CISA has submitted the final CIRCIA rule to the White House Office of Information and Regulatory Affairs for review. The rule will require critical infrastructure entities to report covered cyber incidents and ransomware payments within strict timelines. Healthcare organizations should prepare now for federal cyber incident reporting obligations that may overlap with HIPAA breach notification requirements.
The Cybersecurity and Infrastructure Security Agency (CISA) has submitted the final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) to the White House Office of Information and Regulatory Affairs (OIRA) for review. This procedural step, reported on October 5, 2026, signals that the long-anticipated federal cyber incident reporting regime is nearing publication and enforcement.
CIRCIA, signed into law in March 2022, directs CISA to develop regulations requiring covered entities in critical infrastructure sectors to report substantial cyber incidents and ransomware payments. The rule has been under development for more than four years, with a notice of proposed rulemaking (NPRM) published in April 2024 that drew extensive public comment from industry, legal, and healthcare stakeholders.
The submission to OIRA initiates the final stage of federal regulatory review, which typically takes 30 to 90 days, though timing can vary. Once OIRA completes its review, the rule will be published in the Federal Register as a final rule with an effective date.
CIRCIA applies to "covered entities" across 16 critical infrastructure sectors, including the Healthcare and Public Health (HPH) sector. Within healthcare, this includes:
The CIRCIA final rule introduces federal cyber incident reporting requirements that will coexist with, but not replace, the HIPAA Breach Notification Rule. Key compliance considerations include:
Healthcare organizations that experience a ransomware attack or substantial breach may need to report to both CISA and the HHS Office for Civil Rights (OCR). The proposed CIRCIA rule requires reporting of "covered cyber incidents" within 72 hours of reasonable belief that an incident occurred, plus reports on ransomware payments within 24 hours of payment. HIPAA, by contrast, requires breach notification to OCR within 60 days for incidents affecting 500 or more individuals.
CIRCIA's 72-hour incident reporting window is significantly shorter than HIPAA's 60-day breach notification deadline. Organizations will need to develop rapid detection and triage capabilities to determine whether an incident qualifies as a "covered cyber incident" under CIRCIA and trigger federal reporting within the compressed timeline.
The final rule is expected to clarify the definition of a "substantial cyber incident" — the proposed rule defined this as an incident resulting in substantial loss of confidentiality, integrity, or availability, serious impact on safety, or disruption of business operations. Healthcare organizations should review these definitions against their existing security incident response and reporting procedures.
CIRCIA also requires covered entities to preserve relevant data related to a reported incident for two years. This data preservation obligation is separate from HIPAA documentation requirements and may require technical and governance adjustments.
1. Inventory regulatory obligations. Map all incident reporting requirements — HIPAA, state breach notification laws, and upcoming CIRCIA obligations — into a unified incident response playbook.
2. Update incident response plans. Incorporate CIRCIA's 72-hour incident reporting and 24-hour ransomware payment reporting timelines into existing response procedures, with clear roles and decision authority.
3. Conduct gap assessments. Evaluate current detection, logging, and triage capabilities to ensure the organization can identify a reportable incident within the required timeframe.
4. Train response teams. Ensure legal, compliance, and security teams understand the interplay between HIPAA breach notification and CIRCIA reporting to avoid delays or conflicting disclosures.
5. Monitor the Federal Register. Track OIRA review status and be prepared to implement requirements promptly once the final rule is published, as CISA has indicated it may not provide an extended implementation period.
The submission of the CIRCIA final rule to OIRA marks a decisive step toward implementing the most significant expansion of federal cyber incident reporting in U.S. history. Healthcare organizations should treat the coming rule as a near-term compliance obligation and begin preparation now, rather than waiting for the Federal Register publication date.
CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act of 2022. The final rule implements the law by requiring covered entities in critical infrastructure sectors—including healthcare—to report substantial cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.
The rule was submitted to the White House OIRA for review in October 2026. Typical OIRA review takes 30 to 90 days, after which the rule will be published in the Federal Register. While the exact effective date is not yet public, healthcare organizations should prepare for implementation within months of publication, as CISA has signaled limited transition time.
HIPAA requires covered entities to report breaches affecting 500+ individuals to HHS OCR within 60 days. CIRCIA requires reporting substantial cyber incidents to CISA within 72 hours and ransomware payments within 24 hours. The two obligations are separate and may both apply to the same incident.
No. CIRCIA reporting to CISA is an additional federal obligation that runs parallel to HIPAA breach notification to HHS OCR. Healthcare organizations must comply with both frameworks when an incident triggers reporting requirements under each law.
Under the proposed rule, a "covered cyber incident" is one that results in substantial loss of confidentiality, integrity, or availability; serious impact on safety of operational systems; or disruption of business operations. The final rule's exact definition and thresholds are expected to be clarified when published after OIRA review.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free