"The federal government’s coverage for 22.1 million people hoovered up in the 2015 China-linked breaches is scheduled to end Sept. 30."
22.1 million affected and the approaching Sept. 30 cutoff
Just over a decade after the Office of Personnel Management breaches, the federal identity-protection services put in place for those incidents are expiring. The two intrusions compromised information belonging to about 22.1 million current, former and prospective federal employees, contractors and others — one intrusion exposed personnel records for roughly 4.2 million people, while a second compromised 21.5 million background-investigation records, with an overlap of about 3.6 million people, according to the Government Accountability Office.
People who enrolled in OPM’s MyIDCare program are receiving notices that their complimentary coverage will end 10 years after their individual enrollment date. Some notices began arriving late last year and will continue through September, when OPM plans to conclude the services at the end of the federal fiscal year.
RECOVER PII Act: Warner and Norton’s proposal
Senate Intelligence Committee Vice Chair Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., plan to introduce the RECOVER PII Act, according to bill text first seen by Nextgov/FCW. Sens. Tim Kaine, D-Va.; Angela Alsobrooks, D-Md.; and Chris Van Hollen, D-Md., are listed as Senate cosponsors.
The legislation would replace the current 10-year limit with identity-protection coverage lasting for the remainder of each affected person’s life while retaining the statutory requirement that victims receive no less than $5 million in identity-theft insurance. The bill is described in the text as bicameral and would seek to prevent the scheduled Sept. 30 expiration of government-provided identity services for OPM breach victims.
“We have a responsibility to stand by the federal workers who were put at risk through no fault of their own,” Warner said in the statement accompanying the bill text. “This legislation will ensure those affected continue to receive the identity protection they need, while helping better safeguard personal information from future exploitation.”

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →MyIDCare notices, past law, and agency reimbursements
Congress initially responded to the breaches in a 2017 appropriations law by requiring OPM to provide breach victims with at least 10 years of complimentary identity protection and no less than $5 million in identity-theft insurance. The current notices being mailed to enrollees mark the rolling end of that statutorily mandated 10-year window.
The RECOVER PII Act would also empower agencies to reimburse federal employees and contractors for privacy tools and services — for example, services that remove or limit personal information online. Those reimbursements would be discretionary, decided by agencies, would not be limited to OPM breach victims, and would come from agencies’ salary-and-expense budgets.
Government Accountability Office findings on long-term value of stolen records
GAO has warned that foreign intelligence services can retain the OPM records for years, combine them with information from other cyber intrusions, and use the fuller picture to identify or target government personnel and their families. The record set stolen in 2015 remains useful as adversaries merge it with other data sources, and the risk can grow over time if a person whose records were taken in 2015 later moves into a more sensitive national security role.
GAO also cautioned last year that adversaries can combine publicly available data to identify military personnel and their families or disrupt Defense Department operations, a point the bill’s backers invoke to justify a shift from a fixed-term remedy to lifetime protection.
How federal employees, agencies, policymakers, and adversaries are placed by the proposal
- Affected federal employees and contractors: Many are already receiving MyIDCare notices that their coverage will end 10 years after enrollment; the RECOVER PII Act would, if enacted, replace those expirations with lifetime protection and maintain the minimum insurance requirement.
- Agencies and human-resources offices: Would gain discretionary authority to reimburse privacy tools and services from salary-and-expense budgets, a change that could expand operational responses beyond only those enrolled in OPM programs.
- Policymakers and legislators: Face a decision about whether to overturn the 10-year statutory limit set in 2017 and accept permanent coverage; Norton previously introduced similar lifetime-protection bills that did not become law.
- Foreign intelligence services and other adversaries: Remain a central justification for the legislation because GAO finds the stolen records can be retained and combined with other data to identify, target or track personnel over time.
Del. Eleanor Holmes Norton framed the argument for permanence plainly: “Lifetime identity protection is the only solution that will give the workers whose data was compromised the peace of mind they deserve,” she said in the statement accompanying the bill text, adding that “there is no limit on how long personal information can be exploited.”
The RECOVER PII Act’s introduction — planned for Monday in the bill text Nextgov/FCW reviewed — moves the debate from expiration dates and rolling notices to a congressional choice about whether identity protection tied to the OPM breaches should be an enduring obligation. Similar bills over the years have not reached the finish line, leaving this measure’s prospects and the longer-term federal posture on lifetime protections as the immediate questions for lawmakers and affected individuals alike.




