House Subcommittee Hearing Highlights Growing Cybersecurity Threats to Rural Hospitals and Patient Care
On September 15, 2026, the House Energy and Commerce Committee’s health subcommittee convened to address the pressing cybersecurity threats facing U.S. hospitals, clinics, and other healthcare providers. In the wake of a surge in hacking incidents and cyberattacks, lawmakers examined two proposed bills designed to bolster cybersecurity measures in the healthcare sector. This hearing underscored the vulnerabilities of rural hospitals, which often serve as critical care sources in remote areas.
As of mid-September 2026, the U.S. Department of Health and Human Services reported receiving over 424 notifications of significant data breaches stemming from hacking or IT incidents. Each breach impacted between 500 and 15 million individuals, cumulatively affecting nearly 73 million people across the country. These statistics have raised alarm bells among healthcare providers and lawmakers alike, particularly as cyberattacks threaten not only data security but also the delivery of crucial patient services.
Rep. Erin Houchin, a Republican from Indiana and co-sponsor of the proposed Rural Hospital Cybersecurity Enhancement Act (H.R. 9908), expressed significant concern over the repercussions of recent cyberattacks. She pointed out that the fallout from such incidents goes well beyond mere data theft. In her district, for instance, attacks have led to cancellations of surgeries, disrupted appointment schedules, and outages in payment systems, even impairing emergency care provision. Houchin emphasized the unique challenges faced by rural hospitals, which often lack the resources required to mitigate such risks, jeopardizing patient care.
The subcommittee evaluated another piece of legislation, the Health Care Cybersecurity and Resiliency Act of 2026, which is largely based on a bill previously introduced in the Senate. This legislation aims to improve cybersecurity protocols across the healthcare sector and is aligned with the increased focus on integrating cybersecurity into the operational frameworks of these institutions.
During the hearing, lawmakers discussed the daunting challenges confronting rural healthcare providers, particularly the lack of financial and personnel resources to mount effective defenses against cyber threats. Greg Garcia, the executive director of the Healthcare and Public Health Sector Coordinating Council’s cybersecurity working group, highlighted that the stakes go beyond ransomware aimed at financial gain. He cautioned that future cyberattacks could potentially be orchestrated alongside physical attacks, creating compounded risks for patients and healthcare systems.
Garcia invoked the tragic events of September 11, 2001, illustrating his concern with a stark hypothetical. He raised the possibility that had terrorists simultaneously deployed cyberattacks on hospitals treating victims of the physical attacks, the chaos would have intensified, potentially increasing casualties. This “blended attack” scenario underscores the dire need for robust cybersecurity protocols to protect healthcare facilities, particularly in times of crisis.
The proposed cybersecurity legislation encompasses various initiatives to enhance the responsibilities of the HHS in terms of overseeing healthcare cybersecurity, updating HIPAA security regulations, and providing essential resources to healthcare organizations with limited assets. Specifically, the Health Care Cybersecurity and Resiliency Act would mandate collaboration between HHS and the Cybersecurity and Infrastructure Security Agency (CISA) to coordinate efforts aimed at improving overall cybersecurity in the sector.
Moreover, the Rural Hospital Cybersecurity Enhancement Act would instill a comprehensive strategy to address the acute scarcity of cybersecurity professionals in rural hospitals, alongside offering publicly accessible cybersecurity training resources. Garcia further stressed that while technological advancements have fostered improvements in healthcare delivery, they simultaneously introduce new cybersecurity vulnerabilities. For instance, telehealth technologies allow specialists to deliver care remotely but also enable cybercriminals to exploit these systems for malicious intent.
To address these pressing issues, Garcia recommended crucial amendments to the proposed legislation. He urged the inclusion of the Health Sector Coordinating Council in policy deliberations on cybersecurity, emphasizing the importance of involving experts in threat information-sharing and incident response advisories. Additionally, he proposed designating a senior HHS official specifically charged with coordinating cybersecurity efforts both internally and with external partners, to ensure a cohesive and effective response to cyber threats.
Garcia also advocated for making cybersecurity grants available to a broad spectrum of healthcare providers, thereby allowing them to replace outdated medical technologies that may no longer be adequate against current cyber threats. Furthermore, he cautioned against prescribing specific technologies in legislative language, advocating instead for adaptable approaches that align with the rapid evolution of technology.
As the hearing drew to a close, Garcia reiterated the urgent need for a centralized effort to address cybersecurity workforce training in healthcare. He emphasized that financial support from Congress could significantly help rural hospitals build resilience and mutual assistance across communities. By fortifying their cybersecurity infrastructure, these essential healthcare providers can better protect themselves against the constantly evolving landscape of cyber threats. In summary, the call for comprehensive and proactive measures to enhance cybersecurity in healthcare has never been more critical, particularly for the vulnerable rural hospitals that form the backbone of patient care in many underserved areas across the nation.

