Rural Hospital Cybersecurity Enhancement Act
Click any stage to learn more about the legislative process.
Would require the Department of Health and Human Services to develop a cybersecurity workforce development strategy for rural hospitals and publish free staff training materials — both within one year of enactment — to address a shortage of skilled cybersecurity professionals in those facilities.
What this bill would do
What it would do
The bill would direct the HHS Secretary to develop, within one year, a comprehensive strategy for building a cybersecurity workforce in rural hospitals. The strategy must consider partnerships among rural hospitals, non-rural hospitals, educational institutions, and private entities; the development of cybersecurity curricula for community colleges and vocational schools in rural areas; and identification of cybersecurity workforce challenges specific to rural hospitals with recommended practices to address them. HHS must consult with the Cybersecurity and Infrastructure Security Agency, the Departments of Education and Labor, the National Cyber Director, and at least two rural health care provider representatives from each of the nine U.S. Census geographic divisions.
Separately, within the same one-year window, HHS would be required to publish free instructional materials on its website for rural hospitals to use in training staff on basic cybersecurity. HHS would also conduct an awareness campaign to promote those materials. After the strategy is transmitted, HHS must provide annual briefings to Congress. Notably, the bill explicitly authorizes no additional funds for implementation.
Key provisions
- 1Would require HHS to develop and transmit to Congress a comprehensive rural hospital cybersecurity workforce development strategy within one year of enactment.
- 2Would require HHS to consult with CISA, the Departments of Education and Labor, the National Cyber Director, and at least two rural health care provider representatives from each of the nine Census geographic divisions.
- 3Would require the strategy to address public-private partnerships, rural cybersecurity curricula for community colleges and vocational schools, and identification of workforce challenges with recommended mitigation practices.
- 4Would require HHS to provide annual briefings to Congress on strategy updates, programs established, number of individuals trained, and overall effectiveness.
- 5Would require HHS to publish free instructional materials for rural hospital staff cybersecurity training on its website within one year, supported by an awareness campaign.
- 6Explicitly authorizes no additional funds to carry out any provision of the Act.
Who would be affected
Rural hospitals as defined under Medicare law — including critical access hospitals, sole community hospitals, Medicare-dependent small rural hospitals, low-volume hospitals, and rural emergency hospitals — and their clinical and administrative staff who would be trained using the new materials. Community colleges, vocational schools, and other rural educational institutions could also be affected if they adopt the cybersecurity curricula the strategy envisions.
Why it matters
Rural hospitals typically have limited IT staff and budgets, making them more vulnerable to cyberattacks that can disrupt patient care. If enacted, this bill would push the federal government to map the cybersecurity workforce gap at those facilities and produce free, ready-to-use training materials — but because no new funding is authorized, the impact depends entirely on resources HHS can redirect within existing appropriations.
What would change
Agencies directed to act
Effective dates
- HHS must complete and transmit the workforce development strategy
- HHS must publish free instructional materials for rural hospital staff
- First annual congressional briefing on the strategy is due
Funding and costs
Congressional Budget Office estimate
CBO estimates S. 2169 would cost $8 million over the 2026–2030 period, subject to appropriation, with no effect on direct spending, revenues, or the deficit.
CBO estimates that S. 2169, the Rural Hospital Cybersecurity Enhancement Act, would have no effect on direct (mandatory) spending or revenues, leaving the deficit unchanged over the 2026–2035 period. The bill's costs — estimated at $8 million over 2026–2030 — are discretionary spending subject to the availability of appropriated funds, driven by the equivalent of two additional full-time HHS staff needed to prepare reports, develop online training resources, and publish instructional materials for rural hospital cybersecurity employees. CBO did not estimate costs beyond 2030. The bill contains no intergovernmental or private-sector mandates.
How implementation would work
HHS would lead all activity: developing the workforce strategy through interagency consultation and input from at least 18 rural provider representatives (two per Census division), then transmitting the strategy to the Senate HELP, Senate Finance, House Energy and Commerce, and House Ways and Means committees. Annual briefings must follow within 60 days after each fiscal year end, covering strategy updates, program outcomes, and training numbers. For instructional materials, HHS would survey existing cybersecurity resources, adapt or create new ones, post them on the HHS website at no charge, and run an awareness campaign — all within the same one-year deadline.
Legislative status & sources
Latest action
Placed on Senate Legislative Calendar under General Orders. Calendar No. 309.
Official CRS summary
Show the CRS summaryHide the CRS summary
This bill requires the Department of Health and Human Services (HHS) to create a workforce development strategy to address the need for cybersecurity professionals in rural hospitals.
Among other topics, the strategy must consider (1) partnerships between rural hospitals, hospitals that are not rural hospitals, educational institutions, and private nonprofit or for-profit entities; and (2) the development of a cybersecurity curriculum for use in rural educational institutions. HHS must annually brief Congress on the strategy and any programs or initiatives established thereunder.
Additionally, HHS must disseminate free materials that rural hospitals may use to train staff about cybersecurity.
Legislative subjects
Computer security and identity theft; Health facilities and institutions; Higher education; Rural conditions and development; Science, Technology, Communications; Vocational and technical education