Senate passes bill directing HHS to require MFA and encryption under HIPAA

One passed the Senate on September 30 and would have HHS require MFA and encryption. The other aids rural hospitals.
By admin
Oct 9, 2026, 10:39 AM

The Senate passed a bill on September 30 that would order HHS to make multifactor authentication (MFA) and encryption mandatory under the HIPAA Security Rule. If you’ve been waiting on the agency’s own delayed rule update before you budget for those controls, Congress is now pushing on the same door.

The Health Care Cybersecurity and Resiliency Act (S 3315) passed by unanimous consent. Two weeks earlier, on September 15, the House Energy and Commerce Health Subcommittee held a hearing that covered a discussion draft of that bill and a second bipartisan measure, the Rural Hospital Cybersecurity Enhancement Act (HR 9908). The Senate bill would add security requirements for the healthcare sector, while the rural hospital bill focuses on resources and support.

The Senate bill tells HHS to require specific controls

Sens. Bill Cassidy (R-LA), John Cornyn (R-TX), Maggie Hassan (D-NH) and Mark Warner (D-VA) sponsored S 3315, and it grew out of a bipartisan healthcare cybersecurity working group. It landed on the Senate legislative calendar in March.

The part that hits your budget is Section 8. It directs the HHS secretary to update the HIPAA Security Rule so that it requires a baseline of risk-based security practices. The bill names three:

  • Multifactor authentication or a successor technology
  • Encryption of protected health information or a successor technology
  • Monitoring, including penetration testing, to keep information systems protected

HHS would add other baseline standards drawn from national frameworks such as those from the National Institute of Standards and Technology. The requirements would reach covered entities, business associates and non-governmental organizations in the healthcare and public health sector. The updated regulations would take effect 36 months after enactment, and the secretary could use enforcement discretion for organizations facing extraordinary circumstances.

That list should sound familiar. HHS’s own proposed Security Rule update would also require encryption and MFA. Industry groups objected to the cost and the implementation timelines, and HHS now targets July 2027 for the final rule, a year later than planned.

Ryan Higgins, a partner in the health and life sciences practice at law firm McDermott Will & Schulte, reads the bill as a response to that delay.

“I sense here some legislative frustration with the administration not having published a final rule yet that would contain some of these requirements,” Higgins told Digital Health Insights.

So the bill would not go around HHS. It would order the agency to put these controls into the Security Rule on a timeline Congress sets.

The bill isn’t only mandates. It gives HHS one year to write regulations on how recognized security practices count in an organization’s favor when the agency sets fines, ends audits early or settles potential Security Rule violations.

It also directs HHS and the Cybersecurity and Infrastructure Security Agency (CISA) to coordinate on cybersecurity for healthcare and public health. It has HHS issue best-practice guidance to rural providers and give them technical assistance to act on it.

Federally qualified health centers, nonprofit hospitals, rural health clinics and Indian Health Service facilities could qualify for grants to adopt cybersecurity best practices. The money is another matter. The committee version authorized funding for the grants for fiscal years 2026 through 2030, and the text the Senate passed leaves that authorization out.

Coordination is the harder promise to keep.

“A lot of focus is on interagency coordination and public-private coordination. In some ways, [that is] easier said than done,” Kevin Coy, partner and chair of the privacy and cybersecurity practice at law firm Arnall Golden Gregory, told Digital Health Insights. “One of the focuses of the resiliency bill is to get a primary coordinator within HHS to help lead the effort there.”

In its statement to the House subcommittee, the American Hospital Association (AHA) welcomed the coordination, grant and workforce training provisions. It also asked the committee to clarify how the cybersecurity standards apply to third-party vendors, which it says should meet the same privacy and security standards as covered entities and business associates.

The rural hospital bill puts the homework on HHS

The Rural Hospital Cybersecurity Enhancement Act comes from Reps. Erin Houchin (R-IN-09) and Kim Schrier (D-WA-08), along with several cosponsors. It starts from a problem every rural CIO knows firsthand. There aren’t enough people and there isn’t enough money.

So the bill asks nothing new of rural hospitals. It tells the HHS secretary to build a workforce development strategy that would do three things:

  • Identify the cybersecurity workforce challenges rural hospitals face and ways to mitigate them
  • Develop cybersecurity curriculum and resources for educational institutions in rural areas
  • Consider partnerships between rural hospitals and those institutions

HHS would also have one year after enactment to publish free materials rural hospitals can use to train staff on cybersecurity.

“Our bill takes a targeted approach by directing HHS to develop a comprehensive rural hospital cybersecurity workforce strategy, expand cybersecurity training resources, and improve preparedness against these growing threats,” Houchin said during the hearing.

The AHA told the subcommittee it supports the bill.

Congress and HHS are naming the same controls

Neither bill is law, and S 3315 still has to clear the House. But the Senate bill and HHS’s own proposal name the same controls. Whether the push comes from Congress or the agency, MFA, encryption and penetration testing look less and less optional.


Carrie Pallardy, a Chicago-based freelance writer and editor, began her career covering healthcare more than a decade ago. Her work has taken into many different industries, but covering healthcare delivery remains a constant focus. She can be reached at [email protected] or on LinkedIn.


Show Your Support

Subscribe

Newsletter Logo

Subscribe to our topic-centric newsletters to get the latest insights delivered to your inbox weekly.

Enter your information below

By submitting this form, you are agreeing to DHI’s Privacy Policy and Terms of Use.