the largest healthcare cybersecurity incident in history.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcehelpnetsecurity.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.