S 1851 United States Senate · 119th Congress

Healthcare Cybersecurity Act of 2025

The Healthcare Cybersecurity Act of 2025 requires the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) to improve coordination on cybersecurity for healthcare facilities and systems. It mandates a new agency liaison to the HHS, updates a sector-specific risk management plan within one year (focusing on rural and small providers), and establishes a process to identify "high-risk" healthcare assets for prioritized support. The bill also requires CISA to provide cybersecurity training for healthcare owners/operators and report on support efforts to Congress. This directly affects hospitals, clinics, and health systems - especially smaller or rural facilities - by creating new coordination mechanisms and risk assessment requirements to address rising cyber threats.
Bill status in committee 1 of 4 stages cleared
Introduction
May 2025
Committee Review
Floor Vote
President
Introduced May 21, 2025 Last action May 21, 2025
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
2
Key actions
0
Committee
1
May 21, 2025
Committee
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
upper
May 21, 2025
Introduced
Introduced in Senate
upper
1 primary · 3 co-sponsors

Sponsors