Skip to content
Hugin
A dark desk telephone lying on a bare wooden table in cold light, its coiled cord trailing away, the keypad blank.

Hugin News

The 988 crisis line went dark for hours after a 2022 cyberattack. Four years later, GAO found seven of HHS's own required security control areas were never written into the agreement that runs it.

3 min read

Original editorial artwork generated for Hugin.

GAO's September 17 report on the 988 Suicide and Crisis Lifeline — the number roughly 220 local crisis contact centers answer — finds the cybersecurity controls protecting it only partly in place. HHS defined oversight roles but 'did not include all key HHS-defined cybersecurity control areas' in its cooperative agreement with the network administrator, nor in the administrator's agreement with the crisis centers: seven missing control areas in the first, three in the second. The network administrator has not implemented current NIST password guidance and only partly implemented contingency-plan controls; the crisis centers have only partly implemented incident response and contingency planning. GAO's stated risk is specific: prolonged service disruption 'could... potentially prevent individuals in crisis access to timely mental health support.' Congress ordered this review in the SUPPORT for Patients and Communities Reauthorization Act of 2025. Ten recommendations, all open; HHS concurred with all of them.

gaohhs988cybersecuritymental-healthoversight
2source receipts2source hosts3 minread timelinkedprimary source

If you call 988, the call goes to one of roughly 220 local crisis contact centers. The network that routes it is run, on HHS's behalf, by a network administrator. In December 2022 that network was attacked.

GAO's description of what happened is one sentence long and worth reading slowly:

These services were severely impacted in December 2022 by a cybersecurity attack that compromised critical 988 network infrastructure, leading to a nationwide service disruption lasting several hours.

Congress asked for this report. The SUPPORT for Patients and Communities Reauthorization Act of 2025 "includes a provision for GAO to report on the 988 Lifeline cybersecurity risks and vulnerabilities."

What GAO found in the paperwork

The first finding is not about a firewall. It is about a contract.

HHS has its own list of cybersecurity control areas — its Cybersecurity Performance Goals. GAO found that HHS "did not include all key HHS-defined cybersecurity control areas in the 988 Lifeline cooperative agreement with its network administrator or for the network agreement between the administrator and crisis contact centers."

How many were missing is in the recommendations themselves: seven control areas absent from the cooperative agreement with the network administrator, and three absent from the network agreement between the administrator and the crisis centers.

A control area that is not in the agreement is not a requirement anybody can be held to. That is the whole point of writing it down.

GAO also found the monitoring itself uneven: HHS "established processes to monitor security control implementation but did not always adhere to them."

What GAO found in the systems

Against selected NIST controls:

While the network administrator and crisis contact centers fully implemented selected continuous monitoring controls, they have not consistently implemented other selected cybersecurity controls identified in guidance from the National Institute of Standards and Technology.

Specifically, per GAO: the network administrator "has not implemented identity and access controls related to updated password guidance and partially implemented controls related to contingency plans." The crisis contact centers "have partially implemented incident response and contingency planning controls."

Contingency planning is the plan for what happens when the thing goes down. Incident response is what you do while it is down. Those are the two controls that decide how long "several hours" is next time.

The risk, stated plainly

GAO does not leave the consequence abstract:

Without the full implementation of these controls, the 988 Lifeline faces increased risk of cybersecurity incidents, which could result in prolonged service disruptions and potentially prevent individuals in crisis access to timely mental health support.

Ten recommendations, and an agency that agreed

"GAO is making 10 recommendations to HHS to update the cooperative and network agreements and to fully implement key cybersecurity controls. HHS concurred with the recommendations."

Concurrence is not implementation, and GAO records the difference: every one of the ten carries the status Open, each with the same line — "When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information."

The first two are the contractual ones: incorporate the seven missing control areas into the cooperative agreement, and work with the network administrator to incorporate the three missing areas into its agreement with the crisis centers. Those two cost nothing but drafting, and until they are done the rest are requests rather than requirements.

This desk has added the ten to its open-requests board, where the count runs from the day they were made.

If you or someone you know is in crisis, 988 answers by call or text. The finding above is about how well the network behind that number is defended, not about whether it works.

Source links