Skip to main content
Emerging ThreatsData Breaches

Lawmakers Push to Extend ID Theft Services for OPM Breach Victims

Blurred laptop screen on a table in a government-style hallway with people in the distance.

“Lifetime identity protection is the only solution that will give the workers whose data was compromised the peace of mind they deserve,” Del. Eleanor Holmes Norton said Monday, as lawmakers introduced a bill to make an expiring protection program permanent for victims of the 2015 Office of Personnel Management breach.

RECOVER PII Act: scope and key provisions

Sen. Mark Warner and Del. Eleanor Holmes Norton introduced the Reducing the Effects of the Cyberattack on OPM Victims Enduring Response and Protecting Identifiable Information Act, or RECOVER PII Act, to provide lifetime identity protection to those affected by the OPM compromise. The legislation would extend identity protection coverage indefinitely for roughly 4.2 million federal employees and contractors whose data was exposed in the 2015 breach, and it would also offer reimbursements for privacy services to federal employees and contractors.

Who was affected: the scale of the 2015 OPM breach

The 2015 Office of Personnel Management breach has long been characterized by its size and sensitivity: alleged Chinese hackers stole data that ultimately affected 22.1 million people, and about 4.2 million federal workers and contractors had their records specifically exposed. Warner said “the threat remains,” arguing that the persistence of risk justifies making protections permanent; Norton stressed that once sensitive personal information is in the hands of a bad actor, “you don’t get it back.”

Political landscape: sponsors, control of Congress, and prospects

The bill’s sponsors and immediate backers are Democrats. In the Senate, Warner is joined by co-sponsors Tim Kaine of Virginia and Angela Alsobrooks and Chris Van Hollen, both of Maryland. In the House, Democratic co-sponsors include Reps. Don Beyer and James Walkinshaw of Virginia and Steny Hoyer of Maryland. Warner and Norton listed no Republican co-sponsors. The source notes that Republicans control both chambers of Congress and the White House, a configuration the report says could make the bill’s path difficult.

OPM position and watchdog, consumer-advocate views

Despite the lawmakers’ push, the Office of Personnel Management has said the program is too expensive when judged by the ratio of cost to actual claims. The note of caution from OPM echoes earlier scrutiny: similar legislation, including prior bills introduced by Norton, has failed to pass in recent years. Consumer advocates cited in the report say identity-theft protections can be helpful but are not an adequate complete remedy by themselves.

What this means for federal employees, policymakers, and OPM

  • Federal employees and contractors: Those approximately 4.2 million people whose personal records were exposed would gain indefinite identity-protection coverage if the RECOVER PII Act becomes law; the bill would also allow for reimbursements for privacy services.
  • Policymakers: Democratic sponsors argue permanency is necessary because of lasting risk; however, the absence of Republican co-sponsors and the White House and congressional control cited in the report suggest a challenging legislative environment for passage before existing protections expire.
  • OPM and budget watchdogs: OPM’s current assessment — that the program is expensive relative to claims — frames the debate in fiscal terms as well as in protective policy terms, and similar prior efforts have not secured passage.

The existing identity-protection coverage for OPM breach victims was established by a 10-year authorization from Congress and is due to expire at the end of September. With that deadline approaching, Warner and Norton’s RECOVER PII Act tests whether the political will and fiscal judgment needed to convert a time-limited program into a permanent entitlement can be marshaled in a split-consequence environment: caregivers of the breached data pressing for perpetual safeguards, and administrators pointing to cost concerns and prior legislative failure.

Read the original CyberScoop report: https://cyberscoop.com/opm-breach-lifetime-identity-protection-bill/