On September 15, 2026, the House Energy and Commerce Committee's Subcommittee on Health convened a legislative hearing to examine cybersecurity proposals aimed at the healthcare sector — the clearest signal yet that Congress intends to convert the lessons of the past two years of devastating healthcare breaches into statute. This isn't academic. The hearing follows the seismic Change Healthcare ransomware incident, a sustained wave of attacks against hospitals and health systems, and HHS's proposed update to the HIPAA Security Rule — the first major overhaul of that regulation in over two decades.
For CISOs and security leaders at covered entities and business associates, the message is straightforward: the era of "addressable" security controls and voluntary frameworks is closing. Federal lawmakers are actively weighing mandatory minimum cybersecurity standards, potential funding mechanisms for under-resourced providers, and stronger accountability for business associates. Organizations that wait for final legislation to begin hardening their environments will find themselves compressing a multi-year security program into an eighteen-month compliance window.
This post breaks down what the hearing means, what legislative direction we can reasonably anticipate, and — most importantly — what your security program should be doing in the next 90 days regardless of which bill text ultimately passes.
Technical and Policy Analysis
What the Hearing Signals
Legislative hearings of this type serve a specific function: they establish the evidentiary record and stakeholder positions that shape final bill language. When the Subcommittee on Health examines cybersecurity proposals, the agenda typically centers on several converging threads:
1. Mandatory minimum security standards for HIPAA-regulated entities. The proposed HIPAA Security Rule update (published in early 2025) already moves in this direction — eliminating the "addressable" designation that let organizations defer controls like MFA and encryption. Congressional proposals would give those requirements statutory force, add enforcement teeth, and potentially extend them to entities HHS's rulemaking authority doesn't cleanly reach.
2. Rural and under-resourced provider funding. Hospital groups have consistently argued that mandates without money produce paper compliance. Expect discussion of grant programs or reimbursement mechanisms tied to demonstrated cybersecurity performance — likely modeled on existing "carrot" frameworks that link Medicare incentive payments to adopting recognized security practices.
3. Business associate accountability. The Change Healthcare incident demonstrated that a single clearinghouse compromise can degrade care delivery nationwide. Proposals under examination likely include direct security obligations and breach-reporting timelines for business associates, not just covered entities.
4. Threat intelligence sharing and HHS/CISA coordination. Expect emphasis on formalizing the role of HHS's sector risk management function, the Health-ISAC ecosystem, and CISA's healthcare-specific services in any statutory framework.
Why the Threat Environment Demands This
The legislative momentum isn't happening in a vacuum. Healthcare remains the most-breached critical infrastructure sector by reported incident volume, and the operational consequences are uniquely severe — this is the one sector where a ransomware detonation can directly kill patients by diverting ambulances and forcing downtime procedures on clinicians who haven't run a paper chart in fifteen years. Threat actors including ALPHV/BlackCat successors, LockBit affiliates, and initial access brokers continue to prioritize healthcare targets precisely because downtime pressure maximizes ransom payment probability.
The attack patterns driving regulatory attention are well-established: exploitation of internet-facing remote access without MFA, compromised third-party and business associate credentials, unpatched VPN and remote access appliances, and flat internal networks that let a single phished workstation become a full enterprise encryption event.
Executive Takeaways
Regardless of which specific proposals advance out of committee, the direction of travel is unambiguous. Security leaders at healthcare organizations should act on the following now:
1. Treat the HIPAA Security Rule NPRM as the floor, not the ceiling. Begin your gap assessment against the proposed rule's requirements today: mandatory MFA for all systems accessing ePHI, encryption of ePHI at rest and in transit, network segmentation, asset inventories, and 72-hour restoration requirements. If legislation passes, these requirements will arrive with statutory backing and shorter timelines than you expect.
2. Build your asset inventory and network map before you're required to. Both the proposed rule and congressional proposals emphasize accurate, maintained inventories of systems touching ePHI. Most health systems cannot currently produce one. Start now — this is the longest-lead-time item in any compliance program and the foundation for segmentation work.
3. Segment aggressively, starting with clinical and IoMT devices. Flat networks are the reason single compromises become enterprise disasters. Prioritize isolating medical devices, legacy clinical systems, and administrative networks. Document segmentation decisions — they will be audit evidence.
4. Extend your security requirements contractually to business associates. Don't wait for Congress to impose business associate obligations. Amend BAAs now to require MFA, encryption, breach notification within defined hours (not days), and evidence of annual penetration testing or equivalent assessment.
5. Document your recognized security practices. Under the HITECH Act's enforcement discretion provisions, demonstrated adoption of NIST CSF or HICP (405(d)) practices for the prior twelve months mitigates penalties and audit scope. If you haven't formally adopted and documented a framework, that clock hasn't started.
6. Monitor and engage in the comment process. Whether through HIMSS, the AHA, H-ISAC, or direct counsel engagement, ensure your organization's operational realities are represented in the rulemaking and legislative record. Requirements written without provider input produce unfunded mandates; requirements written with it produce achievable standards.
Remediation and Preparation
There is no patch for legislation — but there is a concrete preparation sequence:
- Gap assessment (0-30 days): Map current state against the proposed HIPAA Security Rule requirements and NIST CSF 2.0. Identify the three largest gaps by risk, not by cost.
- MFA enforcement (30-60 days): Enforce phishing-resistant MFA on all remote access, email, and any system storing or transmitting ePHI. Legacy systems that cannot support MFA must be network-isolated and compensating controls documented.
- Segmentation design (60-90 days): Produce a segmentation architecture separating clinical, IoMT, administrative, and guest networks. Begin implementation with the highest-risk enclaves.
- Incident response testing (ongoing): Run a tabletop exercise simulating a business associate compromise that degrades your operations — the Change Healthcare scenario. Validate your downtime procedures and restoration sequencing against a 72-hour recovery objective.
- Compliance documentation (ongoing): Formalize adoption of HICP or NIST CSF as your recognized security practice and retain implementation evidence.
Organizations that complete this sequence will be positioned to comply with any realistic bill that emerges from this legislative session — and, more importantly, will be materially harder to breach regardless of what Congress does.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.