This bill establishes a federal program to enhance water system security by supporting participation in the Water Information Sharing and Analysis Center (WISAC). It directly affects community water systems and publicly owned treatment works by offsetting their costs to join WISAC and improving EPA coordination with the center for threat monitoring. Key provisions include funding $10 million annually (2026-2027) to help water systems monitor threats, prepare for cyberattacks or natural hazards, and share incident data. The program aims to strengthen the water sector’s ability to detect, respond to, and recover from security incidents.
This bill reauthorizes and expands federal programs addressing the opioid crisis and related health issues through 2030, with increased funding for prevention, treatment, and recovery services. It provides specific funding increases for programs including prenatal and postnatal health services, fetal alcohol spectrum disorder prevention, first responder training, and community-based recovery centers. Key provisions include enhanced cybersecurity protections for suicide prevention hotlines, requirements for reporting on program effectiveness, and expanded support for individuals with substance use disorders through workforce development and peer support services. The bill directly affects healthcare providers, public health agencies, community organizations, and individuals seeking treatment for substance use disorders.
This bill requires major websites and online services (excluding small businesses) to provide a simplified, accessible summary of their terms of service within 360 days. The summary must clearly explain what sensitive data they collect (e.g., health, location, financial info), user rights (like arbitration waivers), data breach history, and estimated reading time, and must be placed prominently on their sites. It also mandates a graphic diagram showing how user data is shared with third parties and an interactive format for full terms. Violations can be enforced by the FTC or state attorneys general acting on behalf of residents.
This bill requires federal contractors with large contracts (over $250,000) or those managing government information systems to implement standardized processes for reporting security flaws. It directs federal agencies to update procurement rules to mandate these vulnerability disclosure policies, aligning with existing NIST cybersecurity guidelines and international standards like ISO 29147. Contractors must address potential security issues in systems used for government work, with limited waivers allowed only for national security reasons and requiring congressional notification. The policy applies directly to major federal contractors handling sensitive government data or systems. The bill does not authorize new funding for implementation.
The Enhanced Cybersecurity for SNAP Act of 2026 requires states to transition from magnetic stripe to chip-enabled EBT cards within 4-5 years, with specific deadlines for new cards and reissuing existing cards. It mandates states to provide multiple user interfaces for managing EBT accounts - including mobile-friendly web portals, text messaging, voice services, and nondigital options - all available 99% of the time in required languages. The bill requires states to provide real-time transaction notifications, access to historical transactions for the past year, and fraud reporting capabilities to SNAP recipients, while prohibiting PIN/password requirements that conflict with federal cybersecurity standards. It eliminates fees for replacing cards due to malfunction, fraud, or required upgrades and requires states to replace damaged or lost cards within 3 business days. Additionally, the bill includes a grant program to help retailers upgrade to chip-compatible payment terminals in areas with limited grocery access.
The Insure Cybersecurity Act of 2025 establishes a working group within the Commerce Department to improve clarity around cyber insurance policies. The working group, composed of federal agencies (like CISA and the FTC), state regulators, and stakeholders, will analyze and explain technical policy terms, coverage limitations, and how policies relate to common cyber incidents (such as ransomware) in plain language for customers - especially small businesses. It will develop voluntary resources for insurers, brokers, and customers to better evaluate coverage and understand policy terms, and submit a report to Congress within one year. The bill does not change insurance regulations but focuses on making existing policies more transparent and accessible.
The Rural Hospital Cybersecurity Enhancement Act requires the Secretary of Health and Human Services to develop a workforce strategy for rural hospitals within one year of enactment. This strategy must address cybersecurity staffing challenges, create partnerships with educational institutions, and develop training materials tailored to rural hospital needs. The bill also mandates the creation of accessible cybersecurity instructional materials for hospital staff and annual congressional briefings on progress. It directly affects rural hospitals - defined as non-urban facilities providing inpatient, emergency, and diagnostic care - without authorizing new funding. Implementation must use existing resources, focusing on practical workforce development and training.
This bill establishes the Department of Commerce as the lead federal agency for blockchain technology policy, designating the Secretary as the principal advisor to the President on blockchain deployment, use, and competitiveness. It creates a Blockchain Deployment Program to develop best practices for security, interoperability, and cost savings, while requiring the Secretary to form advisory committees with industry experts, small businesses, and cybersecurity stakeholders. The bill directly affects federal agencies (through guidance on adopting blockchain) and the private sector (via voluntary best practices for digital tokens and blockchain applications). It mandates annual reports to Congress on implementation progress, emerging risks, and recommendations for future legislation, with the program set to expire 7 years after enactment.
HR 3841, the Healthcare Cybersecurity Act of 2025, requires the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) to coordinate on improving cybersecurity for healthcare facilities. It mandates appointing a CISA-HHS liaison, updating a sector-specific risk management plan within one year (including analysis of impacts on rural and small facilities), and creating a biannually updated list of high-risk healthcare assets to prioritize support. The bill also directs CISA to provide training for healthcare providers on cybersecurity risks and mitigation. These provisions directly affect hospitals, clinics, and other healthcare entities handling patient data, aiming to reduce breaches and improve resilience against cyberattacks.
This bill (S 2605) creates special hiring and pay authorities to help the Department of Defense recruit and retain cybersecurity professionals. It allows the Secretary to establish "qualified positions" outside regular civil service hiring rules, set pay up to 150% of top executive rates, and offer flexible benefits like sabbaticals or retention bonuses. The policy directly affects DoD cyber workers in critical technical roles, including new hires and current employees in converted positions. It requires an implementation plan, annual reports tracking hiring/retention metrics, and a Comptroller General assessment to evaluate effectiveness.