Protecting Suicide Prevention Lifeline from Cybersecurity Incidents
Section 108 · Sec. 108 ·
What this chapter is about
This part changes an older law about the suicide help line. It says the line must be kept safe from computer attacks. It says who must report a problem, and to whom. It also orders a study of the risks.
The document says “is amended”Who acts: CongressHow: statuteSec. 108 in the PDF
What the document says
“taking such steps as may be necessary to ensure the suicide prevention hotline is protected from cybersecurity incidents and eliminates known cybersecurity vulnerabilities.”
The section adds paragraph (6) to section 520E-3(b) of the Public Health Service Act. The added paragraph names protecting the hotline from cybersecurity incidents, and closing known vulnerabilities, among the things the program covers.
What the document actually says
“taking such steps as may be necessary to ensure the suicide prevention hotline is protected from cybersecurity incidents and eliminates known cybersecurity vulnerabilities.”
That sentence, in plain words
Steps must be taken to keep the help line safe. It must be safe from computer attacks. Known weak spots must be closed.
What this is about
The help line is reached by dialing 9-8-8. People call it when they are in crisis. It runs on computers and phone lines like any other service.
No action is recorded against this proposal. That is not evidence that none has been taken, and nobody has yet read it against the record. See what the tracker does not yet cover.
The document says “shall”Who acts: the program's network administratorHow: statuteSec. 108 in the PDF
What the document says
“The program's network administrator receiving Federal funding pursuant to subsection (a) shall report to the Assistant Secretary, in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws--”
The section adds subsection (f) to section 520E-3 of the Public Health Service Act. The new subsection requires the network administrator to report identified cybersecurity vulnerabilities and incidents to the Assistant Secretary within a reasonable amount of time, in a way that protects personal privacy.
What the document actually says
“The program's network administrator receiving Federal funding pursuant to subsection (a) shall report to the Assistant Secretary, in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws--”
That sentence, in plain words
The group that runs the network must report trouble. It reports to a senior official. It must guard people's private facts when it does.
What this is about
There are two kinds of trouble to report. A weak spot is a hole nobody has used yet. An incident is an attack that has already happened.
No action is recorded against this proposal. That is not evidence that none has been taken, and nobody has yet read it against the record. See what the tracker does not yet cover.
The document says “shall”Who acts: local and regional crisis centersHow: statuteSec. 108 in the PDF
What the document says
“Local and regional crisis centers participating in the program shall report to the program's network administrator identified under subparagraph (A), in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws--”
The same new subsection requires local and regional crisis centers taking part in the program to report identified cybersecurity vulnerabilities and incidents to the network administrator. Under paragraph (2), the administrator must then pass what it learns to the Assistant Secretary.
What the document actually says
“Local and regional crisis centers participating in the program shall report to the program's network administrator identified under subparagraph (A), in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws--”
That sentence, in plain words
Local centers must report trouble too. They report to the group that runs the network. They must guard private facts when they do.
What this is about
Calls to the help line are answered by centers around the country. Each is its own group. Word of a problem travels from the center up to the network, then up to the government.
No action is recorded against this proposal. That is not evidence that none has been taken, and nobody has yet read it against the record. See what the tracker does not yet cover.
The document says “shall”Who acts: local and regional crisis centersHow: statuteSec. 108 in the PDF
What the document says
“local and regional crisis centers participating in the program shall oversee all technology each center employs in the provision of services as a participant in the program.”
The section places oversight of each center's technology on the center itself, except where the network participation agreement gives that responsibility to the network administrator. Where it does, the administrator oversees the technology the center uses.
What the document actually says
“local and regional crisis centers participating in the program shall oversee all technology each center employs in the provision of services as a participant in the program.”
That sentence, in plain words
Each local center watches over its own computers and tools. That is the rule unless the deal it signed says otherwise.
What this is about
The centers sign an agreement to join the network. That agreement can shift the job of watching over the tools. If it does, the network does the watching instead.
No action is recorded against this proposal. That is not evidence that none has been taken, and nobody has yet read it against the record. See what the tracker does not yet cover.
“The cybersecurity incident reporting requirements under this subsection shall supplement, and not supplant, cybersecurity incident reporting requirements under other provisions of applicable Federal law that are in effect on the date of the enactment of the SUPPORT for Patients and Communities Reauthorization Act of 2025.”
The new subsection states that its reporting requirements add to, rather than replace, cybersecurity incident reporting requirements under other Federal law in effect on the date this Act was enacted.
What the document actually says
“The cybersecurity incident reporting requirements under this subsection shall supplement, and not supplant, cybersecurity incident reporting requirements under other provisions of applicable Federal law that are in effect on the date of the enactment of the SUPPORT for Patients and Communities Reauthorization Act of 2025.”
That sentence, in plain words
These new reports do not take the place of old ones. They are added on top. Other federal rules still apply.
What this is about
More than one federal law can ask for a report on the same attack. This line settles that the new duty does not cancel the others.
No action is recorded against this proposal. That is not evidence that none has been taken, and nobody has yet read it against the record. See what the tracker does not yet cover.
The document says “shall”Who acts: Comptroller General of the United StatesHow: statuteSec. 108 in the PDF
What the document says
“Not later than 180 days after the date of the enactment of this Act, the Comptroller General of the United States shall--”
The section directs the Comptroller General to complete, within 180 days of enactment, a study evaluating cybersecurity risks and vulnerabilities associated with the 9-8-8 National Suicide Prevention Lifeline, and to report the findings to the Senate health committee and the House Energy and Commerce Committee.
What the document actually says
“Not later than 180 days after the date of the enactment of this Act, the Comptroller General of the United States shall--”
That sentence, in plain words
A government watchdog must do a study. It is due within 180 days. The study looks at risks to the 9-8-8 line.
What this is about
The Comptroller General leads a watchdog office. That office checks how federal money is spent. What it finds goes to Congress.
No action is recorded against this proposal. That is not evidence that none has been taken, and nobody has yet read it against the record. See what the tracker does not yet cover.
Reauthorize certain programs that provide for opioid use disorder prevention, treatment, and recovery, Public Law 119-44, sec. 108, 139 Stat. 675 (2025). https://www.govinfo.gov/content/pkg/PLAW-119publ44/html/PLAW-119publ44.htm
This page
“Protecting Suicide Prevention Lifeline from Cybersecurity Incidents,” Reauthorize certain programs that provide for opioid use disorder prevention, treatment, and recovery, section 108. Read the Mandate, https://readthemandate.org/pl-119-44/section-108/ (retrieved August 26, 2026).
Cite the document when the claim is about what the document says. Cite this page when the indexing, the wording or the record of what has happened is what is being relied on.
What This Page Covers, and What It Leaves Out
Each distinct duty the section creates: the duty to protect the hotline, the reporting duty on the network administrator, the reporting duty on crisis centers, the split of oversight over technology, the rule that these duties add to rather than replace others, and the study by the Comptroller General.
Purely mechanical amendments. Striking an and at the end of a paragraph, changing a period to a semicolon, and redesignating subsection (f) as subsection (g) are bookkeeping and are not recorded as separate items.
The section works by amending section 520E-3 of the Public Health Service Act, which is not indexed here, so nothing is recorded about what the rest of that section requires or what the program looked like before this law.