The U.S. House of Representatives passed its $1.15 trillion fiscal year 2027 National Defense Authorization Act on Wednesday by a razor-thin 216–212 margin, carrying inside it a provision that would reauthorize the Cybersecurity Information Sharing Act for another ten years. CISA — the sharing statute, not the agency — had been stalled in reauthorization limbo for years, leaving the legal framework that governs voluntary threat-indicator sharing between private-sector organizations and the federal government in a state of procedural uncertainty. Attaching the reauthorization to the NDAA is the same legislative tactic Congress has used to move cybersecurity provisions that stall as standalone bills.

What the law actually does for healthcare

The Cybersecurity Information Sharing Act of 2015 created liability protections for private organizations — including hospitals, health systems, and their business associates — that voluntarily share cyberthreat indicators and defensive measures with federal agencies and with each other. Without those protections, sharing detailed threat data could expose an organization to antitrust claims or litigation from parties whose information appears in shared indicators.

For healthcare specifically, the statute underpins the Information Sharing and Analysis Center model that the Health-ISAC operates under. Member organizations can pass along indicators of compromise, phishing infrastructure, ransomware signatures, and attacker TTPs with a reduced legal exposure that would otherwise make counsel hesitant to approve any outbound sharing.

Why the reauthorization uncertainty mattered

The original act carried a sunset provision, and repeated Congresses failed to move a clean reauthorization bill through both chambers. That left participating organizations — and their legal teams — in a grey zone about the durability of the liability shield. For larger health systems with dedicated security operations, the practical effect was modest: sharing continued under existing agreements. For smaller independent practices and regional health centers that participate in shared threat feeds indirectly through their EHR vendors or regional HIEs, the uncertainty had less immediate operational weight but still touched the legal scaffolding those programs depend on.

A ten-year horizon, if the Senate accepts the NDAA provision and the bill is signed, would remove that uncertainty through the mid-2030s and give organizations more confidence that participation in structured sharing programs carries stable legal backing.

What still has to happen

The House passage is one step. The Senate must pass its own version of the NDAA, the two chambers must reconcile any differences in conference, and the president must sign the final bill. The Senate has historically moved its NDAA on a different timeline, and conference negotiations can strip or modify House-passed provisions. Healthcare compliance officers watching this issue should track Senate Armed Services Committee action rather than treat House passage as settled law.

If the provision survives to enactment, organizations participating in threat-sharing arrangements — or considering joining one — would have a cleaner legal foundation to present to counsel. The more immediate operational question for most independent practices remains whether they have the internal capacity to act on shared threat intelligence when they receive it, which the statute does not address.