- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
- Administration
- Agriculture
- Agriculture, Nutrition, And Forestry
- Appropriations
- Armed Services
- Banking, Housing, And Urban Affairs
- Budget
- Commerce, Science, And Transportation
- Education and Workforce
- Energy And Commerce
- Energy And Natural Resources
- Environment And Public Works
- Ethics
- Finance
- Financial Services
- Foreign Affairs
- Foreign Relations
- Health, Education, Labor, And Pensions
- Homeland Security
- Homeland Security And Governmental Affa…
- Indian Affairs
- Indian and Insular Affairs
- Intelligence
- Judiciary
- Natural Resources
- Oversight And Government Reform
- Permanent Select Intelligence
- Rules
- Rules And Administration
- Science, Space, And Technology
- Select Intelligence
- Small Business
- Small Business And Entrepreneurship
- Subcommittee on Aviation
- Subcommittee on Border Security and Enf…
- Subcommittee on Coast Guard and Maritim…
- Subcommittee on Commodity Markets, Digi…
- Subcommittee on Conservation, Research,…
- Subcommittee on Counterterrorism and In…
- Subcommittee on Cybersecurity and Infra…
- Subcommittee on Disability Assistance a…
- Subcommittee on Economic Development, P…
- Subcommittee on Economic Opportunity
- Subcommittee on Emergency Management an…
- Subcommittee on Energy and Mineral Reso…
- Subcommittee on Federal Lands
- Subcommittee on Forestry and Horticultu…
- Subcommittee on General Farm Commoditie…
- Subcommittee on Health
- Subcommittee on Highways and Transit
- Subcommittee on Livestock, Dairy, and P…
- Subcommittee on Nutrition and Foreign A…
- Subcommittee on Oversight and Investiga…
- Subcommittee on Oversight, Investigatio…
- Subcommittee on Railroads, Pipelines, a…
- Subcommittee on Transportation and Mari…
- Subcommittee on Water Resources and Env…
- Subcommittee on Water, Wildlife and Fis…
- Transportation And Infrastructure
- Veterans' Affairs
- Ways And Means

H.R. 3841
U.S. House•In House Committee
Summary
H.R. 3841, the Healthcare Cybersecurity Act of 2025, was introduced in the House on Jun 9, 2025 by Rep. Jason Crow (D) with 2 co-sponsors. It was referred to Subcommittee on Cybersecurity and Infrastructure Protection, and last saw action on Jun 10, 2025: Referred to the Subcommittee on Cybersecurity and Infrastructure Protection.
Record
Text
H.R. 3841 has 2 co-sponsors.
hb3841/introduced-in-house.txt119 HR 3841 IH: Healthcare Cybersecurity Act of 2025U.S. House of Representatives2025-06-09text/xmlENPursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.I 119th CONGRESS 1st Session H. R. 3841 IN THE HOUSE OF REPRESENTATIVES June 9, 2025 Mr. Crow (for himself and Mr. Fitzpatrick ) introduced the following bill; which was referred to the Committee on Homeland Security , and in addition to the Committee on Energy and Commerce , for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned A BILLTo enhance the cybersecurity of the Healthcare and Public Health Sector.1.Short titleThis Act may be cited as the Healthcare Cybersecurity Act of 2025 .2.DefinitionsIn this Act—(1)the term Agency means the Cybersecurity and Infrastructure Security Agency;(2)the term covered asset means a Healthcare and Public Health Sector asset, including technologies, services, and utilities;(3)the term Cybersecurity State Coordinator means a Cybersecurity State Coordinator appointed under section 2217(a) of the Homeland Security Act of 2002 ( 6 U.S.C. 665c(a) );(4)the term Department means the Department of Health and Human Services;(5)the term Director means the Director of the Agency;(6)the term Healthcare and Public Health Sector means the Healthcare and Public Health sector, as identified in the National Security Memorandum on Critical Infrastructure and Resilience (NSM–22), issued April 30, 2024;(7)the term Information Sharing and Analysis Organizations has the meaning given the term in section 2200 of the Homeland Security Act of 2002 ( 6 U.S.C. 650 );(8)the term Plan means the Healthcare and Public Health Sector-specific Risk Management Plan; and(9)the term Secretary means the Secretary of Health and Human Services.3.FindingsCongress finds the following:(1)Covered assets are increasingly the targets of malicious cyberattacks, which result not only in data breaches but also increased healthcare delivery costs and can ultimately affect patient health outcomes.(2)Data reported to the Department shows that large cyber breaches of the information systems of healthcare facilities rose 93 percent between 2018 and 2022.(3)According to the Annual Report to Congress on Breaches of Unsecured Protected Health Information for Calendar Year 2022 issued by the Office for Civil Rights of the Department, breaches of unsecured protected health information have increased 107 percent since 2018, and, in 2022 alone, the Department received 626 reported breaches affecting not fewer than 500 individuals at covered entities or business associates (as defined in section 160.103 of title 45, Code of Federal Regulations) that occurred or ended in 2022, with nearly 42,000,000 individuals affected.4.Agency coordination with the Department(a)In generalThe Agency shall coordinate with the Department to improve cybersecurity in the Healthcare and Public Health Sector.(b)Agency liaison to the Department(1)AppointmentThe Director shall, in coordination with the Secretary, appoint an individual, who shall be an employee of the Agency or a detailee assigned to the Administration for Strategic Preparedness and Response Office of the Department by the Director, to serve as a liaison of the Agency to the Department, who shall—(A)have appropriate cybersecurity qualifications and expertise; and(B)report directly to the Director.(2)Responsibilities and dutiesThe liaison appointed under paragraph (1) shall—(A)serve as a primary contact of the Department to coordinate cybersecurity issues with the Agency;(B)support the implementation and execution of the Plan and assist in the development of updates to the Plan;(C)facilitate the sharing of cyber threat information between the Department and the Agency to improve understanding of cybersecurity risks and situational awareness of cybersecurity incidents;(D)assist in implementing the training described in section 5;(E)facilitate coordination between the Agency and the Department during cybersecurity incidents within the Healthcare and Public Health Sector; and(F)perform such other duties as determined necessary by the Secretary to achieve the goal of improving the cybersecurity of the Healthcare and Public Health Sector.(3)Report(A)RequirementNot later than 18 months after the date of enactment of this Act, the Secretary, in coordination with the Director, shall submit a report that describes the activities undertaken to improve cybersecurity coordination between the Agency and the Department to—(i)the Committee on Health, Education, Labor, and Pensions, the Committee on Finance, and the Committee on Homeland Security and Governmental Affairs of the Senate; and(ii)the Committee on Energy and Commerce, the Committee on Ways and Means, and the Committee on Homeland Security of the House of Representatives.(B)ContentsThe report submitted under subparagraph (A) shall include—(i)a summary of the activities of the liaison appointed under paragraph (1);(ii)a description of any challenges to the effectiveness of the liaison appointed under paragraph (1) completing the required duties of the liaison; and(iii)a study of the feasibility of an agreement to improve cybersecurity in the public sector of healthcare.(c)Resources(1)In generalThe Agency shall coordinate with and make resources available to Information Sharing and Analysis Organizations, information sharing and analysis centers, the sector coordinating councils, and non-Federal entities that are receiving information shared through programs managed by the Department.(2)ScopeThe coordination under paragraph (1) shall include—(A)developing products specific to the needs of Healthcare and Public Health Sector entities; and(B)sharing information relating to cyber threat indicators and appropriate defensive measures.5.Training for healthcare owners and operatorsThe Agency shall make available training to the owners and operators of covered assets on—(1)cybersecurity risks to the Healthcare and Public Health Sector and covered assets; and(2)ways to mitigate the risks to information systems in the Healthcare and Public Health Sector.6.Sector-specific risk management plan(a)In generalNot later than 1 year after the date of enactment of this Act, the Secretary, in coordination with the Director, shall update the Plan, which shall include the following elements:(1)An analysis of how identified cybersecurity risks specifically impact covered assets, including the impact on rural and small- and medium-sized covered assets.(2)An evaluation of the challenges the owners and operators of covered assets face in—(A)securing—(i)updated information systems owned, leased, or relied upon by covered assets;(ii)medical devices or equipment owned, leased, or relied upon by covered assets, which shall include an analysis of the threat landscape and cybersecurity vulnerabilities of such medical devices or equipment; and(iii)sensitive patient health information and electronic health records;(B)implementing cybersecurity protocols; and(C)responding to data breaches or cybersecurity attacks, including the impact on patient access to care, quality of patient care, timeliness of health care delivery, and health outcomes.(3)An evaluation of the best practices for utilization of resources from the Agency to support covered assets before, during, and after data breaches or cybersecurity attacks, such as by Cyber Security Advisors and Cybersecurity State Coordinators of the Agency or other similar resources.(4)An assessment of relevant Healthcare and Public Health Sector cybersecurity workforce shortages, including—(A)training, recruitment, and retention issues; and(B)recommendations for how to address these shortages and issues, particularly at rural and small- and medium-sized covered assets.(5)An evaluation of the most accessible and timely ways for the Agency and the Department to communicate and deploy cybersecurity recommendations and tools to the owners and operators of covered assets.(b)Congressional briefingNot later than 120 days after the date of enactment of this Act, the Secretary, in consultation with the Director, shall provide a briefing on the updating of the Plan under subsection (a) to—(1)the Committee on Health, Education, Labor, and Pensions, the Committee on Finance, and the Committee on Homeland Security and Governmental Affairs of the Senate; and(2)the Committee on Energy and Commerce, the Committee on Ways and Means, and the Committee on Homeland Security of the House of Representatives.7.Identifying high-risk covered assets(a)In generalThe Secretary, in consultation with the Director and health sector owners and operators, as appropriate, may establish objective criteria for determining whether a covered asset may be designated as a high-risk covered asset, provided that such criteria shall align with the methodology promulgated by the Director for identifying functions relating to critical infrastructure, as defined in section 1016(e) of the Critical Infrastructures Protection Act of 2001 ( 42 U.S.C. 5195c(e) ), and associated risk assessments.(b)List of high-Risk covered assets(1)In generalThe Secretary may develop a list of, and notify, the owners and operators of each covered asset determined to be a high-risk covered asset using the methodology promulgated by the Director pursuant to subsection (a).(2)Biannual updatingThe Secretary may—(A)biannually review and update the list of high-risk covered assets developed under paragraph (1); and(B)notify the owners and operators of each covered asset added to or removed from the list as part of a review and update of the list under subparagraph (A).(3)Notice to CongressThe Secretary shall notify Congress when an initial list of high-risk covered assets is developed under paragraph (1) and each time the list is updated under paragraph (2).(4)UseThe list developed and updated under this subsection may be used by the Department to prioritize resource allocation to high-risk covered assets to bolster cyber resilience.8.Reports(a)Report on assistance provided to entities of Healthcare and Public Health SectorNot later than 120 days after the date of enactment of this Act, the Agency shall submit to Congress a report on the organization-wide level of support and activities that the Agency has provided to the healthcare and public health sector to proactively prepare the sector to face cyber threats and respond to cyber attacks when such threats or attacks occur.(b)Report on critical infrastructure resourcesNot later than 18 months after the date of enactment of this Act, the Comptroller General of the United States shall submit to Congress a report on Federal resources available, as of the date of enactment of this Act, for the Healthcare and Public Health Sector relating to critical infrastructure, as defined in section 1016(e) of the Critical Infrastructures Protection Act of 2001 ( 42 U.S.C. 5195c(e) ), including resources available from recent and ongoing collaboration with the Director and the Secretary.9.Rules of construction(a)Agency actionsNothing in this Act shall be construed to authorize the Secretary or Director to take an action that is not authorized by this Act or existing law.(b)Protection of rightsNothing in this Act shall be construed to permit the violation of the rights of any individual protected by the Constitution of the United States, including through censorship of speech protected by the Constitution of the United States or unauthorized surveillance.(c)No additional fundsNo additional funds are authorized to be appropriated for the purpose of carrying out this Act.
Tracker
The tracker indicates the progress of this legislation as it moves through the legislative process.
- Introduced2025-06-09
- Passed House
- Passed Senate
- Conference
- To President
- Became Law
To enhance the cybersecurity of the Healthcare and Public Health Sector.
Sponsors
Rep. Jason Crow (D) sponsors H.R. 3841, and 2 members have co-sponsored it, 1 of them from the day it was introduced.
Committees
H.R. 3841 went before 3 committees: Cybersecurity and Infrastructure Protection Subcommittee, Energy and Commerce and Homeland Security.

Actions
H.R. 3841 has taken 3 actions since Jun 9, 2025, the latest on Jun 10, 2025.
| Chamber | Action | |||
|---|---|---|---|---|
Jun 10, 2025 | House | Referred to the Subcommittee on Cybersecurity and Infrastructure Protection.Cybersecurity and Infrastructure Protection Subcommittee | ||
Jun 9, 2025 | House | Introduced in House | ||
Jun 9, 2025 | House | Referred to the Committee on Homeland Security, and in addition to the Committee on Energy and Commerce, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.Homeland Security Committee |
Votes
H.R. 3841 has not gone to a roll call.
Related bills
1 bill is related to H.R. 3841, as Identical bill.
Titles
H.R. 3841 goes by 3 titles, 1 of them short titles.
- Healthcare Cybersecurity Act of 2025 — Display Title
- Healthcare Cybersecurity Act of 2025 — Short Title(s) as Introduced
- To enhance the cybersecurity of the Healthcare and Public Health Sector. — Official Title as Introduced
Lobbying
5 clients hired 5 firms and 14 registered lobbyists who named H.R. 3841 in 15 quarterly filings, 2025 to 2026. Reported under the Lobbying Disclosure Act; a filing’s income covers everything its registrant worked that quarter, so the amounts below are the filings’, not this bill’s.
Filed under Health Issues, Pharmacy, Medicare/Medicaid, Budget/Appropriations.
Clients
Who paid to be heard, by how many filings named the bill.
| Client | Business | State | Firms | Filings | Reported |
|---|---|---|---|---|---|
| BCBSM INC | — | Minnesota | 1 | 4 | — |
| BLUE CROSS AND BLUE SHIELD OF KANSAS INC | — | Kansas | 1 | 4 | — |
| BLUE CROSS AND BLUE SHIELD ASSOCIATION | — | District of Columbia | 1 | 3 | — |
| BLUE CROSS AND BLUE SHIELD OF FLORIDA INC | — | Florida | 1 | 3 | — |
| BLUE CROSS BLUE SHIELD OF MICHIGAN | — | District of Columbia | 1 | 1 | — |
Firms
Registrants who filed on the bill, by filings.
| Registrant | Clients | Filings | Reported |
|---|---|---|---|
| BCBSM, INC. | 1 | 4 | — |
| BLUE CROSS AND BLUE SHIELD OF KANSAS, INC. | 1 | 4 | — |
| BLUE CROSS AND BLUE SHIELD ASSOCIATION | 1 | 3 | — |
| BLUE CROSS AND BLUE SHIELD OF FLORIDA, INC. | 1 | 3 | — |
| BLUE CROSS BLUE SHIELD OF MICHIGAN | 1 | 1 | — |
Lobbyists
Named on the filings that cite the bill.
| Lobbyist | Firms | Clients | Filings |
|---|---|---|---|
| LIN NELSON | 1 | 1 | 4 |
| SUNEE MICKLE | 1 | 1 | 4 |
| ALYSSA PALISI | 1 | 1 | 3 |
| AMANDA INGRAM JACOBS | 1 | 1 | 3 |
| AMANDA SCHWARTZ | 1 | 1 | 3 |
| DAVID MERRITT | 1 | 1 | 3 |
| KRIS HALTMEYER | 1 | 1 | 3 |
| KRISTIN STUART | 1 | 1 | 3 |
| THOMAS GILES | 1 | 1 | 3 |
| DAVID ADAMS | 1 | 1 | 2 |
| THOMAS FLETCHER | 1 | 1 | 2 |
| THOMAS RADDER | 1 | 1 | 2 |
| AMY MODLIN | 1 | 1 | 1 |
| ERIK HAMES | 1 | 1 | 1 |
Filings
The documents themselves, on the Senate’s Lobbying Disclosure site, largest reported first.
| Client | Registrant | Period | Reported | Document |
|---|---|---|---|---|
| BLUE CROSS AND BLUE SHIELD ASSOCIATION | BLUE CROSS AND BLUE SHIELD ASSOCIATION | 2026 first_quarter | $1.5M | 1st Quarter - Report |
| BLUE CROSS AND BLUE SHIELD ASSOCIATION | BLUE CROSS AND BLUE SHIELD ASSOCIATION | 2025 fourth_quarter | $1.4M | 4th Quarter - Report |
| BLUE CROSS AND BLUE SHIELD ASSOCIATION | BLUE CROSS AND BLUE SHIELD ASSOCIATION | 2025 third_quarter | $1.2M | 3rd Quarter - Report |
| BLUE CROSS BLUE SHIELD OF MICHIGAN | BLUE CROSS BLUE SHIELD OF MICHIGAN | 2025 fourth_quarter | $266K | 4th Quarter - Report |
| BLUE CROSS AND BLUE SHIELD OF FLORIDA INC | BLUE CROSS AND BLUE SHIELD OF FLORIDA, INC. | 2026 first_quarter | $130K | 1st Quarter - Report |
| BLUE CROSS AND BLUE SHIELD OF FLORIDA INC | BLUE CROSS AND BLUE SHIELD OF FLORIDA, INC. | 2025 fourth_quarter | $90K | 4th Quarter - Report |
| BLUE CROSS AND BLUE SHIELD OF FLORIDA INC | BLUE CROSS AND BLUE SHIELD OF FLORIDA, INC. | 2025 third_quarter | $80K | 3rd Quarter - Report |
| BCBSM INC | BCBSM, INC. | 2025 third_quarter | $32K | 3rd Quarter - Report |
| BCBSM INC | BCBSM, INC. | 2026 first_quarter | $30K | 1st Quarter - Report |
| BCBSM INC | BCBSM, INC. | 2026 second_quarter | $28K | 2nd Quarter - Report |
| BCBSM INC | BCBSM, INC. | 2025 fourth_quarter | $28K | 4th Quarter - Report |
| BLUE CROSS AND BLUE SHIELD OF KANSAS INC | BLUE CROSS AND BLUE SHIELD OF KANSAS, INC. | 2026 second_quarter | $10K | 2nd Quarter - Report |
| BLUE CROSS AND BLUE SHIELD OF KANSAS INC | BLUE CROSS AND BLUE SHIELD OF KANSAS, INC. | 2026 first_quarter | $10K | 1st Quarter - Report |
| BLUE CROSS AND BLUE SHIELD OF KANSAS INC | BLUE CROSS AND BLUE SHIELD OF KANSAS, INC. | 2025 fourth_quarter | $10K | 4th Quarter - Report |
| BLUE CROSS AND BLUE SHIELD OF KANSAS INC | BLUE CROSS AND BLUE SHIELD OF KANSAS, INC. | 2025 third_quarter | $10K | 3rd Quarter - Report |
Classification
The Congressional Research Service files H.R. 3841 under Health, one of its 31 policy areas.
CRS Subjects
CRS assigns every bill one policy area from its 31; H.R. 3841’s is Health.
hr3841/policy-areas.txtConstitutional authority
The clause the sponsor cites as Congress’s power to enact H.R. 3841, as entered in the Congressional Record.
[Congressional Record Volume 171, Number 98 (Monday, June 9, 2025)][House]From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]By Mr. CROW:H.R. 3841.Congress has the power to enact this legislation pursuantto the following:Article I, Section 8, clause 18 AND Article I, Section 8,clause 3[Page H2569]
Source: congress.gov · legiscan.com
