HR-10034-119
Referred to the Committee on Oversight and Government Reform, and in addition to the Committees on House Administration, and the Judiciary, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
Sponsored by Eleanor Norton (D-DC)
What it does
This bill would make two changes related to federal agency data breaches. First, it would extend identity protection coverage — currently set to expire in 2026 — to last for the remainder of each affected individual's life, and would increase the minimum identity theft insurance from its current level to $5,000,000 per person. Second, it would allow federal agencies to use existing salary and expense appropriations to reimburse employees and certain contractors for the full cost of personal privacy-enhancing software or hardware tools that reduce risks from data processing.
Who benefits
Current and former federal employees and contractors whose personally identifiable information (PII) was exposed in federal agency data breaches — most notably the 2014-2015 Office of Personnel Management (OPM) breach, which affected an estimated 21.5 million individuals. Federal employees and contractors going forward who would receive reimbursement for privacy-enhancing tools. Cybersecurity and privacy software vendors who would gain a new government-backed customer base. Identity theft monitoring and insurance companies that would provide expanded coverage.
Who is hurt
Federal agencies whose discretionary salary and expense budgets would be drawn upon to fund reimbursements, potentially reducing funds available for other operational needs. Taxpayers who bear the cost of expanded and permanent coverage obligations. Contractors not directly supporting federal agencies, who would not qualify for reimbursements. Uninsured or private-sector workers affected by non-federal data breaches, who would receive no comparable benefit under this bill.
Supporters argue
Supporters argue that the federal government has a unique obligation to individuals whose most sensitive personal data — including background investigation records, fingerprints, and Social Security numbers — was exposed due to the government's own security failures. They contend that the OPM breach created a lifelong vulnerability for millions of people, making time-limited coverage inadequate, and that a $5,000,000 insurance floor reflects the long-term financial risk victims face from identity fraud enabled by deeply personal records.
Opponents argue
Opponents argue that making identity protection coverage permanent and raising the insurance threshold to $5,000,000 per person creates an open-ended, unfunded liability that could cost taxpayers billions over decades without a clear mechanism to control costs. They contend that the reimbursement provision for privacy-enhancing services is broadly written — covering all agencies across all three branches and all future fiscal years — and lacks sufficient oversight guardrails to prevent misuse of salary and expense funds for purposes unrelated to core agency missions.