Arkansas Is Pulling in Nearly Ten Times More Federal Cybersecurity Dollars Than It Did a Year Ago
A Boozman-earmarked health data grant and a recurring CISA award landed simultaneously, and the state is using both to shore up rural infrastructure that has long been its most exposed vulnerability.
Federal cybersecurity-tagged grants flowing into Arkansas have reached $15.04 million in the past 90 days, up 851 percent from $1.58 million in the same window a year ago, and the largest check is not going to a city IT department or a defense contractor, but to a rural health information exchange trying to make sure a doctor in the Arkansas Delta can see a patient's records before treating them.
The surge is the product of two distinct federal streams that landed at nearly the same moment. The dominant award is a $13.3 million HHS appropriation, championed by Sen. John Boozman as part of the Labor, HHS, Education, and Related Agencies Appropriations Act of 2026, directed to the Arkansas Department of Health to fund the Arkansas Health Data Infrastructure Modernization and Interoperability Initiative. That program expands participation in SHARE, the state's official health information exchange, upgrades electronic medical record systems across rural hospital systems, and modernizes telehealth hardware and software, with secure data exchange built in as an explicit component. According to the Arkansas Department of Health, the grant started September 30, 2026, and runs through September 2027. Governor Sarah Sanders backed it publicly, describing it as closing the gap between patients and providers.
The second stream is more conventionally cyber in its purpose. DHS and CISA awarded Arkansas $1.58 million through the FY2025 State and Local Cybersecurity Grant Program, the fourth consecutive annual SLCGP award to the state. Arkansas's share of the FEMA-administered $91.75 million national allocation flows through the Division of Emergency Management, the Division of Information Systems, the Arkansas Municipal League, and the Association of Arkansas Counties, funding network risk assessments and infrastructure hardening for state and local government systems statewide. The two awards are different instruments doing different things: the HHS grant is a Boozman-directed Congressional earmark for health modernization; the SLCGP is a competitive federal program for government-network risk reduction. Both happened to activate around September 30, 2026, which is what produces the statistical spike in the trailing 90-day window.
Arkansas ranks 2nd among regional peers in federal cybersecurity grants, trailing 90 days
Source: NationGraph.
The distinction matters because the $13.3 million award's cybersecurity component is embedded, not standalone. The primary mission is health data interoperability for a state where fragmentation is an acute problem: rural Arkansas hospitals frequently lack the capital to modernize on their own, and SHARE is the connective tissue holding those systems together. Hardening that exchange against intrusion is a security priority, but the grant funds the broader infrastructure as well. Arkansas Tech University is separately receiving a $2 million NSF workforce grant, running from July 2026 through 2032, to fund cybersecurity scholarships for low-income students, a pipeline investment with no direct connection to the infrastructure programs.
Taken together, the three awards place Arkansas second among seven neighboring and peer states in cybersecurity-tagged federal grant volume over the past 90 days, behind only Texas at $20.5 million and ahead of Tennessee ($6.7 million), Mississippi ($6.3 million), Louisiana ($3.9 million), and Oklahoma ($3.1 million). For a state not typically associated with technology investment, that ranking reflects an unusually efficient use of Congressional appropriations channels: Arkansas's Republican trifecta is aligned with federal Republican leadership, making Boozman-directed earmarks a relatively direct funding path.
The timing is not coincidental. The Senate engrossed the Health Care Cybersecurity and Resiliency Act (S. 3315) on September 30, 2026, the same day the HHS grant started. That bill would mandate baseline cybersecurity practices for all HIPAA-covered entities, including multi-factor authentication, encryption, and penetration testing, and would authorize grant support specifically for rural providers. It is not yet law, but its momentum is putting hospitals on notice. HHS separately issued a proposed rule in late 2024 to tighten HIPAA security requirements; the final-rule deadline has been pushed to July 2027. Donald McCormick, director of data and financial policy at the Arkansas Hospital Association, told Arkansas Business that hospitals are "actively enhancing their cybersecurity as fast as they can" in response to that pressure.
What that means practically for Arkansans is a state government and hospital sector simultaneously upgrading the security of the systems that hold their health records and process their interactions with local governments. Rural patients who rely on small critical-access hospitals should see those facilities better connected to statewide records systems over the next 12 months as the SHARE expansion rolls out. Local governments across the state should see free risk assessments and hardening support through the SLCGP pass-through infrastructure.
The next signal to watch is whether S. 3315 advances in the House. If it becomes law, it would authorize a new round of federal grants specifically for rural HIPAA-covered entities, and Arkansas, with its existing SHARE infrastructure and a demonstrated capacity to absorb federal health-data dollars, would be positioned to compete for them. A second signal is the July 2027 deadline for the HHS HIPAA Security Rule final rule, which will set the compliance baseline that determines how much more hardening Arkansas hospitals need to do after this round of investment is spent.