Skip to main content
LAST ACTION SEP 17, 2026  UPDATED OCT 2
S. 5443SENATE BILL · 119TH CONGRESS119TH

Health Infrastructure Security and Accountability Act of 2026

Sets health data security requirements and provides Medicare support for hospitals adopting cybersecurity practices.

WHERE IT STANDS

In the Senate Finance Committee since Sept. 17, 2026, 18 days after it was introduced. Most bills never leave committee.

  1. INTRODUCEDINTROSEP 17, 2026
  2. COMMITTEECOMM.IN COMMITTEE
  3. SENATESENATE—
  4. HOUSEHOUSE—
  5. LAWLAW—
Read the text
WHAT IT DOES

What the bill would do, and why it matters

BASED ON THE TEXT AS INTRODUCED
tl;drWRITTEN OCT 4 FROM THE TEXT AS INTRODUCED

Health care depends on digital systems to protect patient information and keep services running. The bill would set new security requirements for health care organizations, require recurring risk reviews and audits, and increase penalties for certain failures. It would also offer Medicare support for hospitals adopting cybersecurity practices and allow advances when cyber incidents disrupt Medicare claims processing.

  • INTRODUCED ONLY This bill has been introduced and possibly referred to a committee, but it has not passed any vote. Most introduced bills never become law — they die in committee without a hearing.
  • DATA NOTE No Congressional Research Service summary was available.
WHAT IT WOULD DO · 6 PROVISIONSINTRODUCED IN SENATE
  1. Set health data security standards

    The bill would require the Secretary of Health and Human Services to set minimum security requirements for covered entities and business associates, plus enhanced requirements for entities deemed systemically important or important to national security. The Secretary would review and update the requirements at least every two years.

  2. Require yearly risk plans and audits

    Covered entities and business associates would generally have to conduct and document annual risk analyses, recovery plans, and resilience tests, and publish compliance statements online. They would also have to hire independent auditors for annual security audits; starting four years after enactment, HHS would audit at least 20 entities each year.

  3. Pay hospitals to adopt cybersecurity practices

    The bill would provide proportional Medicare payments for hospitals adopting essential cybersecurity practices in fiscal years 2029 and 2030, and enhanced practices in fiscal years 2031 and 2032. The specified payment amounts are $800,000,000 for fiscal years 2029 and 2030 and $500,000,000 for fiscal years 2031 and 2032.

  4. Increase penalties and fund enforcement

    The bill would set higher minimum civil penalties for security violations and allow penalties of up to $5,000 per day for specified failures to submit records or comply with audits. It would also authorize HHS to collect fees from covered entities and business associates to support oversight and enforcement, subject to annual limits.

  5. Reduce payments for nonadopting hospitals

    Starting in fiscal year 2031, eligible hospitals and critical access hospitals that do not adopt the required practices would face reductions in certain Medicare payments. The reductions would grow over time, and HHS could grant a renewable hardship exception in qualifying cases.

  6. Allow Medicare advances after cyber incidents

    The bill would let HHS provide accelerated or advance Medicare payments to specified providers and suppliers facing significant cash-flow problems, including when a cybersecurity incident substantially disrupts Medicare claims processing. Payments would be subject to safeguards against fraud, waste, and abuse.

THE CONTEXT

The bill’s stated aim is to protect health information and patient safety while keeping health care information systems and transactions available and resilient. It treats cybersecurity as a continuity-of-care issue as well as a data-protection issue, and would add federal oversight and compliance requirements.

It also addresses the possibility that a cybersecurity incident could disrupt Medicare claims processing and leave providers with significant cash-flow problems. The bill would pair hospital assistance with financial incentives and payment reductions tied to cybersecurity practices.

Written from the bill text.

KEY DATES
WITHIN 18 MONTHS AFTER ENACTMENT
HHS issues regulations for minimum and enhanced security requirements
180 DAYS AFTER ENACTMENT
Independent security audit requirements take effect
2 YEARS AFTER ENACTMENT
Minimum and enhanced security requirements take effect
3 YEARS AFTER ENACTMENT
Annual risk management and reporting requirements take effect
MONEY
$800,000,000
authorized for medicare payments for adopting essential cybersecurity practices, Fiscal years 2029 and 2030
$500,000,000
authorized for medicare payments for adopting enhanced cybersecurity practices, Fiscal years 2031 and 2032
$40,000,000
authorized for centers for Medicare & Medicaid Services implementation of cybersecurity practice incentives and payment adjustments, Fiscal year 2027
TEXT VERSIONS
  1. ISIntroduced in SenateSEP 17, 20266,712
THE JOURNEY

The path it took, step by step

FROM THE OFFICIAL ACTIONS ON CONGRESS.GOV
  1. IntroducedSEP 17, 2026
    SENATE
    SEP 17, 2026
    By Sen. Warner with 1 original cosponsor
    Referred to Finance
  2. SAME DAYNOW
    Senate committeeSEP 17, 2026
    FINANCE NOW
    SEP 17, 2026
    In committee for 18 days
    No hearing yet
  3. 18 DAYS SO FAR
    Passed the Senate—
    SENATE FLOOR
    —
    Not scheduled
  4. House committee—
    HOUSE
    —
  5. Passed the House—
    HOUSE FLOOR
    —
    Not scheduled
  6. Resolve differencesONLY IF NEEDED
    BOTH CHAMBERS
    ONLY IF NEEDED
    Skipped if the other chamber passes the same text
  7. Signed into law—
    PRESIDENT
    —
    10 days to sign or veto
KEY ACTIONS2 OF 2 · PROCEDURAL STEPS FOLDED
  1. SEP 172026SEP 17, 2026REFERREDRead twice and referred to the Committee on Finance.
  2. SEP 172026SEP 17, 2026INTRODUCEDSENATEIntroduced in Senate
HOW LONG LAWS TAKE118 LAWS THIS CONGRESS

At day 18, this bill is already older than 6% of the laws passed this Congress were when they were signed.

DAYS FROM INTRODUCTION TO SIGNING · ○ CEREMONIAL
YOUR MEMBERS

Where your members stand on it

WHO’S BEHIND IT · 1 COSPONSOR

Support from one state

PARTY MIX
0 REPUBLICANS1 DEMOCRAT

Plus the sponsor, a Democrat. Every cosponsor is from one party.

COSPONSORS BY STATEEACH BAR IS ONE OF THE STATE’S TWO SENATORS
AK
ME
VT
NH
WA
ID
MT
ND
MN
IL
WI
MI
NY
RI
MA
OR
NV
WY
SD
IA
IN
OH
PA
NJ
CT
CA
UT
CO
NE
MO
KY
WV
VA
MD
DE
AZ
NM
KS
AR
TN
NC
SC
OK
LA
MS
AL
GA
HI
TX
FL
DEMOCRATDEMREPUBLICANREPINDEPENDENTINDSPONSORNOT A COSPONSORNONE
PARTY MIX
0 REPUBLICANS1 DEMOCRAT

Plus the sponsor, a Democrat. Every cosponsor is from one party.

MOMENTUM
SEP 2026 · 1 ORIGINALNOW · 1

Sen. Warner’s record: sponsored 61 bills this Congress. 0 passed the Senate; 0 became law.

EVERY COSPONSOR · IN THE ORDER THEY JOINED1 ACTIVE
READERS · 0 COMMENTS

What readers think

READERS’ VIEWS, NOT CHAMBERLIGHT’S

What do you think?

0 votes

Discussion

Loading comments...
TRACK THIS BILL

Get an alert when it changes stage, gets a floor vote in the Senate, or is signed into law.