Digital Privacy Watch

US healthcare cybersecurity moves toward mandatory standards

US healthcare cybersecurity moves toward mandatory standards

A proposed bill would require hospitals to implement cybersecurity standards, assess third-party risk, undergo audits, obtain executive attestations, and face penalties, backed by approximately $1.3 billion in proposed funding. Telehealth reporting also exposes a consumer-facing HIPAA coverage gap, where health data may be shared with advertising platforms and used in automated prescribing; legislative passage and final requirements remain uncertain.

Sources (2)
Updated Sep 22, 2026