Congress moves to shield healthcare from cyberattacks—quietly, without new funding
S. 1851 — Healthcare Cybersecurity Act of 2025 · Filed by Jacky Rosen (D-NV) · 3 cosponsors · Introduced May 21, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill directs the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) to coordinate on protecting healthcare systems from cyberattacks. It requires them to appoint a liaison, develop training for hospital and clinic operators, update a sector-specific risk management plan within one year, and identify high-risk healthcare assets. The bill aims to reduce the rising tide of healthcare data breaches (up 107% since 2018) by improving information sharing, threat awareness, and cybersecurity resources for healthcare providers—particularly rural and smaller facilities.
Why we flagged it
The bill's core function is to mandate inter-agency coordination and information-sharing between CISA and HHS to improve cybersecurity defenses in the healthcare sector. It is a governance and infrastructure-protection measure, not a regulatory carve-out or appropriation.
What the text implies
- The 'high-risk covered asset' designation (Section 7) may create a tiered system where smaller, rural healthcare providers receive less federal support if they fall below the threshold, potentially widening disparities in cybersecurity resilience.
- The bill mandates no new funding but relies on existing CISA and HHS budgets; if resources are not reallocated internally, coordination may be nominal rather than substantive.
The full analysis lists 4 implications of this text.
Who stands to gain
Cybersecurity consulting firms; Healthcare IT vendors; Information security training providers