S-5217-119
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Sponsored by Mark Warner (D-VA)
What it does
This bill would remove the 2026 expiration date on identity protection coverage required for individuals whose personal data was compromised in federal agency breaches (such as the 2015 OPM hack), making the coverage permanent and effective for the victim's lifetime rather than a limited term. It would also increase the required identity theft insurance minimum to $5,000,000 and let federal agencies use their existing salaries-and-expenses funds to reimburse employees or contractor staff for up to 100 percent of costs for privacy-enhancing technologies.
Who benefits
Individuals whose personal information was exposed in past federal data breaches, including the roughly 21 million people affected by the 2015 Office of Personnel Management hack, who would keep lifetime identity protection coverage instead of losing it in 2026. Federal employees and contractor staff who would become eligible for reimbursement of privacy-enhancing technology costs. Companies that sell identity theft monitoring, insurance, and privacy-enhancing technology products would gain a steady revenue stream from government contracts.
Who is hurt
Federal taxpayers who would bear the open-ended cost of lifetime coverage and higher insurance minimums rather than a time-limited benefit. Federal agencies would face new budgetary pressure on their salaries-and-expenses accounts to cover both breach-related identity protection and employee privacy-service reimbursements, potentially competing with other operational priorities.
Supporters argue
Supporters argue that victims of federal data breaches like the 2015 OPM hack face lifelong exposure to identity theft since stolen Social Security numbers and biometric data cannot be changed, so a coverage cutoff in 2026 leaves victims unprotected against harm that can surface decades later. They contend raising the insurance minimum to $5 million and letting agencies reimburse privacy-enhancing technology costs reflects the government's obligation to fully remedy harm it caused through inadequate cybersecurity.
Opponents argue
Opponents argue that converting a time-limited benefit into a permanent, lifetime entitlement removes any incentive for periodic reassessment of whether coverage remains necessary or cost-effective, and creates open-ended fiscal exposure without a sunset review. They contend that letting agencies fund employee privacy-service reimbursements from existing salaries-and-expenses accounts, without new appropriations, could divert money from core operations and lacks a documented cost estimate for how many employees would claim the benefit.