Healthcare organizations’ cybersecurity investments are perfectly adequate – until the moment attackers prove otherwise. With the proposed Healthcare Cybersecurity Act, Congress has recognized the truth healthcare security executives have known for years: our infrastructure is outdated, and patient data protection is not the #1 priority of any company. The bill calls for HHS and CISA to collaborate on a coordinated federal response to healthcare cybersecurity. Despite America’s healthcare system generating $4.9 trillion in revenue (as of 2023), a 2025 HIMSS survey of nearly 300 healthcare cybersecurity professionals found that 20% of respondents had no specific cybersecurity carveout within their IT budgets. Yes, Congress should pass the Healthcare Cybersecurity Act.