If you call 988, the call goes to one of roughly 220 local crisis contact centers. The network that routes it is run, on HHS's behalf, by a network administrator. In December 2022 that network was attacked.
GAO's description of what happened is one sentence long and worth reading slowly:
These services were severely impacted in December 2022 by a cybersecurity attack that compromised critical 988 network infrastructure, leading to a nationwide service disruption lasting several hours.
Congress asked for this report. The SUPPORT for Patients and Communities Reauthorization Act of 2025 "includes a provision for GAO to report on the 988 Lifeline cybersecurity risks and vulnerabilities."
What GAO found in the paperwork
The first finding is not about a firewall. It is about a contract.
HHS has its own list of cybersecurity control areas — its Cybersecurity Performance Goals. GAO found that HHS "did not include all key HHS-defined cybersecurity control areas in the 988 Lifeline cooperative agreement with its network administrator or for the network agreement between the administrator and crisis contact centers."
How many were missing is in the recommendations themselves: seven control areas absent from the cooperative agreement with the network administrator, and three absent from the network agreement between the administrator and the crisis centers.
A control area that is not in the agreement is not a requirement anybody can be held to. That is the whole point of writing it down.
GAO also found the monitoring itself uneven: HHS "established processes to monitor security control implementation but did not always adhere to them."
What GAO found in the systems
Against selected NIST controls:
While the network administrator and crisis contact centers fully implemented selected continuous monitoring controls, they have not consistently implemented other selected cybersecurity controls identified in guidance from the National Institute of Standards and Technology.
Specifically, per GAO: the network administrator "has not implemented identity and access controls related to updated password guidance and partially implemented controls related to contingency plans." The crisis contact centers "have partially implemented incident response and contingency planning controls."
Contingency planning is the plan for what happens when the thing goes down. Incident response is what you do while it is down. Those are the two controls that decide how long "several hours" is next time.
The risk, stated plainly
GAO does not leave the consequence abstract:
Without the full implementation of these controls, the 988 Lifeline faces increased risk of cybersecurity incidents, which could result in prolonged service disruptions and potentially prevent individuals in crisis access to timely mental health support.
Ten recommendations, and an agency that agreed
"GAO is making 10 recommendations to HHS to update the cooperative and network agreements and to fully implement key cybersecurity controls. HHS concurred with the recommendations."
Concurrence is not implementation, and GAO records the difference: every one of the ten carries the status Open, each with the same line — "When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information."
The first two are the contractual ones: incorporate the seven missing control areas into the cooperative agreement, and work with the network administrator to incorporate the three missing areas into its agreement with the crisis centers. Those two cost nothing but drafting, and until they are done the rest are requests rather than requirements.
This desk has added the ten to its open-requests board, where the count runs from the day they were made.
If you or someone you know is in crisis, 988 answers by call or text. The finding above is about how well the network behind that number is defended, not about whether it works.
