A U.S. Senate committee overwhelmingly passed the Healthcare Cybersecurity and Resiliency Act of 2025 (HCRA). This bill, known as S. 3315, includes a grant program to help fund cybersecurity for many healthcare organizations.
The committee passed the bill with a bipartisan 22-1 vote to move the bill to the Senate floor. Next, the full Senate and House of Representatives must pass the bill. Then, the President has to sign it into law.
Why MSPs Should Pay Attention to HCRA
The proposed HCRA bill includes just a handful of required cybersecurity practices, like MFA, encryption, pen testing, and cybersecurity audits. It also states that additional requirements must be developed with input from the private sector. Meanwhile, the proposed HIPAA Security Rule update included many strict requirements to which the industry objected during the public comment period and in letters to government officials.
Most notably, HCRA includes grant funding. This money can be used by healthcare organizations for cybersecurity tools and to hire third parties — including MSPs or MSSPs — to implement security.
A wide variety of healthcare organizations will qualify for funding under the bill, including:

Mike Semel
- Public or nonprofit private health centers
- Indian Health Service clinics
- Hospitals
- Cancer centers
- Rural health clinics
- Academic health centers
- Nonprofit entities that partner or coordinate referrals with qualifying providers
The grants exclude private for-profit medical practices.
How This Affects the HIPAA Security Rule Update
The bipartisan support and HCRA’s alignment with the recently published Cyber Strategy for America may have another result. The HIPAA Security Rule update, which is widely unpopular throughout the health care industry for being expensive, may not publish as scheduled in May 2026.
If the HIPAA Security Rule update is published, the HCRA will help many organizations cover part or all of their costs of implementation. But if it is shelved, HCRA will set basic healthcare cybersecurity practices and help pay for them.
The MSP Takeaway
Regardless of which way things go, MSPs can benefit. There are several ways to maximize your opportunities with healthcare regulation.
You want to be the one people remember for first telling them about the new HIPAA Security Rule and the pending Healthcare Cybersecurity and Resiliency Act of 2025.
Mike Semel, owner of Semel Consulting, is a recognized HIPAA authority in the MSP and healthcare industries. Semel authored the best-selling book, How to Avoid HIPAA Headaches. His Compliance MASTERY for MSPs training system for MSPs includes a HIPAA training course with templates and checklists.
Featured image: AI generated by Copilot












