Back to Intelligence

Health Infrastructure Security and Accountability Act Reintroduced: What Healthcare CISOs Must Do Before Mandatory Standards Arrive

SA
Security Arsenal Team
September 18, 2026
6 min read

On September 17, 2026, Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act (HISAA) — legislation designed to replace today's largely voluntary healthcare cybersecurity posture with mandatory, enforceable minimum standards administered by the Department of Health and Human Services (HHS). This is not a new idea; the bill builds on prior congressional efforts that gained momentum after the catastrophic 2024 Change Healthcare ransomware incident, which crippled claims processing for thousands of providers and exposed the protected health information of roughly one-third of Americans. The reintroduction signals that lawmakers have not abandoned the push to treat healthcare cybersecurity as critical infrastructure protection — and healthcare organizations that have been deferring investment are running out of runway.

For defenders, the takeaway is blunt: the era of cybersecurity-as-best-effort in healthcare is ending. Whether this specific bill passes or not, the trajectory is unmistakable — the HIPAA Security Rule overhaul proposed in late 2024, state-level mandates like New York's hospital cybersecurity regulations, and now HISAA all point the same direction. Organizations that begin aligning now will absorb these requirements as incremental change. Those that wait will face a compliance cliff.

What the Bill Would Actually Require

Based on the legislation's framework as introduced in prior sessions and carried forward in this reintroduction, HISAA's core provisions are aimed squarely at the gaps that made the Change Healthcare and Ascension Health incidents so damaging:

  • Mandatory minimum cybersecurity standards. HHS would be directed to establish baseline security requirements for covered entities and business associates, moving beyond the HIPAA Security Rule's current "addressable" implementation flexibility. Expect these to map closely to NIST CSF 2.0 and the healthcare-sector-specific HICP (Health Industry Cybersecurity Practices) guidance.
  • Executive accountability and certification. Leadership at large healthcare organizations would be required to attest — personally — that security requirements are being met, similar in spirit to Sarbanes-Oxley attestation for financial controls. This is a significant escalation: security failure becomes an executive liability problem, not just an IT problem.
  • Independent audits and stress testing. Larger entities would face mandatory third-party cybersecurity audits, with HHS gaining authority to verify compliance rather than relying on self-reported security postures.
  • Financial support for under-resourced providers. Rural, safety-net, and smaller providers would receive funding assistance to meet the new standards — a direct acknowledgment that the sector's weakest links (small hospitals and clinics) are also its most-targeted.
  • Accelerated payment mechanisms during incidents. Modeled on the advanced and accelerated payments HHS deployed after Change Healthcare, this provision codifies financial lifelines for providers whose revenue cycles are disrupted by a cyber event.

Why This Matters to Your Security Program Right Now

In my 15+ years leading IR engagements in the healthcare sector, the pattern behind nearly every catastrophic healthcare breach has been identical: flat networks with no segmentation between clinical and administrative systems, unmanaged third-party connections (clearinghouses, billing processors, EHR integrators), legacy medical devices running unpatchable operating systems, and incident response plans that existed on paper but had never been exercised. Attackers — particularly ransomware operators who deliberately target healthcare for its low tolerance for downtime — know these weaknesses better than many of the organizations that own them.

HISAA is effectively a legislative codification of the controls that would have prevented or contained these incidents. The bill's audit and attestation requirements mean that "we have a policy" will no longer survive scrutiny — auditors will want evidence: segmentation diagrams, MFA enrollment data, EDR coverage metrics, tabletop exercise records, and tested backup restoration times.

Executive Takeaways

Regardless of HISAA's legislative fate, healthcare security leaders should act on these priorities now — they align with the bill, the proposed HIPAA Security Rule updates, and the hard lessons of the past two years of healthcare ransomware:

  1. Map your current posture against NIST CSF 2.0 and HICP now. Perform a gap assessment against the controls HISAA is expected to mandate: asset inventory, MFA on all remote and privileged access, network segmentation, endpoint detection coverage, and encryption of ePHI at rest and in transit. Document the gaps — this becomes both your remediation roadmap and your audit artifact.

  2. Assume executive attestation is coming and prepare accordingly. CISOs should begin producing quarterly, evidence-backed security posture reports that a CEO or CFO could sign without flinching. If you could not today certify under penalty of liability that MFA covers 100% of remote access, that is your first remediation project.

  3. Segment ruthlessly around your revenue cycle and clinical operations. The Change Healthcare lesson is that a single compromised clearinghouse or claims processor can halt operations across an entire health system. Isolate EHR environments, medical device VLANs, and third-party connections. Validate segmentation with internal testing — do not trust the diagram.

  4. Test restoration, not just backup existence. Establish and measure recovery time objectives for your EHR, PACS, and claims systems. Run a full restoration exercise at least annually. HISAA-style audits will ask for evidence of tested recoverability, and ransomware operators bet that your backups have never been restored at scale.

  5. Formalize third-party risk management for business associates. Inventory every vendor with access to ePHI or connectivity into your environment, contractually require security baselines and incident notification SLAs, and monitor for their incidents — your biggest breach risk may be a partner's compromise, as the sector has repeatedly demonstrated.

  6. Exercise your incident response plan with clinical and executive leadership in the room. Run a ransomware tabletop that includes downtime procedures for clinical care, patient safety escalation paths, and the financial decision-making around accelerated payments and potential ransom scenarios. Hospitals that improvise these decisions during an incident lose weeks; hospitals that have rehearsed them lose days.

Preparing for the Audit Era

Whether HISAA passes in this session or returns again, healthcare organizations should operate under the assumption that mandatory minimum standards, third-party audits, and executive liability are a matter of when, not if. The organizations best positioned for this shift are those that treat it as an opportunity to secure the funding and board-level attention their security programs have needed for years. Start with the gap assessment, build your evidence trail, and make resilience — not just prevention — a measured, tested capability.

Related Resources

Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.