A former colleague called me within hours of the Change Healthcare attack. His organization was down hard. I thought then what I think now: this was a structural failure, and it called for a standard. Change Healthcare went on to affect more than 192 million people, the largest healthcare breach on record.
The pace has held since. The HHS Office for Civil Rights breach portal posted 426 hacking-related breaches between January 1 and August 31, 2026, exposing the protected health information of 73 million Americans.
On September 17, Senators Mark Warner and Ron Wyden reintroduced the Health Infrastructure Security and Accountability Act. The bill pairs mandatory standards with $1.3 billion in funding. I support it, and I want to explain why.
I have been urging stronger protections for healthcare for nearly two decades. In that time the pattern has repeated: an incident, a round of attention, and a return to voluntary effort. This bill puts the three things I have argued for in one place: enforceable standards, independent verification and funding.
I have made the case publicly on voluntary standards. When HHS proposed voluntary cybersecurity performance goals in late 2023, I told HealthLeaders that voluntary measures were "akin to applying a band-aid on a hemorrhage," and I wrote in Healthcare Innovation that the sector needs a clear mandate for minimum standards. The argument has stayed the same because the problem has stayed the same.
On June 18, 2024, I took the same argument to Washington, on the "When Ransomware Strikes" panel at Semafor's Cybersecurity: Tackling the Policy Puzzle. Four months after Change Healthcare, hospitals had no leverage over the suppliers that could shut them down. I told the audience that "you can't even ask for a SOC 2 report" without being asked why you need it. On concentration risk, I said, "I'm libertarian by nature, but there has to be some kind of standard that says you can't put all your eggs in one basket." On what changes attacker behavior, I said, "We're never going to stop these people until the pain of the perpetrator is greater than the gain that they're getting."
Brian Mazanec of HHS said on the same panel that more needs to be done from a mandatory minimum standard perspective. I took that as a signal about where policy was headed.
What The Bill Would Require
The bill directs HHS to set minimum cybersecurity standards and refresh them every two years. The standards apply to covered entities, health plans, clearinghouses and business associates, with heightened requirements for systemically important entities. Senator Warner put the premise plainly, according to Fierce Healthcare: "Voluntary standards are not enough to protect Americans' health, safety, and privacy."
The core obligations are specific:
- Annual Risk Analysis: A documented risk analysis every year, not a periodic exercise.
- Annual Testing: Regular testing of security controls and of the ability to recover essential functions.
- Continuity Plans: Written plans for responding to cyber incidents, natural disasters and technology failures.
- Independent Audits: Security audits performed by a party outside the organization.
- Enforcement: Penalties of $5,000 per day for noncompliance, with criminal penalties for knowingly false reporting.
- Waivers: Available where the burden outweighs the benefit.
Why Ransomware Found Healthcare
Attackers follow economics, and healthcare offers them three advantages at once.
- Downtime Costs Lives: Patient care cannot pause, so an outage carries clinical risk as well as lost revenue. That pressure favors a fast payment.
- Durable Data: Health records stay sensitive for a lifetime, which raises the value of any theft that accompanies encryption.
- Uneven Defenses: Security investment varies widely across the sector, so attackers can choose a weakly defended entry point, often a smaller provider or a vendor connected to a larger one.
Standards that vary by organization produce defenses that vary by organization. A sector-wide minimum, verified independently, narrows the gap that attackers depend on.
Why Voluntary Standards Have Run Their Course
I have led more than 700 security risk assessments. The risk analysis is where I see the widest range in quality, and OCR sees the same thing: it remains the most frequently cited deficiency in its investigations. Some organizations run it as a working management tool. Others produce a document once and file it. At Semafor I described the skipped basics, such as rotating keys and passwords, as teeing it up with a beach ball for attackers.
From the outside, the two look identical. An independent audit tells them apart. A documented analysis tells a regulator what an organization says it did. A third-party audit tells the regulator what an outsider verified. After 426 breaches in eight months, the industry has earned the higher level of assurance.
Why The Funding Matters
The bill attaches $1.3 billion to the mandate. $800 million goes to roughly 2,000 rural and underserved hospitals as upfront payments over two years, and $500 million incentivizes enhanced security practices.
Do the math. $800 million across 2,000 hospitals averages $400,000 per hospital over two years. That will not build a mature program from nothing. It does fund a real assessment, remediation of the highest risks and a recovery test, which is where a small hospital should start. A standard with no funding asks the smallest hospitals to choose between security and services. Pairing the two is the right design, and the $1.3 billion is what makes the mandate credible.
The Case Against The Bill, And My Response
The objections deserve a direct answer.
- Cost Burden: Small practices and rural providers will bear real costs. The waiver provision and the hospital funding address part of this, and the waiver criteria will need careful drafting to avoid becoming a loophole.
- Audit Quality: Independent audits can degrade into a checkbox market if standards for auditors are weak. HHS should define auditor qualifications and scope with as much care as the security standards themselves.
- Legislative Odds: The 2024 version did not become law. Reintroduction by the minority party does not guarantee movement.
Each of these is a reason to get the details right, and a reason to start now.
What This Means For Business Associates
This bill is substantially the architecture of the stalled HIPAA Security Rule proposal, which HHS published in January 2025. The final rule has slipped from a May 2026 target to July 2027 on the OMB agenda, and that date is a planning estimate. The bill adds independent audits and per-day penalties on top of that structure.
My planning assumption is that a third-party audit requirement arrives by one route or the other. I hold it as an assumption, because both vehicles point the same direction. If it holds, "we performed a risk analysis" stops being a defensible answer without third-party attestation, and HITRUST or an equivalent framework moves from business associate differentiator to table stakes. A certification supports compliance; it does not make an organization compliant, and regulators will continue to draw that line.
Practical Steps For 2027
- Date Your Risk Analysis: Confirm it is current, documented and specific to your environment.
- Test Recovery: Run a recovery exercise and keep the evidence.
- Choose An Assessor Early: Independent audit capacity will tighten if either vehicle lands.
- Prepare Business Associate Evidence: Covered entities will ask their vendors for third-party attestation first.
Credit To Senator Warner
Senator Warner has treated healthcare cybersecurity as a patient safety issue for years. In November 2022 he published "Cybersecurity is Patient Safety", a policy options paper that called for stronger federal leadership, mandates and incentives, and a better ability to recover from attacks. He wrote that the sector's transition to better cybersecurity had been "painfully slow and inadequate." I was quoted alongside him on that paper at the Healthcare and Public Health Sector Coordinating Council (HSCC) meeting in Washington, DC, and I later discussed the paper on the ClearDATA podcast.
Nearly four years later, the ideas in that paper have become legislative text, with $1.3 billion attached to help hospitals meet the standards. Senator Warner and Senator Wyden have kept this issue in front of Congress through a major breach and a change in administration, and I thank them for it.
The Path Forward
I am calling on Congress to pass this bill with its $1.3 billion intact and on HHS to finish the Security Rule. Patients share their most sensitive information with the healthcare system, and they expect every reasonable effort to protect it. In eight months of this year, hacking breaches exposed the records of 73 million Americans. It is time to verify.