cybersecurity
Every record this desk has filed under cybersecurity, newest first, each with the number of sources it can still show you.
The 988 crisis line went dark for hours after a 2022 cyberattack. Four years later, GAO found seven of HHS's own required security control areas were never written into the agreement that runs it.
GAO's September 17 report on the 988 Suicide and Crisis Lifeline — the number roughly 220 local crisis contact centers answer — finds the cybersecurity controls protecting it only partly in place. HHS defined oversight roles but 'did not include all key HHS-defined cybersecurity control areas' in its cooperative agreement with the network administrator, nor in the administrator's agreement with the crisis centers: seven missing control areas in the first, three in the second. The network administrator has not implemented current NIST password guidance and only partly implemented contingency-plan controls; the crisis centers have only partly implemented incident response and contingency planning. GAO's stated risk is specific: prolonged service disruption 'could... potentially prevent individuals in crisis access to timely mental health support.' Congress ordered this review in the SUPPORT for Patients and Communities Reauthorization Act of 2025. Ten recommendations, all open; HHS concurred with all of them.
Also filed undergaohhs988mental-healthoversight
A record appears here because it carries cybersecurity in its own frontmatter. If a record you expected is missing, it was filed under a different subject — the full list is on the topics index.