The Strengthening American Cybersecurity Act passed by the Senate would require critical infrastructure operators to report significant cyber incidents to CISA within 72 hours and within 24 hours when they make a ransomware payment. Combining three previous cybersecurity bills, its other two key components include an update to the Federal Information Security Modernization Act, and authorization for FedRAMP, the governmentwide program standardizing contracted cloud services.
How this could impact the healthcare industry is not entirely clear. A ransomware attack on a DoD, VA, or State Department healthcare provider presumably would quality, and HIPAA would still apply to such entities. Service providers who serve large sectors of the healthcare industry might also. In any case, the short time periods involved could push healthcare providers to over-report when it isn’t yet clear what the scope or impact of an incident is.
Source:
- Careers Info Security: How the Senate’s Cyber Bill Could Affect Health Sector
