S. 3315, the Health Care Cybersecurity and Resiliency Act: What It Means for HIPAA (2026)
HIPAA Compliant Hosting · https://hipaacomplianthosting.com/blog/s-3315-health-care-cybersecurity-and-resiliency-act
Last updated: October 6, 2026
S. 3315, the Health Care Cybersecurity and Resiliency Act of 2026, passed the U.S. Senate by unanimous consent on September 30, 2026. It is not law yet. As of October 6, 2026, S. 3315 still needs a House vote and the President's signature. If it becomes law, HHS must update the HIPAA Security Rule. Covered entities and business associates would then need multifactor authentication, encryption of protected health information, and monitoring that includes penetration testing. Those rules would start 36 months after enactment. Breach letters would also have to state, to the extent possible, how many people were affected. We sell HIPAA hosting and security testing, so weigh our view accordingly. Bill text and status below were read on October 6, 2026.
TL;DR: Quick answer
S. 3315 is a federal bill in the 119th Congress, sponsored by Senator Bill Cassidy (R-LA). Some news coverage calls it SB 3315. It is not a state bill.
The Senate passed it on September 30, 2026, by unanimous consent. No roll call vote was taken on the floor. As of October 6, 2026, Congress.gov shows no House action on it.
Section 8 would make HHS require multifactor authentication, encryption of PHI, and monitoring that includes penetration testing. The new rules would take effect 36 months after enactment.
It names HIPAA covered entities, business associates, and other non-governmental entities in the Healthcare and Public Health Sector.
Breach notices to individuals would add one item: "The number of individuals affected by the breach".
HHS would have one year after enactment to write rules on how recognized security practices can lower HIPAA fines and shorten audits.
Nothing changes today. The current Security Rule still applies, and HHS lists July 2027 for final action on its separate Security Rule proposal.
What is S. 3315, the Health Care Cybersecurity and Resiliency Act?
S. 3315 is the Health Care Cybersecurity and Resiliency Act of 2026. Senator Bill Cassidy (R-LA) introduced it on December 2, 2025, as the "Health Care Cybersecurity and Resiliency Act of 2025". The original cosponsors were Senators Maggie Hassan (D-NH), John Cornyn (R-TX), and Mark Warner (D-VA). Senators Cindy Hyde-Smith (R-MS) and Angus King (I-ME) joined on September 30, 2026.
The long title states the main aim. HHS and the Cybersecurity and Infrastructure Security Agency (CISA) are "to coordinate to improve cybersecurity in the health care and public health sectors". Much of the bill sets up federal plans, reports, training, and grants. Four sections matter most to businesses that hold PHI: Sections 2, 6, 7, and 8.
Section 2 borrows HIPAA's own terms. "Covered entity" and "business associate" take their meanings from 45 CFR 160.103. So a covered entity or a business associate under HIPAA today would be one under S. 3315 too.
Some news coverage writes the number as "S.B. 3315" or SB 3315. The official record calls it S. 3315, a U.S. Senate bill. In his floor remarks, Senator Cassidy said the bill "would ensure health institutions can safeguard Americans' health data against increasing attacks".
Where S. 3315 stands as of October 6, 2026

The bill went through one Senate committee and then the Senate floor. The table follows the official actions on Congress.gov, the bill status file on GovInfo, and the Congressional Record.
Date | What happened | Source |
|---|---|---|
December 2, 2025 | Introduced and referred to the Senate HELP Committee | Congress.gov actions |
February 26, 2026 | HELP ordered it reported with a substitute amendment | Congress.gov actions |
March 23, 2026 | Reported without a written report; placed on the calendar as No. 365 | Congress.gov actions |
June 9, 2026 | Senator Cassidy's substitute, amendment No. 5819, submitted | GovInfo bill status |
September 15, 2026 | House Energy and Commerce Health Subcommittee hearing on an unnumbered House discussion draft | Energy and Commerce |
September 30, 2026 | Passed the Senate by unanimous consent with amendment No. 5819; no recorded vote | Congressional Record, pages S5231 to S5236 |
October 3, 2026 | Latest bill status update; Senate passage is still the latest action | GovInfo bill status |
Next | House passage, Senate agreement to any House changes, and the President's signature | Pending |
On September 30, Senator Cassidy asked for unanimous consent to pass the bill with his substitute. The presiding officer answered, "Without objection, it is so ordered". That means no senator objected. It does not mean every senator voted yes, because no vote was recorded. Some news reports gave October 1 as the date. The Congressional Record and the Senate-passed text both say September 30, 2026.
To become law, S. 3315 needs more steps. The House must pass it. If the House changes the text, the Senate must agree to the changes. Then the bill goes to the President. On the House side, there is no numbered companion bill yet. The Health Subcommittee hearing listed "H.R. ___, [Health Care Cybersecurity and Resiliency Act of 2026]" as a discussion draft.
Time matters too. A Congressional Research Service guide says bills not enacted during a Congress "die" and must be reintroduced. The same guide says each Congress begins on January 3 after a federal election. So the 119th Congress runs out in early January 2027.
What S. 3315 would require: the Section 8 security standards

Section 8 is the part most HIPAA-regulated businesses would feel. It tells HHS to update the HIPAA Security Rule at 45 CFR part 160 and subparts A and C of part 164. The updated rule would cover "non-governmental entities in the Healthcare and Public Health Sector and covered entities and business associates". Each would have to adopt "minimum risk-based cybersecurity practices, including":
"multifactor authentication, or a successor technology".
"encryption of protected health information, or a successor technology".
"requirements to conduct monitoring, including penetration testing, to maintain the protections of information systems".
"other minimum cybersecurity standards, as reflected in national cybersecurity frameworks".
HHS would base the practices on national frameworks. The text names these sources:
The NIST Risk Management Framework or the NIST Cybersecurity Framework.
NIST SP 800-53 Revision 5, with relevant parts of the NIST Privacy Framework.
The NIST Artificial Intelligence Risk Management Framework.
The Healthcare and Public Health Cybersecurity Performance Goals, which the bill credits to the Health Sector Coordinating Council.
CISA's health care cybersecurity performance goals.
The start date is fixed in the text. The updated rules "shall take effect on the date that is 36 months after the date of enactment". So the rules would take effect three years after enactment, which has not happened yet. The text sets that date, but it gives HHS no deadline to publish the updated rules. HHS "may exercise enforcement discretion for entities experiencing extraordinary circumstances".
The text leaves the details to HHS. It does not say how often to test, which systems need MFA, or what encryption strength counts. The introduced version required MFA "for access to any information systems that may include protected health information". The passed text dropped that phrase. S. 3315 does not say "at rest and in transit". That wording is in HHS's separate 2025 proposal.
How Section 8 compares with today's rule and HHS's 2025 proposal
Control | Security Rule today | S. 3315, if enacted | HHS proposal, 90 FR 898 |
|---|---|---|---|
Multifactor authentication | Not named; 45 CFR 164.312(d) requires verifying that a person "is the one claimed" | "multifactor authentication, or a successor technology" | MFA on "all technology assets" in relevant electronic information systems |
Encryption | Addressable under 164.312(a)(2)(iv) and (e)(2)(ii) | "encryption of protected health information, or a successor technology" | Encrypt all ePHI at rest and in transit, with limited exceptions |
Penetration testing | Not named; 164.308(a)(8) requires periodic evaluation | "monitoring, including penetration testing"; no frequency in the text | At least once every 12 months, or more often if the risk analysis calls for it |
Vulnerability scanning | Not named | Not named | No less often than once every six months |
Start date | In force now | 36 months after enactment | Proposed only; final action listed for July 2027 |
The bill and the proposal point the same way. The proposal is HHS rulemaking under existing law, so HHS can still finish it, change it, or drop it. S. 3315 would add a direct order from Congress with a fixed start date. For the MFA side today, see HIPAA MFA requirements.
Who S. 3315 would cover

Section 8 names three groups. Two come straight from HIPAA. The third goes beyond it.
Who | Covered by Section 8? | Basis |
|---|---|---|
Health plans, health care clearinghouses, and providers that send covered HIPAA transactions electronically | Yes | Covered entity, 45 CFR 160.103 |
Vendors that create, receive, maintain, or transmit PHI for a covered entity, such as hosting, IT, and billing vendors, whether or not they have signed a BAA | Yes | Business associate, 45 CFR 160.103 |
Subcontractors of those vendors | Yes | 160.103 counts subcontractors as business associates |
Other private companies in the Healthcare and Public Health Sector | Named, but the text does not define which ones | "non-governmental entities in the Healthcare and Public Health Sector" |
Medical devices | No carve-out in the Senate text | The House discussion draft adds a medical device exclusion |
Consumer health apps outside HIPAA | Not named | Only if HHS treats them as part of the sector |
The third group is the open question. The bill uses the sector "as identified in National Security Memorandum-22", dated April 30, 2024. CISA says "the vast majority of the sector's assets are privately owned and operated". The sector's 2016 plan, hosted by CISA, lists six private subsectors. One is health information technology, which it says includes "electronic medical record systems vendors". The bill does not say which of these companies the rule would reach. HHS would likely settle that when it writes the rule.
For HIPAA businesses, the answer is simpler. If you are a covered entity or a business associate, S. 3315 names you directly. Your BAAs already bind vendors to the Security Rule under 45 CFR 164.314. So a stricter rule would flow down your whole vendor chain. Our guide to the HIPAA business associate agreement covers that chain.
How S. 3315 changes breach notification letters

Section 6 would amend section 13402(f) of the HITECH Act. That subsection lists what a breach notice to individuals must say. Today it has five items, "to the extent possible":
What happened, with the breach date and discovery date, if known.
The types of unsecured PHI involved.
Steps individuals should take to protect themselves.
What the covered entity is doing to investigate, limit losses, and prevent more breaches.
How to ask questions, including a toll-free number, email address, website, or postal address.
S. 3315 would add a sixth item: "The number of individuals affected by the breach". HHS's matching regulation, 45 CFR 164.404(c), lists the same five items today. The bill does not change the outer deadline in 164.404(b), which is 60 calendar days after discovery. Breaches of 500 or more people already go to HHS at the same time, under 164.408(b). Our Breach Notification Rule entry explains the full process.
Business associates feed this count. Under 45 CFR 164.410(c), a business associate's notice to its client must identify each affected person, to the extent possible. A hosting or software vendor that cannot say whose records were exposed leaves its client guessing at the number.
Crowell & Moring, a law firm, wrote about the committee version on March 11, 2026. It said the count could "increase the likelihood that larger breaches will attract class action lawsuits". That is one firm's view, not a finding. For how big recent breaches have been, see our healthcare data breach statistics.
Recognized security practices: how S. 3315 ties security work to HIPAA fines

Section 7 builds on a law from January 2021, section 13412 of the HITECH Act. That law tells HHS to consider "recognized security practices" when it sets fines, shortens audits, or agrees on remedies. The practices must have been in place "for not less than the previous 12 months".
The current law points to NIST practices, the approaches HHS publishes under section 405(d) of the Cybersecurity Act of 2015, and other recognized programs. It also says this section creates no liability for choosing not to use them. And it gives HHS no power to raise fines because an entity skipped them.
S. 3315 would change three things. It adds "investments" to the definition, next to "other programs". It also orders HHS to write regulations within one year of enactment. Those rules must cover four things:
Which recognized security practices HHS may consider when it sets fines.
How fully those practices must be in place to count.
What a covered entity or business associate must submit to HHS.
How HHS will weigh them "when determining fines, earlier favorable termination of audits, or mitigating remedies".
Third, from two years after enactment, HHS's annual report to Congress would list every case where it considered these practices. The 12-month lookback already exists, so the useful habit starts now. Pick a framework, map your controls to it, and keep dated evidence. Our guide to HIPAA violation fines and penalties shows what is at stake.
What S. 3315 means for healthcare websites, hosting, and vendors

The bill text never mentions websites, tracking pixels, or hosting. Its reach comes through the Security Rule, which protects electronic PHI wherever an entity keeps it. A patient portal, intake form, or booking page that stores or sends PHI runs on systems the updated rule would cover.
Admin and hosting logins. The CMS admin, hosting control panel, SSH, and database console guard the servers that hold PHI. They are the obvious first place for MFA.
Forms and databases. Encryption of PHI would cover what your forms collect and where submissions are stored. Today encryption is addressable. Section 8 would have HHS require it as one of several "minimum risk-based" practices. See HIPAA compliant forms.
Portals and custom apps. These are natural targets for the penetration testing Section 8 describes. HHS would set how often.
Tracking pixels and analytics. S. 3315 does not address them. Those questions still run through HIPAA's existing privacy rules and BAAs; see HIPAA tracking technologies.
Hosting and cloud vendors. Vendors that store PHI for you are business associates, so the updated rule would bind them directly. Ask each one how it handles MFA, encryption, and testing today.
Rural providers and grants. Section 9 would order rural guidance within one year, including "migrating data to secure cloud-based platforms". Section 10 would let HHS give grants to federally qualified health centers, Indian Health Service facilities, nonprofit hospitals, rural health clinics, and partner nonprofits. The passed text has no authorization of appropriations for those grants.
What to do now, before S. 3315 becomes law

Nothing in S. 3315 binds anyone today. But its core controls already match where HHS points. HHS's voluntary Cybersecurity Performance Goals list multifactor authentication and strong encryption as essential goals. They list cybersecurity testing as an enhanced goal. These eight steps help under today's rule and would give you a head start if the bill passes.
Update your risk analysis. 45 CFR 164.308(a)(1)(ii)(A) already requires "an accurate and thorough assessment" of risks to ePHI. See our HIPAA risk analysis guide.
Turn on MFA for admin, remote access, email, and hosting logins first.
Encrypt ePHI in databases, backups, and form submissions, and in transit. Write down any exception and the reason.
Book a penetration test of each portal, site, or app that handles PHI. Fix what it finds, then retest.
Map your controls to one framework, such as the NIST Cybersecurity Framework or HHS's 405(d) practices. Keep 12 months of dated evidence.
Add the affected-individual count to your breach response template. Check that vendor BAAs require notice that names each affected person.
Ask your hosting, EHR, and form vendors, in writing, how they handle MFA, encryption, and testing.
Watch two places: Congress.gov for House action, and the federal Unified Agenda for the Security Rule.
How S. 3315 fits with the proposed HIPAA Security Rule update
HHS proposed its own Security Rule update on January 6, 2025, at 90 FR 898. Comments closed on March 7, 2025. The latest Unified Agenda entry lists final action for July 2027, as a long-term action. Our new HIPAA Security Rule tracker follows that track.
The two tracks overlap, but they are separate. Neither the bill nor the proposal says how HHS would merge them if both move ahead. S. 3315 would also have HHS name one official to lead cybersecurity coordination. That role "shall not include implementation or enforcement" of the HIPAA Security Rule. So Security Rule enforcement would not move to the new role.
What could still change before S. 3315 becomes law
The House text. The House discussion draft matches the four Section 8 practices and the 36-month start. It adds a medical device exclusion that the Senate text does not have.
The calendar. If the bill is not enacted before the 119th Congress ends, it would have to be reintroduced in the next Congress.
The rules. HHS would write the details, including which sector companies are covered and how often to test.
Funding. The Senate removed the grant program's authorization of appropriations on the floor. Any grant money would depend on later spending decisions.
Old summaries. The introduced bill named the Assistant Secretary for Preparedness and Response to lead HHS cyber work. It also had a breach reporting portal section. Neither made it into the passed text.
If you want a head start on the S. 3315 controls
We sell this, so weigh it as a disclosure. Section 8 names penetration testing and ties the other controls to national frameworks. Two of our services line up with that. Our penetration testing agrees scope and rules of engagement in writing before any test. Testing is manual, supported by tooling. Findings are ranked by risk, and a retest confirms your fixes. Our cyber security audit checks your controls, policies, and configurations against the framework you work to, including HIPAA.
If your PHI sits on servers you run yourself, our managed HIPAA cloud hosting runs on single-tenant AWS. We sign the BAA within 24 hours, and 4 hours of migration and configuration are included. Our BAA covers only the servers and services we run.
Here is the honest inverse. S. 3315 is not law, so nothing is due under it today. If your EHR vendor holds all your PHI and already tests its systems, and your website collects no PHI, you may need nothing from us. If you are unsure, take our HIPAA compliance assessment or request a quote. Our HIPAA compliant hosting plans are listed on the site.
Frequently asked questions
Is S. 3315 law yet?
No. As of October 6, 2026, S. 3315 has passed the Senate only. The Senate passed it by unanimous consent on September 30, 2026. The House must pass it, and the President must sign it (or let it become law without signing), before it becomes law.
Is SB 3315 a state bill?
Not this one. The SB 3315 in health care cybersecurity news is S. 3315, a U.S. Senate bill in the 119th Congress. State legislatures sometimes use the same number for unrelated bills.
When would the S. 3315 requirements take effect?
The Section 8 security rules would take effect 36 months after enactment. HHS's recognized security practices rules would be due within one year of enactment. The text sets no delayed start for the breach letter change.
Does S. 3315 apply to business associates and hosting companies?
Yes, if it becomes law. Section 8 names business associates directly, using the HIPAA definition in 45 CFR 160.103. That definition covers vendors that store or transmit PHI for a covered entity, and their subcontractors.
Does S. 3315 require penetration testing?
If enacted, it would direct HHS to require "monitoring, including penetration testing". It does not set a frequency. HHS's separate 2025 proposal would require a test at least once every 12 months, but that proposal is not final.
Does S. 3315 change HIPAA penalty amounts?
No. It does not change the penalty tiers. If enacted, it would order HHS to write rules on how recognized security practices can lower fines and shorten audits.
Does S. 3315 cover health apps that are not under HIPAA?
Not by name. Section 8 would reach non-governmental entities in the Healthcare and Public Health Sector, and HHS would likely settle that scope in its rules. Personal health record vendors outside HIPAA fall under the FTC's Health Breach Notification Rule today. A separate privacy bill, S. 3097, the Health Information Privacy Reform Act, is also pending in the Senate. It is not part of S. 3315.
Recap: S. 3315
S. 3315, the Health Care Cybersecurity and Resiliency Act of 2026, passed the Senate by unanimous consent on September 30, 2026. As of October 6, 2026, it is not law. If enacted, HHS must require MFA, encryption of PHI, and monitoring with penetration testing, starting 36 months later. Breach letters would state the number of people affected. Start on those controls now, because HHS's 2025 proposal and its voluntary performance goals already point the same way. If you want an outside check first, a penetration test of your PHI systems is a practical place to start.
This article is general information, not legal advice. Bill text and status were read on October 6, 2026, from Congress.gov, GovInfo, and the Congressional Record. S. 3315 is not law, and the House can still change its text. Confirm current law with counsel, and base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting, penetration testing, and security audits. Reviewed October 2026.
Sources
Congress.gov: S. 3315 bill page and all actions.
GovInfo: Senate-passed text, reported text, introduced text, and bill status file.
Congressional Record, Vol. 172, No. 155: Senate, September 30, 2026, pages S5231 to S5236.
House Energy and Commerce: hearing announcement, September 8, 2026, and the House discussion draft.
U.S. Code (GovInfo, 2024 edition): 42 U.S.C. 17932, breach notification and 42 U.S.C. 17941, recognition of security practices.
eCFR: 45 CFR 160.103, 164.308, 164.312, 164.314, 164.404, 164.408, 164.410, and 16 CFR part 318.
HHS Security Rule proposal: 90 FR 898, January 6, 2025, and the Unified Agenda entry for RIN 0945-AA22.
HHS 405(d): HPH Cybersecurity Performance Goals highlights.
CISA: Healthcare and Public Health Sector and the Healthcare and Public Health Sector-Specific Plan (2016; CISA labels it 2015).
Congress.gov: S. 3097, Health Information Privacy Reform Act.
Congressional Research Service: Federal Legislative History, R48533, May 9, 2025.
Secondary, law firm commentary on the committee version: Crowell & Moring, March 11, 2026.
Secondary, news coverage that styles the bill S.B. 3315 and gives an October 1 date: HIPAA Journal, October 5, 2026.