H.R. 3841 (119th)Bill Overview

Healthcare Cybersecurity Act of 2025

Health|Health
Cosponsors
Support
Lean Republican
Introduced
Jun 9, 2025
Discussions
Bill Text
Current stageCommittee

Referred to the Committee on Homeland Security, and in addition to the Committee on Energy and Commerce, for a period to be subsequently determined by the Speaker, in each case fo…

Introduced
Committee
Floor
President
Law
Congressional Activities
01 · The brief
Plain-English summaryWhat this bill actually does

This bill directs the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) to coordinate to improve cybersecurity across the Healthcare and Public Health Sector. It requires CISA to appoint a liaison to HHS, to share threat information and resources with sector entities and information sharing organizations, and to provide training to owners and operators of covered assets.

Why people may split

Funding vs. expectations: liberals emphasize the need for new funding for small/rural providers; conservatives see the lack of appropriations as limiting government overreach.

Watch point

Relative to its intended legislative type, this bill is a reasonably well-structured administrative measure that assigns responsibilities, sets deadlines, and creates reporting obligations to strengthen coordination between CISA and HHS for Healthcare and Public Health cybersecurity.

This bill directs the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) to coordinate to improve cybersecurity across the Healthcare and Public Health Sector.

It requires CISA to appoint a liaison to HHS, to share threat information and resources with sector entities and information sharing organizations, and to provide training to owners and operators of covered assets.

HHS and CISA must update a sector-specific risk management plan within one year (with a congressional briefing within 120 days) that analyzes risks, medical device vulnerabilities, workforce shortages, and communication/response practices; HHS may also create and biannually update a list of high-risk covered assets to prioritize resources.

Passage30/100

On content alone the bill is a narrowly focused, technical, and non‑ideological measure that mainly orders agency coordination, planning, training, and reporting while forbidding new appropriations. Those attributes typically produce bipartisan support and low controversy, increasing the chance of enactment. Key practical obstacles are committee prioritization, interagency implementation capacity, and procedural steps in the Senate; absence of appropriations may also limit meaningful implementation even if the bill passes.

CredibilityPartially aligned

Relative to its intended legislative type, this bill is a reasonably well-structured administrative measure that assigns responsibilities, sets deadlines, and creates reporting obligations to strengthen coordination between CISA and HHS for Healthcare and Public Health cybersecurity. It combines operational directives (liaison, plan update, training) with reporting and a GAO review.

Contention35/100

Funding vs. expectations: liberals emphasize the need for new funding for small/rural providers; conservatives see the lack of appropriations as limiting government overreach.

02 · What it does

Who stands to gain, and who may push back.

Likely benefits vs burdens50% / 50%
Cities · Federal agenciesFederal agencies

These are examples from the analysis, not a ranked list of the most-affected groups.

Likely helped
  • Potential benefitImproved coordination between CISA and HHS could yield faster, more effective responses to cyber incidents in healthcar…
  • CitiesSector-specific training and dissemination of threat indicators and defensive measures may raise baseline cybersecurity…
  • Federal agenciesAn updated risk management plan and identification of high-risk assets could help prioritize federal and non‑federal re…
Likely burdened
  • Potential burdenBecause the bill authorizes no additional appropriations, implementation likely requires CISA/HHS to use existing budge…
  • Potential burdenCreation of a list of 'high‑risk covered assets' and associated prioritization could impose reputational, insurance, or…
  • Federal agenciesExpanded information sharing and coordination, even with protections stated, may raise concerns about patient privacy a…
03 · Why people split

Why the argument around this bill splits.

Funding vs. expectations: liberals emphasize the need for new funding for small/rural providers; conservatives see the lack of appropriations as limiting government overreach.
Progressive75%

A mainstream liberal would likely view the bill positively overall because it strengthens federal coordination on healthcare cybersecurity, directs attention to vulnerable small and rural providers, and mandates analysis of workforce shortages and medical device vulnerabilities.

They would note, however, that the bill explicitly authorizes no new funding, which could limit the practical impact and leave equity gaps for under-resourced providers.

They would welcome the emphasis on information sharing and training but want assurances that implementation will prioritize underserved communities and patient protections.

Leans supportive
Centrist65%

A centrist/moderate would generally view the bill as a pragmatic, technocratic approach to a clear problem—cyber threats to healthcare—focusing on coordination, planning, and information sharing rather than heavy-handed new regulation.

They would appreciate deadlines and reporting requirements that create accountability but be concerned that the bill authorizes no additional funds, which could limit implementation and shift expectations onto already strained providers.

They would look for clarity on how the high-risk asset list will be used in practice and whether it creates implicit obligations.

Split reaction
Conservative55%

A mainstream conservative would view the bill as a relatively restrained federal effort because it emphasizes coordination and information sharing rather than imposing new regulatory authorities or mandating appropriations.

They may appreciate the rules of construction that limit new powers and explicitly protect constitutional rights, including a prohibition on unauthorized surveillance.

However, they could be wary of the potential for the high-risk covered asset list to become a de facto regulatory instrument or for federal prioritization to grow into mandates affecting private healthcare operations.

Split reaction
04 · Can it pass?

The path through Congress.

Introduced

Reached or meaningfully advanced

Committee

Reached or meaningfully advanced

Floor

Still ahead

President

Still ahead

Law

Still ahead

Passage likelihood30/100

On content alone the bill is a narrowly focused, technical, and non‑ideological measure that mainly orders agency coordination, planning, training, and reporting while forbidding new appropriations. Those attributes typically produce bipartisan support and low controversy, increasing the chance of enactment. Key practical obstacles are committee prioritization, interagency implementation capacity, and procedural steps in the Senate; absence of appropriations may also limit meaningful implementation even if the bill passes.

Scope and complexity
24%
Scopenarrow
24%
Complexitylow
Why this could stall
  • Whether authorizing no new funds will limit agencies' ability to fulfill requirements in practice and whether Congress or the agencies will dedicate resources through other appropriations or reprogramming.
  • How committees will prioritize the bill relative to other legislative items and whether it will be attached to a larger vehicle (which can both help or hinder passage).
05 · Recent votes

Recent votes on the bill.

No vote history yet

The bill has not accumulated any surfaced votes yet.

06 · Go deeper

Go deeper than the headline read.

Included on this page

Funding vs. expectations: liberals emphasize the need for new funding for small/rural providers; conservatives see the lack of appropriatio…

On content alone the bill is a narrowly focused, technical, and non‑ideological measure that mainly orders agency coordination, planning, t…

Unlocked analysis

Relative to its intended legislative type, this bill is a reasonably well-structured administrative measure that assigns responsibilities, sets deadlines, and creates reporting obligations to strengthen coordination bet…

Go beyond the headline summary with full stakeholder mapping, legislative design analysis, passage barriers, and lens-by-lens tradeoff breakdowns.

Perspective breakdownsPassage barriersLegislative design reviewStakeholder impact map
Open full analysis