Healthcare Cybersecurity Act of 2025
The Healthcare Cybersecurity Act of 2025 requires the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) to improve coordination on cybersecurity for healthcare facilities and systems. It mandates a new agency liaison to the HHS, updates a sector-specific risk management plan within one year (focusing on rural and small providers), and establishes a process to identify "high-risk" healthcare assets for prioritized support. The bill also requires CISA to provide cybersecurity training for healthcare owners/operators and report on support efforts to Congress. This directly affects hospitals, clinics, and health systems - especially smaller or rural facilities - by creating new coordination mechanisms and risk assessment requirements to address rising cyber threats.
Bill status
in committee
1 of 4 stages cleared
Introduction
May 2025
Committee Review
Floor Vote
President
Introduced May 21, 2025
Last action May 21, 2025
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
2
Key actions
0
Committee
1
May 21, 2025
Committee
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
upper
May 21, 2025
Introduced
Introduced in Senate
upper
1 primary · 3 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Jacky Rosen
DDemocratic
Co
Angus S. King, Jr.
IIndependent
Co
Thom Tillis
RRepublican
Co
Todd Young
RRepublican
Ask Maddy
·
AI policy assistant
Ask Maddy about S 1851
Scope: US
Hi! I can help you understand S 1851. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline