S5443119th CongressWALLET

Health Infrastructure Security and Accountability Act of 2026

Sponsored By: Senator Warner, Mark R. [D-VA]

Introduced

Summary

This bill would strengthen cyber protections for health data by creating a two-tier security regime that sets stricter rules for some health entities and layers in audits, penalties, and Medicare payment incentives.

Show full summary
  • Providers and business associates would face new minimum and enhanced security requirements, annual risk analyses, stress tests, and CEO/CISO sign-offs. Regulations must be issued within 18 months and most requirements would take effect about 2 years after enactment.
  • Hospitals that do not adopt enhanced cybersecurity practices would face payment penalties, including a 1.0 percentage-point cut to their annual update and a 1.0% reduction to DRG payments. Critical access hospitals would face smaller phased reductions that reach the same 1.0% level if noncompliant.
  • Enforcement gets dedicated funding. The bill would create a user fee based on an entity's share of national health spending and cap collections at $40.0 million in FY2028 and $50.0 million in FY2029. It also provides targeted CMS funding to support implementation.

Personalized for You

How does this bill affect your finances?

Personalize government policy and PRIA will tell you what this bill means for your household, plus every other piece of legislation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.

Bill Overview

Analyzed Economic Effects

3 provisions identified: 0 benefits, 1 costs, 2 mixed.

Medicare payments tied to cybersecurity

If enacted, the bill would offer payment pools to help hospitals adopt cybersecurity practices: $800 million for FY2029–FY2030 and $500 million for FY2031–FY2032, paid to eligible hospitals on request. At the same time, the bill would reduce Medicare payment updates and DRG base payments for hospitals that are non‑adopters in FY2031–FY2034 (gradually larger cuts from 0.25 to 1.0 percentage points and specific per‑discharge cuts in FY2032–FY2033). CMS could grant hardship exemptions, and the bill would also let Medicare make accelerated payments to providers after contractor disruptions or cybersecurity incidents.

New health-sector cybersecurity rules

If enacted, the bill would create a two-tier cybersecurity regime for all HIPAA-covered entities and business associates. It would add "availability" to legal protections for health data and require annual risk analyses, recovery plans, stress tests, and CEO/CISO attestations. Entities would need independent audits and the Secretary would audit at least 20 entities yearly starting 4 years after enactment, with biennial reports to Congress for 10 years. The bill would add civil penalties and criminal liability for false or willful failures, and require CMS to post state-level counts of hospitals that are not adopters.

New annual health data user fee

If enacted, the bill would charge each covered entity and business associate an annual fee based on its prior‑year revenue as a share of national health expenditures. Total collections would be capped each year: $40 million in FY2028, $50 million in FY2029, and thereafter the prior year cap adjusted by CPI‑U. Fees collected would be available to the Secretary without further appropriation and used only for oversight and enforcement.

Sponsors & CoSponsors

Sponsor

Warner, Mark R. [D-VA]

VA • D

Cosponsors

  • Sen. Wyden, Ron [D-OR]

    OR • D

    Sponsored 9/17/2026

Roll Call Votes

No roll call votes available for this bill.

View on Congress.gov
Back to Legislation