Bill Details

HR.912 - 119th Congress

Track 9–8–8 Lifeline Cybersecurity Responsibility Act? Stop tracking 9–8–8 Lifeline Cybersecurity Responsibility Act?

When you track this bill you will receive emails when the bill has been updated.

You will no longer receive emails when this bill is updated.

Status
  1. Introduced
  2. Passed House
  3. Passed Senate
  4. To President
  5. Law
Latest action
2025-02-04 - Referred to the House Committee on Energy and Commerce.
Introduced Date
2025-02-04
Policy Area
Health
Committees
8
0

AI Summary This summary was generated by AI from the bill text. AI can get information wrong.

This bill would make the 9-8-8 suicide prevention lifeline stronger against hacking and other cybersecurity problems. It would require the system to take steps to fix known weak spots and protect the hotline from cyber incidents. It would also create new rules for quickly reporting security problems, while still protecting people’s private information. In addition, the bill calls for a government study of the lifeline’s cybersecurity risks so Congress can better understand what needs to be improved.

  • The lifeline’s main network operator would have to work to remove known cybersecurity weaknesses and help keep the system safe from attacks.
  • If a cybersecurity weakness or incident is found, the network operator and participating local or regional crisis centers would have to report it within a reasonable time.
  • These reports must be handled in a way that protects personal privacy and follows federal and state privacy laws.
  • The Government Accountability Office would have 180 days to study the lifeline’s cybersecurity risks and send its findings to the House and Senate committees that oversee health policy.

Official Summaries

9-8-8 Lifeline Cybersecurity Responsibility Act

This bill requires the Substance Abuse and Mental Health Services Administration (SAMHSA) to undertake efforts to protect the 9-8-8 Suicide & Crisis Lifeline from cybersecurity threats. (The lifeline is a three-digit number that connects callers in suicidal crisis or mental health distress to a national network of crisis centers.)

The bill also establishes related reporting requirements. Specifically, the network administrator for the lifeline must report identified cybersecurity incidents and vulnerabilities to SAMHSA, and local and regional crisis centers that participate in the lifeline must report identified cybersecurity incidents and vulnerabilities to the network administrator.

Additionally, the Government Accountability Office must conduct a study that evaluates cybersecurity risks and vulnerabilities associated with the lifeline and report the findings to Congress.

Current Full Text

[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[H.R. 912 Introduced in House (IH)]

<DOC>






119th CONGRESS
  1st Session
                                H. R. 912

To amend title V of the Public Health Service Act to secure the suicide 
    prevention lifeline from cybersecurity incidents, and for other 
                               purposes.


_______________________________________________________________________


                    IN THE HOUSE OF REPRESENTATIVES

                            February 4, 2025

 Mr. Obernolte (for himself and Mrs. Dingell) introduced the following 
    bill; which was referred to the Committee on Energy and Commerce

_______________________________________________________________________

                                 A BILL


 
To amend title V of the Public Health Service Act to secure the suicide 
    prevention lifeline from cybersecurity incidents, and for other 
                               purposes.

    Be it enacted by the Senate and House of Representatives of the 
United States of America in Congress assembled,

SECTION 1. SHORT TITLE.

    This Act may be cited as the ``9-8-8 Lifeline Cybersecurity 
Responsibility Act''.

SEC. 2. PROTECTING SUICIDE PREVENTION LIFELINE FROM CYBERSECURITY 
              INCIDENTS.

    (a) National Suicide Prevention Lifeline Program.--Section 520E-
3(b) of the Public Health Service Act (42 U.S.C. 290bb-36c(b)) is 
amended--
            (1) in paragraph (4), by striking ``and'' at the end;
            (2) in paragraph (5), by striking the period at the end and 
        inserting ``; and''; and
            (3) by adding at the end the following:
            ``(6) taking such steps as may be necessary to ensure the 
        suicide prevention hotline is protected from cybersecurity 
        incidents and eliminates known cybersecurity 
        vulnerabilities.''.
    (b) Reporting.--Section 520E-3 of the Public Health Service Act (42 
U.S.C. 290bb-36c) is amended--
            (1) by redesignating subsection (f) as subsection (g); and
            (2) by inserting after subsection (e) the following:
    ``(f) Cybersecurity Reporting.--
            ``(1) Notification.--
                    ``(A) In general.--The program's network 
                administrator receiving Federal funding pursuant to 
                subsection (a) shall report to the Assistant Secretary, 
                in a manner that protects personal privacy, consistent 
                with applicable Federal and State privacy laws--
                            ``(i) any identified cybersecurity 
                        vulnerabilities to the program within a 
                        reasonable amount of time after identification 
                        of such a vulnerability; and
                            ``(ii) any identified cybersecurity 
                        incidents to the program within a reasonable 
                        amount of time after identification of such 
                        incident.
                    ``(B) Local and regional crisis centers.--Local and 
                regional crisis centers participating in the program 
                shall report to the program's network administrator 
                identified under subparagraph (A), in a manner that 
                protects personal privacy, consistent with applicable 
                Federal and State privacy laws--
                            ``(i) any identified cybersecurity 
                        vulnerabilities to the program within a 
                        reasonable amount of time after identification 
                        of such vulnerability; and
                            ``(ii) any identified cybersecurity 
                        incidents to the program within a reasonable 
                        amount of time after identification of such 
                        incident.
            ``(2) Notification.--If the program's network administrator 
        receiving funding pursuant to subsection (a) discovers, or is 
        informed by a local or regional crisis center pursuant to 
        paragraph (1)(B) of, a cybersecurity vulnerability or incident, 
        within a reasonable amount of time after such discovery or 
        receipt of information, such entity shall report the 
        vulnerability or incident to the Assistant Secretary.
            ``(3) Clarification.--
                    ``(A) Oversight.--
                            ``(i) Local and regional crisis centers.--
                        Except as provided in clause (ii), local and 
                        regional crisis centers participating in the 
                        program shall oversee all technology each 
                        center employs in the provision of services as 
                        a participant in the program.
                            ``(ii) Network administrator.--The 
                        program's network administrator receiving 
                        Federal funding pursuant to subsection (a) 
                        shall oversee the technology each crisis center 
                        employs in the provision of services as a 
                        participant in the program if such oversight 
                        responsibilities are established in the 
                        applicable network participation agreement.
                    ``(B) Supplement, not supplant.--The cybersecurity 
                incident reporting requirements under this subsection 
                shall supplement, and not supplant, cybersecurity 
                incident reporting requirements under other provisions 
                of applicable Federal law that are in effect on the 
                date of the enactment of the 9-8-8 Lifeline 
                Cybersecurity Responsibility Act.''.
    (c) Study.--Not later than 180 days after the date of the enactment 
of this Act, the Comptroller General of the United States shall--
            (1) conduct and complete a study that evaluates 
        cybersecurity risks and vulnerabilities associated with the 9-
        8-8 National Suicide Prevention Lifeline; and
            (2) submit a report on the findings of such study to the 
        Committee on Health, Education, Labor, and Pensions of the 
        Senate and the Committee on Energy and Commerce of the House of 
        Representatives.
                                 <all>