S. 1007
119th CONGRESS 1st Session
To amend title V of the Public Health Service Act to secure the suicide prevention lifeline from cybersecurity incidents, and for other purposes.
IN THE SENATE OF THE UNITED STATES · March 12, 2025 · Sponsor: Mr. Mullin · Committee: Committee on Health, Education, Labor, and Pensions
Table of contents
SEC. 1. Short title
- This Act may be cited as the 9–8–8 Lifeline Cybersecurity Responsibility Act.
SEC. 2. Protecting suicide prevention lifeline from cybersecurity incidents
- (a) National suicide prevention lifeline program
- Section 520E–3(b) of the Public Health Service Act (42 U.S.C. 290bb–36c(b)) is amended—
- in paragraph (4), by striking
andat the end; - in paragraph (5), by striking the period at the end and inserting
; and; and- coordinating with the Chief Information Security Officer of the Department of Health and Human Services to take such steps as may be necessary to ensure the program is protected from cybersecurity incidents and eliminates known cybersecurity vulnerabilities.
- by adding at the end the following:
- in paragraph (4), by striking
- Section 520E–3(b) of the Public Health Service Act (42 U.S.C. 290bb–36c(b)) is amended—
- (b) Reporting
- Section 520E–3 of the Public Health Service Act () is amended— 42 U.S.C. 290bb–36c
- by redesignating subsection (f) as subsection (g); and
- (f) Cybersecurity reporting
- (1) In general
- (A) In general
- The program’s network administrator receiving Federal funding pursuant to subsection (a) shall report to the Assistant Secretary, in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws—
- (i) any identified cybersecurity vulnerabilities to the program within 24 hours of identification of such a vulnerability; and
- (ii) any identified cybersecurity incidents to the program within 24 hours of identification of such incident.
- The program’s network administrator receiving Federal funding pursuant to subsection (a) shall report to the Assistant Secretary, in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws—
- (B) Local and regional crisis centers
- Local and regional crisis centers participating in the program shall report to the program’s network administrator described in subparagraph (A), in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws—
- (i) any identified cybersecurity vulnerabilities to the program within 24 hours of identification of such vulnerability; and
- (ii) any identified cybersecurity incidents to the program within 24 hours of identification of such incident.
- Local and regional crisis centers participating in the program shall report to the program’s network administrator described in subparagraph (A), in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws—
- (A) In general
- (2) Notification
- If the program’s network administrator receiving funding pursuant to subsection (a) discovers, or is informed by a local or regional crisis center pursuant to paragraph (1)(B) of, a cybersecurity vulnerability or incident described in such paragraph, within 24 hours of such discovery or receipt of information, such entity shall report the vulnerability or incident to the Assistant Secretary.
- (3) Clarification
- (A) Oversight
- (i) Except as provided in clause (ii), local and regional crisis centers participating in the program shall oversee all technology each center employs in the provision of services as a participant in the program.
- (ii) The program’s network administrator receiving Federal funding pursuant to subsection (a) shall oversee the technology each crisis center employs in the provision of services as a participant in the program if such oversight responsibilities are established in the applicable network participation agreement.
- (B) Supplement, not supplant
- The cybersecurity incident reporting requirements under this subsection shall supplement, and not supplant, cybersecurity incident reporting requirements under other provisions of applicable Federal law that are in effect on the date of the enactment of the .
- (A) Oversight
- (1) In general
- (f) Cybersecurity reporting
- by inserting after subsection (e) the following:
- by redesignating subsection (f) as subsection (g); and
- Section 520E–3 of the Public Health Service Act () is amended— 42 U.S.C. 290bb–36c
- (c) Study
- Not later than 180 days after the date of the enactment of this Act, the Comptroller General of the United States shall—
- conduct and complete a study that evaluates cybersecurity risks and vulnerabilities associated with the 9–8–8 National Suicide Prevention Lifeline; and
- submit a report of the findings of such study to the Committee on Energy and Commerce of the House of Representatives and the Committee on Health, Education, Labor, and Pensions of the Senate.
- Not later than 180 days after the date of the enactment of this Act, the Comptroller General of the United States shall—