Skip to main content

Cybersecurity: HHS Should Strengthen Oversight and Enhance Security Controls for the 988 Suicide and Crisis Lifeline

GAO-26-108836 Published: Sep 17, 2026. Publicly Released: Sep 17, 2026.
Jump To:

Fast Facts

The Department of Health and Human Services' 988 Suicide and Crisis Lifeline is critical to the health and safety of millions of Americans. In 2022, the Lifeline faced a cybersecurity attack that led to a nationwide service disruption for several hours.

The Lifeline is managed by a network administrator, who oversees its nearly 220 crisis contact centers. We found that the administrator and these centers haven't fully implemented cybersecurity controls that protect against service disruptions. HHS also hasn't fully implemented oversight of the Lifeline's cybersecurity.

We made 10 recommendations to strengthen the cybersecurity of the Lifeline.

A cellphone in a hand with the 988 Suicide and Crisis Lifeline number on top.

A cellphone in a hand with the 988 Suicide and Crisis Lifeline number on top.

Skip to Highlights

Highlights

What GAO Found

The 988 Suicide and Crisis Lifeline (988 Lifeline) is managed on behalf of the Department of Health and Human Services (HHS) by a network administrator who oversees the day-to-day operations and ensures that the nearly 220 local crisis contact centers are compliant with the organization’s cybersecurity requirements.

HHS partially implemented oversight activities related to cybersecurity for the 988 Lifeline. Specifically, HHS defined oversight roles and responsibilities to monitor cybersecurity control implementation. However, HHS did not include all key HHS-defined cybersecurity control areas in the 988 Lifeline cooperative agreement with its network administrator or for the network agreement between the administrator and crisis contact centers. In addition, HHS established processes to monitor security control implementation but did not always adhere to them.

Inclusion of Department of Health and Human Services (HHS)-defined Cybersecurity Control Areas in 988 Lifeline Agreements

Inclusion of Department of Health and Human Services (HHS)-defined Cybersecurity Control Areas in 988 Lifeline Agreements

While the network administrator and crisis contact centers fully implemented selected continuous monitoring controls, they have not consistently implemented other selected cybersecurity controls identified in guidance from the National Institute of Standards and Technology. Specifically, the network administrator has not implemented identity and access controls related to updated password guidance and partially implemented controls related to contingency plans. In addition, the crisis contacts centers have partially implemented incident response and contingency planning controls. Without the full implementation of these controls, the 988 Lifeline faces increased risk of cybersecurity incidents, which could result in prolonged service disruptions and potentially prevent individuals in crisis access to timely mental health support.

Why GAO Did This Study

HHS’s Substance Abuse and Mental Health Services Administration launched the National Suicide Prevention Lifeline in 2005 to serve individuals in suicidal crisis or emotional distress. In 2022, it was renamed the 988 Suicide and Crisis Lifeline. The uninterrupted operation of the 988 Lifeline is critical to the health and safety of millions of Americans. These services were severely impacted in December 2022 by a cybersecurity attack that compromised critical 988 network infrastructure, leading to a nationwide service disruption lasting several hours. In addition, Congress passed the SUPPORT for Patients and Communities Reauthorization Act of 2025 that, among other things, includes a provision for GAO to report on the 988 Lifeline cybersecurity risks and vulnerabilities.

The objectives for this report were to determine (1) to what extent HHS has provided oversight of cybersecurity controls for the 988 Lifeline and (2) to what extent the 988 Lifeline network administrator and crisis contact centers have implemented selected cybersecurity controls.

To do so, GAO assessed cooperative and network agreements and related cybersecurity documentation and compared them to best practices and selected National Institute of Standards and Technology controls. GAO also interviewed HHS officials, the network administrator, and selected crisis contact centers.

Recommendations

GAO is making 10 recommendations to HHS to update the cooperative and network agreements and to fully implement key cybersecurity controls. HHS concurred with the recommendations.

Recommendations for Executive Action

Agency Affected Recommendation Status
Department of Health and Human Services The Secretary of HHS should direct the Assistant Secretary for Mental Health and Substance Abuse to incorporate the seven missing cybersecurity control areas from HHS's CPG in the 988 Lifeline cooperative agreement. (Recommendation 1)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of HHS should direct the Assistant Secretary for Mental Health and Substance Abuse to work with the network administrator to incorporate the three missing cybersecurity control areas from HHS's CPG in the 988 Lifeline network administrator's network agreement with the crisis contact centers. (Recommendation 2)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of HHS should direct the Assistant Secretary for Mental Health and Substance Abuse to work with the network administrator to ensure full implementation of the 988 Lifeline network agreement compliance checklist process. (Recommendation 3)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of HHS should direct the Assistant Secretary for Mental Health and Substance Abuse to work with the network administrator to implement the current NIST password guidance. (Recommendation 4)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of HHS should direct the Assistant Secretary for Mental Health and Substance Abuse to work with the network administrator to establish requirements for crisis contact centers' development of incident response planning policies and monitor the implementation of such policies. (Recommendation 5)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of HHS should direct the Assistant Secretary for Mental Health and Substance Abuse to work with the network administrator to establish requirements for crisis contact centers' development of incident response plans and monitor the implementation of such plans. (Recommendation 6)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of HHS should direct the Assistant Secretary for Mental Health and Substance Abuse to work with the network administrator to establish requirements for crisis contact centers' development of incident response training and testing and monitor implementation of such training and testing. (Recommendation 7)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of HHS should direct the Assistant Secretary for Mental Health and Substance Abuse to work with the network administrator to establish requirements for crisis contact centers' development of contingency planning policies and monitor the implementation of such policies. (Recommendation 8)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of HHS should direct the Assistant Secretary for Mental Health and Substance Abuse to ensure that the network administrator includes key elements of a disaster recovery plan in the contingency plan. (Recommendation 9)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of HHS should direct the Assistant Secretary for Mental Health and Substance Abuse to work with the network administrator to establish requirements for crisis contact centers' development of contingency plan training and testing and monitor the implementation of such training and testing. (Recommendation 10)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.

Full Report

GAO Contacts

Media Inquiries

Sarah Kaczmarek
Managing Director
Office of Public Affairs

Public Inquiries

Topics

CrisisCybersecurityContingency plansCompliance oversightHealth care standardsInformation systemsAuthenticationHealth careSubstance abuseMental health