S. 3315

Sets cybersecurity rules for health care groups

Requires private health care groups to adopt minimum cybersecurity practices, and has federal health and cyber agencies coordinate, share training, and help rural providers.

  • Health care groups would have to use minimum security practices like multifactor authentication
  • Breach notices would have to say how many people were affected
  • Two federal agencies would write a joint plan for responding to major incidents
  • Rural health care groups would get guidance on cybersecurity readiness

Passed the Senate · House's turn

Read the full bill