The Health Care Cybersecurity and Resiliency Act: What It Means for MSPs

The Health Care Cybersecurity and Resiliency Act (S. 3315) passed the U.S. Senate by unanimous consent on September 30, 2026. It is not law yet; the House still has to act. If it becomes law, HHS must update the HIPAA Security Rule to require multifactor authentication, encryption, and ongoing monitoring from covered entities and business associates, which includes most MSPs with healthcare clients.
That last part is the news for MSPs. You are named in the bill. Here's what it says, what it doesn't, and what to do with your healthcare clients while the House decides.
Where the bill stands (updated October 5, 2026)
- December 2, 2025: Introduced by Senators Bill Cassidy (R-LA), Mark Warner (D-VA), Maggie Hassan (D-NH), and John Cornyn (R-TX).
- February 26, 2026: Approved by the Senate HELP Committee, 22 to 1.
- September 30, 2026: Passed the full Senate by unanimous consent, with an amendment.
- Next: The House of Representatives. Then the President's signature.
We'll update this section as the bill moves. Until it's signed, nothing in it is a legal requirement. You can read the Senate-passed bill text and track its status on Congress.gov.
What does the Health Care Cybersecurity and Resiliency Act require?
The bill has 12 sections. Five matter most to MSPs.
Minimum cybersecurity standards for HIPAA (Section 8)
HHS must update the HIPAA Security Rule so that covered entities and business associates adopt minimum risk-based cybersecurity practices, including:
- multifactor authentication
- encryption of protected health information (PHI)
- monitoring, including penetration testing
- other minimum standards drawn from national frameworks: the NIST Cybersecurity Framework, NIST SP 800-53, the HHS Healthcare and Public Health Cybersecurity Performance Goals, and CISA's healthcare performance goals
The new rules take effect 36 months after the bill becomes law. That's a long runway, but your clients' insurers and auditors won't wait three years to start asking.
Recognized security practices that can lower fines (Section 7)
Since 2021, HHS has been allowed to consider "recognized security practices" when it sets HIPAA fines and settles audits. The bill gives HHS one year to write the rules for how that works: which practices count, how long they must be in place, and what proof an organization submits.
For MSPs, this turns documentation into money. A healthcare client that can show a year of recognized practices may face a smaller fine after a breach.
Rural cybersecurity guidance (Section 9)
Within a year, HHS must issue guidance for rural healthcare organizations. The bill tells HHS to explore outsourcing IT and part-time CISO functions to third parties.
In other words, Congress is telling rural clinics to hire someone like you.
Grants for eligible providers (Section 10)
HHS may award grants of up to three years to:
- Federally qualified health centers
- facilities run by or under contract with the Indian Health Service
- nonprofit hospitals
- rural health clinics
- nonprofits that partner with any of the above
Grant money can pay for staff training, cloud migration, risk and vulnerability assessments, incident response plans, threat-sharing memberships, and contracts with third parties to do that work.
MSPs can't apply directly. Your eligible clients can, and they can use the money to hire you. Note that "may award" means Congress still has to fund the program.
Workforce training (Section 11)
HHS must train healthcare organizations on cyber risks. Within a year, it must also publish a strategic plan that includes best practices for training the healthcare workforce.
Does the Health Care Cybersecurity and Resiliency Act apply to MSPs?
Yes, if you're a business associate. Section 8 applies to covered entities and business associates, using the same definitions as HIPAA.
An MSP that manages systems holding PHI for a healthcare client is a business associate under HIPAA today, with or without this bill. That includes backups, email, endpoints, remote monitoring, and file storage. If you've signed a Business Associate Agreement (BAA), you already know this. If you support a clinic and haven't signed one, fix that first.
So the new standards would apply to your own environment as well as your clients'.
What should MSPs do now?
The bill isn't law, so treat this as preparation, not compliance. The work is worth doing anyway, because most of it is already expected under the current HIPAA Security Rule.
Want this as something you can hand to clients? Our free HCCRA readiness kit for MSPs has a 12-point checklist, a client email, talk tracks, and a grant eligibility screen. No form required.
- List your healthcare clients. Note which ones are rural, nonprofit, or federally qualified health centers. Those are the likely grant candidates.
- Check every BAA. One for each client, signed and current, plus your own BAAs with subprocessors who touch PHI.
- Close the three named gaps. MFA everywhere PHI lives, encryption at rest and in transit, and monitoring you can show.
- Map clients to the HHS performance goals. These are named in Section 8 and are the likeliest basis for the final rule.
- Start the paper trail. Recognized security practices only help if they can be proven, and a fine reduction will depend on records that go back in time.
- Document workforce training. The current Security Rule already requires a security awareness program for the workforce (45 CFR 164.308(a)(5)). Keep the completion records.
- Write or update incident response plans. That's a grant-eligible activity, and a breach is the worst time to draft one.
Where security awareness training fits
Most healthcare breaches start with a person: a phishing email, a phone call to the front desk, a shared login. MFA and encryption reduce the damage. Training reduces how often it starts.
The bill points that way too. It names workforce training in the grant uses, the rural guidance, and the Section 11 strategic plan.
Hook Security's HIPAA training is built for the roles inside a healthcare client:
- HIPAA Security Awareness Training for every workforce member at covered entities and business associates
- HIPAA in Real Life for clinical care providers
- HIPAA Habits for Admins for front-desk and administrative staff
- HIPAA Advanced Safeguards for IT & Leadership for the people who own the safeguards
Hook runs it with the same psychology-based approach behind all of our training. It's short, it's funny, and the completion records your clients need are built in. MSPs can deliver it to every healthcare client they support.
For the full requirements, see our guide to HIPAA training requirements. For phishing simulations written for clinics, see our healthcare phishing templates. To see how Hook covers HIPAA, visit our HIPAA compliance page. Partners can start on our MSP partner page.
What we don't know yet
- Whether the House passes it, changes it, or lets it sit.
- What HHS writes in the final rule. Section 8 sets a minimum; the rule will set the details.
- Whether Congress funds the grants.
- How the bill interacts with HHS's separate proposal to update the HIPAA Security Rule. Our HIPAA training guide tracks where that proposal stands.
Frequently asked questions
Is the Health Care Cybersecurity and Resiliency Act law?
No. As of October 5, 2026, it has passed the Senate and is waiting on the House. It becomes law only after both chambers pass the same text and the President signs it.
Does the Health Care Cybersecurity and Resiliency Act apply to MSPs?
Yes, to MSPs that are HIPAA business associates. Section 8 applies the new minimum standards to covered entities and business associates, and an MSP that manages systems holding PHI is a business associate.
When would the new HIPAA cybersecurity requirements take effect?
36 months after the bill is signed into law. HHS must first update the HIPAA Security Rule through rulemaking.
Can MSPs get grants under the Health Care Cybersecurity and Resiliency Act?
Not directly. Federally qualified health centers, IHS facilities, nonprofit hospitals, rural health clinics, and their nonprofit partners are eligible. They may use grant money to contract with third parties like MSPs, and Congress still has to fund the program.
What should an MSP do before the bill becomes law?
Sign or confirm BAAs, close MFA and encryption gaps, document security awareness training, and start keeping records of the security practices you run. All of that is already expected under current HIPAA rules.
Training courses on this topic
From Hook Security’s security awareness training library.
- 40 minThe Too Late Show Annual TrainingHook Security's premier training is back. Grab a snack and get ready to laugh. The Too Late Show with host Kimberly Caine has games, guests, and a few extra surprises! Covering topics such as social engineering, passwords, safe web browsing, malware, and more!
- 5 minPhishing for AnswersFollow along as we answer common questions regarding cybersecurity and dive deep into specific terms. Plus - learn how to spot and avoid these common attacks. Available courses: Updating Devices, Too good to be true offers, Spyware, MFA, Passphrases, Evil Twin Attacks, Email Attachments
- 8 minPhishing with Mike Fry The Cyber GuyPhishing with Mike Fry The Cyber Guy - Security awareness training
Ready to Strengthen Your Security Culture?
See how Hook Security can help protect your organization.