The Government Accountability Office (GAO) recently found that the Department of Health and Human Services (HHS) has not fully implemented cybersecurity controls for the 988 Suicide and Crisis Lifeline, leaving the service exposed to potential hacks.
What happened
GAO reviewed the cybersecurity posture of the 988 Lifeline and found that the service has not implemented updated identity and access controls, including updated password guidance. GAO also said the Lifeline should improve its cybersecurity contingency plans.
HHS defined cybersecurity controls but did not include many of them as requirements in its fiscal 2026 cooperative agreement with the network administrator or in the administrator's agreement with the contact centers. The agency also did not always follow its own cybersecurity monitoring practices. GAO made 10 recommendations to HHS. The agency said it supports them but pointed to constraints.
The backstory
A ransomware attack hit the 988 line in 2022 and interrupted service for several hours. Last year, Congress passed the SUPPORT for Patients and Communities Reauthorization Act of 2025, which requires the line to report cybersecurity incidents and vulnerabilities. The law also directed GAO to review the service's cybersecurity.
The Substance Abuse and Mental Health Services Administration (SAMHSA) and the Mental Health Association of New York City created the lifeline in 2005. In 2007, SAMHSA partnered with the Department of Veterans Affairs (VA) to create a veterans crisis line. In 2022, the services became a nationwide three-digit number for suicide prevention.
Going deeper
- Agreements: HHS's agreement with the network administrator covers only three of the agency's 10 cybersecurity control areas, which align with National Institute of Standards and Technology (NIST) guidance. Neither type of agreement includes controls against email-based attacks or requirements for separate accounts for common users and administrators.
- Monitoring: HHS and the network administrator each have two processes to monitor compliance, but neither always follows them. GAO reviewed compliance checklists for a dozen crisis contact centers. None of the centers provided all required documentation before the deadline, and five still had not submitted everything as of March.
- Passwords and authentication: The administrator requires two-factor authentication on the platforms it manages, but it has not updated its password guidance. It still requires password changes and special characters.
- Incident response: The administrator implemented incident response controls, but the contact centers struggled to do the same. They only partially developed incident response plans and only partially conducted incident response training and testing.
- HHS's response: Agency officials said they lack the authority to require all controls in non-federal systems. They said the network administrator can include the controls in its agreement with contact centers, and that future versions of the agreement will include them. They also said enforcement is difficult since each center's relationship with the administrator is voluntary.
What was said
The GAO report warned that without full implementation of these controls, the lifeline faces a higher risk of cybersecurity incidents that could "prevent individuals in crisis access to timely mental health support."
HHS told GAO that its main recourse for noncompliance, such as a center failing to submit required documentation, is to "remove a crisis contact center from the 988 Lifeline network."
A VA official wrote that the agency "strongly supports" all of the recommendations for HHS. The VA's letter described its own cybersecurity efforts for the Veterans Crisis Line, including adherence to NIST guidance. The official said the VA's crisis line faces risk if 988 suffers an attack, and that the VA stands ready to share its practices and lessons.
By the numbers
- 8 million contacts (calls, texts, and chats) reached the 24/7 lifeline in 2025, according to GAO.
- Nearly 220 local contact centers make up the federated network.
- HHS's agreement with the administrator covers 3 of 10 essential control areas.
- 0 of 12 reviewed contact centers submitted all required compliance documentation before the deadline.
- 5 of those 12 centers still had not submitted everything as of March.
- GAO made 10 recommendations to HHS.
In the know
A network administrator oversees the 988 Lifeline on behalf of HHS and manages a federated system of nearly 220 local contact centers across the country. Each center has a voluntary relationship with the administrator. This structure shapes who can require and enforce security controls.
Why it matters
The 988 Lifeline exists to reach people in crisis, so an outage affects people's access to help. The 2022 ransomware attack already shut down service for several hours, and GAO warns that gaps in access controls and contingency planning raise the risk of longer disruptions. Demand keeps growing, with 8 million contacts in 2025 alone.
The network's structure makes fixing these gaps harder. HHS says it cannot require all controls in nonfederal systems, and its only real enforcement tool is removing a contact center from the network. Removing a center would also take capacity away from a service that people depend on. Meanwhile, five of the 12 reviewed centers still had not submitted all required compliance documents as of March.
The bottom line
GAO's findings show that a security program is only as strong as the requirements written into its agreements and the follow-through on monitoring. HHS says future versions of the administrator's agreement with contact centers will include the missing controls. The 988 Lifeline now needs to follow through on that commitment and GAO's 10 recommendations before another incident interrupts service for people in crisis.
FAQs
Why are access controls important for the 988 Lifeline?
Access controls help limit access to systems and information to authorized users only. In the abovementioned case, the GAO found that some recommended access controls were not included in HHS's agreements with the network administrator and crisis contact centers.
What is a cybersecurity contingency plan?
A contingency plan is a documented set of steps an organization follows to keep services running or restore them quickly after a cyber incident or outage.
What is an incident response plan?
An incident response plan outlines who does what to detect, contain, and recover from a security incident, and regular training and testing help teams carry it out under pressure.
