The US Senate Health, Education, Labor, and Pensions (HELP) Committee advanced the bipartisan Health Care Cybersecurity and Resiliency Act by a 22–1 vote, proposing new baseline cybersecurity requirements for HIPAA-regulated entities. Reported measures include multifactor authentication, data encryption, penetration testing, and regular security audits, alongside changes to breach reporting such as requiring entities to report the number of individuals affected and directing HHS to publish post-breach corrective actions and recognized security practices used by the impacted organization.
In parallel, HHS’ Office of the National Coordinator for Health IT (ONC) proposed reducing health IT certification criteria—cutting from 60 to 34 and modifying seven others—including criteria tied to privacy and security controls. Healthcare industry groups (including CHIME and the American Hospital Association) warned that removing longstanding certification requirements would shift privacy and security compliance burden from health IT developers (e.g., EHR and patient engagement tool vendors) to healthcare providers, potentially weakening standardized security expectations across certified health IT products.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The U.S. Senate HELP Committee advanced the Health Care Cybersecurity and Resiliency Act by a 22-1 vote. The bipartisan bill would impose minimum cybersecurity standards on HIPAA-regulated entities, strengthen HHS-CISA coordination, and provide support for under-resourced and rural providers.
Healthcare industry groups including CHIME, co-signing associations, and the American Hospital Association publicly urged HHS to preserve baseline certification requirements for controls such as authentication, access control, audit logging, and encryption. They warned the rollback would shift security and compliance burdens to providers, increase costs, and raise patient safety and cybersecurity risks.
HHS' Office of the National Coordinator for Health IT proposed reducing health IT certification criteria from 60 to 34 and removing multiple privacy and security-related requirements. The proposal argued certification is no longer the main driver of privacy and security improvements and that some expectations are addressed through other programs such as TEFCA.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.