Congress mandates healthcare cybersecurity coordination to stem rising breach epidemic
H.R. 3841 — Healthcare Cybersecurity Act of 2025 · Filed by Jason Crow (D-CO) · 2 cosponsors · Introduced Jun 9, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill directs the federal government's cybersecurity agency (CISA) and the Department of Health and Human Services to coordinate more closely on protecting hospitals, clinics, and healthcare systems from cyberattacks. It requires them to appoint a liaison, develop training for healthcare providers, create a risk management plan identifying vulnerable assets, and report back to Congress on their progress. The bill aims to reduce the rising tide of healthcare data breaches (which have doubled since 2018) by improving information-sharing and resource allocation to high-risk healthcare facilities.
Why we flagged it
The bill's core function is to mandate interagency coordination and planning to improve cybersecurity resilience in the healthcare sector. It is a governance and risk-management measure, not a regulatory carve-out or appropriation.
What the text implies
- The 'high-risk covered asset' designation (Section 7) may create a de facto federal registry of vulnerable healthcare facilities, which could be sensitive information if disclosed or misused.
- The bill mandates no new funding but requires significant coordination work from CISA and HHS; implementation may be constrained by existing budget limitations, potentially delaying real-world impact.
The full analysis lists 4 implications of this text.
Who stands to gain
Cybersecurity consulting firms; Healthcare IT vendors; Medical device manufacturers (indirectly, through improved security standards)