S. 3315, the Health Care Cybersecurity and Resiliency Act: What It Means for HIPAA (2026)
S. 3315, the Health Care Cybersecurity and Resiliency Act of 2026, passed the U.S. Senate by unanimous consent on September 30, 2026, but it is not law. This guide explains what it would require of HIPAA covered entities and business associates, the breach letter change, the 36-month timeline, and what to do now. Verified October 6, 2026.