nisttrade-pressNewsThe Broadside2 min read

GAO Finds 988 Lifeline Cybersecurity Controls Fall Short

HHS and its network administrator didn't always follow their own monitoring processes, and key NIST-aligned controls were left out of the agreements that govern the lifeline's 215-plus contact centers.


TL;DR

A GAO audit of the 988 Suicide & Crisis Lifeline found that HHS and its network administrator failed to include most of the department's own essential cybersecurity controls in the agreements binding the lifeline's roughly 220 local contact centers. The cooperative agreement for fiscal 2026 included only 3 of HHS's 10 control areas aligned with NIST guidance. Missing: protections against email-based attacks and requirements for separate administrator accounts. Of a dozen centers reviewed, none submitted all required compliance documentation on time, and five were still incomplete as of March. The audit follows a 2022 ransomware incident that disrupted service for several hours. Demand has surged, the lifeline handled 8 million calls, texts, and chats in 2025 alone.

The GAO report lands three years after a ransomware attack knocked the 988 Suicide & Crisis Lifeline offline for several hours. The attack didn't bring the system down permanently, but it concentrated attention on a question that hadn't been asked loudly enough: how well is the nation's largest crisis hotline defended?

The answer, per the watchdog, is not well enough.

HHS's Substance Abuse and Mental Health Services Administration defined 10 essential cybersecurity control areas aligned with NIST guidance. But when SAMHSA set the terms for the network administrator's fiscal 2026 cooperative agreement, it baked in only three. Neither the cooperative agreement nor the administrator's agreements with contact centers required controls for email-based attacks or separate accounts for regular users and administrators. These aren't exotic measures, they're the kind of things that show up on page two of a baseline controls assessment.

What monitoring found, and what it didn't

HHS and the network administrator each had two processes for monitoring contact-center compliance. Then they didn't always follow them. GAO reviewed compliance checklists for 12 crisis centers: none submitted all required documentation before the deadline, and five still hadn't as of March.

The administrator made progress on multifactor authentication, requiring it for the platforms it manages. But password guidance hadn't been updated to reflect current NIST recommendations, it still mandates periodic password changes and special characters. Incident response was similarly uneven: the administrator had implemented controls, but individual contact centers had only partially done so, including incomplete incident response plans and testing.

The expansion underneath the exposure

The lifeline isn't shrinking. Contact volume hit 8 million in 2025, up from roughly 5 million when the three-digit number launched in mid-2022. The system routes through a federated network of nearly 220 centers, each a potential entry point. Congress raised the stakes last year when it passed the SUPPORT for Patients and Communities Reauthorization Act, which requires the lifeline to report cybersecurity incidents and directed GAO to conduct this review.

The GAO's recommendations are plain: put the missing controls into the agreements, and follow the monitoring processes that already exist. Neither requires new regulation. Both are things HHS can do Monday.


Published ·Deep Fathom