The US Senate passed the Health Care Cybersecurity and Resilience Act by unanimous consent, moving a bipartisan bill that would fund cyber defenses across the healthcare sector to the House of Representatives. The passage was reported on October 5, and the exact date of the Senate vote was not stated in the coverage available.
What the Health Care Cybersecurity and Resilience Act Would Fund
The bill provides grants for preventing and responding to cyberattacks, along with training, stronger coordination between federal agencies and improved cybersecurity practices for rural providers. It would, if enacted, pay for and coordinate healthcare cyber defense, according to the reporting on the measure. The grants cover both prevention and response, so they are meant to help providers stop attacks and recover from them.
The legislation is sponsored by Senators Bill Cassidy, Maggie Hassan, John Cornyn and Mark Warner. One report spells Cornyn’s first name “Jon,” an apparent error given that the senator is John Cornyn.
A Bill That Failed in 2024 and Returned in December 2025
The measure has a history. Lawmakers first introduced it in 2024, and it failed that term without becoming law. Sponsors reintroduced it in December 2025, and the Senate has now cleared it without objection. Passage by unanimous consent means no senator objected to moving it forward, though that does not guarantee the House will take it up or pass it in the same form. Senate passage is the first step; the House must still act before the bill can reach the president.
Training and stronger interagency coordination are the two non-grant elements. The coverage does not name the agencies involved or describe how the coordination would work.
The Breach Figures Behind the Push for Federal Healthcare Cyber Funding
Supporters cited a series of numbers to make the case. Spread across the 730-plus breaches, 270 million affected Americans works out to roughly 370,000 people per breach, though a few very large incidents account for much of that total. More than 730 breaches affected over 270 million Americans last year, at an average cost of $10 million per incident. Backers also pointed to the Change Healthcare attack, in which 190 million people are believed to have been exposed, and to the 2024 ransomware attack on Ascension.
Change Healthcare involved an estimated 190 million people, and Ascension involved a major ransomware attack in 2024. Those are the only two incidents the coverage names. Supporters cited both as the scale of risk the bill is meant to address.
Rural Provider Support in the Health Care Cybersecurity Act
The bill includes improved cybersecurity practices for rural providers. The bill’s text, as described, does not say how much money would be provided or how it would be divided between provider types, and those details will matter once the House takes up the legislation.
The bill is bipartisan, sponsored by Senators Bill Cassidy, Maggie Hassan, John Cornyn and Mark Warner, and it cleared the Senate by unanimous consent.
Next Steps in the House and the Question of Funding Levels
The bill now awaits House consideration. The bill failed in 2024 and was reintroduced in December 2025, so the House will decide whether this attempt succeeds. The coverage describes grants for prevention and response, training, interagency coordination and rural provider practices, but it gives no dollar figure for any of them and does not say which providers would qualify first.
The reported measure provides grants and does not describe new mandates. The coverage does not state funding levels or which agency would administer the grants, so the bill’s practical effect on providers remains uncertain.
