Healthcare breaches cost 3x the industry average. See what HCRA's pending cybersecurity mandates mean for compliance — and how to get ahead of it.
For years, healthcare organizations operated under a familiar model: deploy tools, document policies, pass the audit. Compliance was a checkbox, not a discipline. The Health Care Cybersecurity and Resiliency Act (HCRA) is on track to end that model — permanently.
HCRA cleared the Senate HELP Committee by a bipartisan 22-1 vote in February 2026 and is now on the Senate Legislative Calendar, with House action and a presidential signature the remaining steps to enactment. It's one of the most significant federal cybersecurity efforts for the sector since HITECH. And once it's law, it won't just expand existing requirements — it will restructure how cybersecurity is defined, measured, and enforced across the entire healthcare industry. The implications extend well beyond IT departments.
Here's what the numbers tell you.
1. $10.9M avg. breach cost
Healthcare Breaches Cost Nearly 3× the Cross-Industry Average — and HCRA Will Make Inaction Harder to Defend
Healthcare consistently ranks as the most expensive sector for data breaches — with average incident costs nearly triple those of other industries. Once HCRA is signed into law, organizations that can't demonstrate proactive, measurable risk reduction will face compounded exposure: the breach cost itself, plus the regulatory and legal liability of falling short of the new standard of care. Compliance is becoming less about avoiding fines and more about establishing defensibility before an incident occurs — and that shift is worth planning for now, not after the bill is signed.
2. 86% lack framework proof
Most Organizations Claim Framework Alignment — But Can't Prove Control Effectiveness
The majority of healthcare organizations say they follow NIST or similar frameworks — but when audited, most can't demonstrate documented control mapping, continuous validation, or measurable remediation performance. HCRA is built to close that gap by making "adequacy" externally benchmarked rather than self-defined. Organizations that have claimed alignment without execution are the ones facing the highest transition risk once the bill takes effect. The gap between saying you're aligned and proving you are is about to disappear.
3. 1 in 3 rural hospitals at risk
Rural and Mid-Market Healthcare Is Specifically Targeted — Decentralized Security Won't Be Tolerated Much Longer
HCRA explicitly addresses resource-constrained environments, calling out rural and mid-market healthcare by name. Its direction: augment IT with external expertise, participate in shared regional programs, and migrate to secure cloud platforms. This isn't informal guidance — it's shaping up to be a mandate, with grant funding attached to help offset the cost. Roughly one in three rural hospitals currently operates below the cybersecurity maturity threshold HCRA is designed to enforce, making the outsourced security operating model not just practical but soon to be the legally expected one.
The through-line across all three numbers is the same: the gap between awareness and action is becoming a liability. Organizations that understand these risks but can't demonstrate measurable steps to reduce them are exactly who this legislation was written to hold accountable — and bipartisan momentum means the runway to prepare is shorter than it looks.
The question isn't whether your organization is aware of the threat landscape. It's whether your security program can produce evidence that you're reducing it — before the requirement to do so is law.
Is Your Program Built for the New Standard?
Download InfoSight's full analysis of the Health Care Cybersecurity and Resiliency Act — including a readiness checklist and implementation model for covered entities and business associates.
Download the Full Report →