The House Energy and Commerce Subcommittee on Health examined the Healthcare Cybersecurity and Resiliency Act of 2026 and the Rural Hospital Cybersecurity Enhancement Act as healthcare breaches remain elevated. By August 30, 496 large breaches had been reported to HHS OCR, exposing more than 74.6 million individuals’ protected health information; hacking and other IT incidents accounted for 426 of those incidents. The bills seek to improve healthcare cyber workforce capacity, funding, federal coordination, patient-data protection, and operational resilience, particularly for rural and resource-constrained providers.
Healthcare and Public Health Sector Coordinating Council Cybersecurity Working Group Executive Director Greg Garcia endorsed the legislation with revisions, urging grants, training, community support, safe-harbor protections, and funding to replace unsecurable end-of-life medical devices. He also called for stronger HHS cybersecurity leadership and formal HSCC participation in HHS and CISA policy, threat-sharing, and incident-response efforts. Garcia opposed legislatively prescribed controls, including specific MFA and encryption requirements, and recommended a risk-based framework rather than the proposed prescriptive HIPAA Security Rule update.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
The House Energy and Commerce Subcommittee on Health held a hearing, "Examining Legislative Proposals to Reform Medicare Provider Payment and Bolster Health Care Cybersecurity," considering the Rural Hospital Cybersecurity Enhancement Act and the Health Care Cybersecurity and Resiliency Act of 2026. HSCC Executive Director Greg Garcia testified in support of refinements including grants, workforce support, replacement of insecure legacy devices, stronger HHS leadership, and risk-based rather than prescriptive technical requirements.
HSCC published its report, "On the Edge: Cybersecurity Health of America’s Resource-Constrained Health Providers," documenting cybersecurity challenges facing low-resourced health providers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcehealthsectorcouncil.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.