



A GAO review finds HHS has only partially overseen cybersecurity for the 988 Suicide and Crisis Lifeline, which is run by a network administrator managing nearly 220 local crisis contact centers. HHS did not include all key cybersecurity control areas in its agreements with the administrator or between the administrator and the contact centers, and did not always follow its own monitoring processes.
The network administrator has not implemented updated password guidance or fully built out contingency plans, and crisis contact centers have only partially implemented incident response and contingency planning controls, per NIST standards. The Lifeline suffered a cybersecurity attack in December 2022 that caused a nationwide service disruption lasting several hours.
GAO made 10 recommendations to strengthen oversight and security controls; HHS concurred with all of them.
The full dispatch is available from the source below.