Senate passes healthcare cybersecurity bill after 190 million impacted by Change Healthcare breach
The U.S. Senate passed the Health Care Cybersecurity and Resiliency Act of 2026 by unanimous consent, a bill that would expand federal cybersecurity requirements for healthcare organizations. The legislation follows the Change Healthcare breach, which affected an estimated 190 million people.
Why this matters: 190 million people had their health data exposed in a single breach. That is more than half the country. Congress finally moved, and the vote was unanimous, which is rare. The bill would push healthcare organizations to meet stricter federal cybersecurity standards. That matters because healthcare data is some of the most sensitive information that exists. People do not get to opt out of sharing it when they are sick. The real test now is whether the requirements have teeth, or whether they become another checklist that looks good on paper and fails in practice.
Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.