Yaamlabs
Regulation

Senate passes health care cyber bill: MFA, encryption next

S. 3315 passed the Senate and now needs the House. What it would require of providers and vendors, when, and what is worth doing before it is law.

By Yaali. October 9, 2026, 6 min read, Regulation, Resilience, Identity.

Cover illustration of a hospital building behind a glowing shield with a padlock and a heartbeat line, with the Yaamlabs logo and the text: Passed the Senate, not yet law. Senate passes a HIPAA security overhaul, 36 months after enactment: MFA and encryption required

The US Senate has passed S. 3315, the Health Care Cybersecurity and Resiliency Act of 2026, by unanimous consent. The Senate-passed text records the vote on September 30, 2026; some outlets reported it on October 1 or 2. The bill tells the Department of Health and Human Services (HHS) to rewrite the HIPAA Security Rule so that hospitals, clinics, health plans and their vendors must use multifactor authentication (MFA), encrypt protected health information (PHI) and run penetration tests.

It is not law. The House of Representatives still has to pass it and the President has to sign it, and none of its deadlines start until then. If you run IT or security for a provider, or for a company that handles PHI on a provider's behalf, the controls it names are the ones that failed at Change Healthcare in 2024, and they are worth checking now.

Timeline of S. 3315: Change Healthcare breach in February 2024, the proposed HIPAA Security Rule in January 2025, introduction in December 2025, committee approval 22 to 1 on February 26, 2026 and Senate passage on September 30, 2026; if enacted, HHS plans within one year, a GAO report within three years and minimum standards in force at 36 months

What the bill would require

Section 8 carries the obligations. HHS must update the HIPAA Security Rule (45 CFR part 160 and subparts A and C of part 164) so that covered entities, business associates and other non-governmental organisations in the health sector adopt "minimum risk-based cybersecurity practices". Four are named: MFA or a successor technology, encryption of PHI or a successor technology, monitoring that includes penetration testing, and other minimum standards drawn from national frameworks.

The baseline has to be built from the NIST Cybersecurity Framework, NIST SP 800-53 revision 5, the NIST Risk Management Framework or the NIST AI Risk Management Framework, plus the health sector Cybersecurity Performance Goals published by HHS and CISA (the Cybersecurity and Infrastructure Security Agency). The new rules take effect 36 months after enactment. HHS may use enforcement discretion for organisations in "extraordinary circumstances", which the bill does not define.

Business associates are named directly. A billing company, clearinghouse, cloud EHR host or managed service provider that handles PHI would carry the same MFA and encryption duties as the hospital it serves.

The rest of the bill gives HHS and Congress more information and coordination:

  • Breach notices under the HITECH Act must state the number of individuals affected (section 6).
  • Within a year, HHS must write rules on how it credits "recognized security practices" when setting HIPAA fines and ending audits early. Section 13412 of the HITECH Act already requires HHS to consider practices in place for the previous 12 months; the bill adds "investments" to what counts (section 7).
  • Within a year, HHS and CISA must agree a joint plan for sector-wide incidents, and HHS must expand the cyber annex of its own all-hazards plan (sections 3 and 5).
  • Within a year, HHS must convene a working group with CISA, the SEC, the FBI, the FTC, state attorneys general and industry to cut duplicate incident reporting, and report back to Congress (section 12).
  • HHS must issue rural cybersecurity guidance within a year, and the GAO reports on its use within three years (section 9).

Grants are authorised but not funded. HHS "may award" grants of up to three years to federally qualified health centres, Indian Health Service facilities, nonprofit hospitals, rural health clinics and nonprofits that partner with them. An earlier draft authorised "such sums as may be necessary"; the passed text has no funding line, so the amount depends on appropriations. For-profit hospitals and private practices are not eligible.

Why Change Healthcare shaped it

In February 2024 the ALPHV/BlackCat ransomware group got into Change Healthcare, the UnitedHealth Group claims processor, using stolen credentials on a Citrix remote access portal that did not have MFA turned on. UnitedHealth's chief executive, Andrew Witty, told Congress in May 2024 that company policy required MFA on external systems and that this portal had been missed. Data was taken and ransomware was deployed nine days after the first login.

Claims and pharmacy processing across the US stalled for weeks, and in July 2025 the company put the number of people affected at 192.7 million. Senators cited the attack throughout the bill's progress.

The proposed rule from HHS would reach many of the same places. The Office for Civil Rights published it in January 2025: it would make encryption and MFA mandatory, end the "addressable" label that lets organisations document an alternative, and require a technology asset inventory and network map. HHS estimated first-year costs of about $9 billion. Its final rule has slipped to July 2027 at the earliest, and the administration has not said whether it will be issued. The statute would fix the controls in law whatever happens to the rule.

What has to happen next

The House Energy and Commerce Subcommittee on Health held a hearing on September 15 that included health care cybersecurity proposals, among them grants for adopting security practices. The House has not voted on S. 3315 and no date is set. It can pass the Senate text, change it, or let it lapse when the 119th Congress ends in January 2027. The earlier version, introduced in 2024, lapsed that way.

Read every date in the bill as "from enactment". If it were signed this year, MFA and encryption would become HIPAA requirements in late 2029.

What to do now

Four priorities for providers and business associates: MFA on all remote access this month, an asset and PHI map this quarter, reporting readiness before contract renewals, and ongoing evidence of recognized security practices

Find every login that skips MFA. List each internet-facing entry point: VPN, Citrix NetScaler Gateway, RD Gateway, webmail, EHR and billing portals, and vendor support tools. In Microsoft Entra ID, filter the sign-in logs on Authentication requirement equals "Single-factor authentication" and review the ones that come from outside your network. Then list the Conditional Access exclusions and service accounts that can sign in from the internet. Change Healthcare's portal was one forgotten exception.

Check whether those exceptions were already used. Look for successful single-factor sign-ins from unfamiliar countries or hosting providers, logins to dormant accounts, and remote sessions outside working hours. If you find one, reset the account, revoke its sessions and check what it touched.

Build the asset and PHI map. Record each system, its owner, whether it stores or moves PHI and whether that data is encrypted at rest and in transit. Add the vendors you could not bill, prescribe or schedule without, and what you would do if one went down for a month.

Get incident reporting ready. Write down who you must notify and by when: HHS and patients under the HIPAA breach rule (within 60 days of discovery), state breach laws, the SEC if you are listed (Form 8-K within four business days of deciding an incident is material), and partners under contract. The bill would make the count of affected individuals a required field, so know which logs and databases would let you produce that number.

Keep the evidence. Map your controls to the NIST CSF or the health sector Performance Goals, keep penetration test reports and remediation tickets, and record MFA coverage. That record already counts under the HITECH Act today, and it is what the new rules would measure you against.

Vendors should expect these questions in contract renewals and business associate agreements before any law requires them.

If you want a gap assessment against the bill's controls or a penetration test of your remote access, see our compliance and audit readiness and network penetration testing services. Open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: S. 3315, Senate-passed text (GPO), S. 3315, reported text (GPO), Senate HELP section-by-section, HIPAA Journal, Paubox, SecurityWeek, CyberScoop, Health System CIO, American Hospital Association, TechTarget, Healthcare IT News.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.