{"check":null,"uid":"e515b4b691e031c8","title":"SUPPORT for Patients and Communities Reauthorization Act of 2025","title_generated":false,"country":"США","organ":"Конгресс США","kind":"law","kind_name":"Законодательство","lang":"en","date":"2026-06-23","summary":"Закон обязывает Администрацию по вопросам злоупотребления психоактивными веществами и психического здоровья защищать линию помощи 9-8-8 от киберугроз. Администратор сети должен сообщать в SAMHSA о выявленных инцидентах и уязвимостях, а местные кризисные центры — администратору сети; срок уведомления составляет 24 часа с соблюдением требований конфиденциальности. GAO проводит оценку рисков и уязвимостей линии и докладывает Конгрессу. Требования дополняют существующие нормы отчётности.","snippet":"","topics":["Кибербезопасность"],"status":"ok","error":"","text_len":5845,"versions":1,"url":"https://www.congress.gov/bill/119-congress/s/1007","first_seen":"2026-09-08","last_checked":"2026-09-17 01:59","relevance":"hit","score":21,"query":"","source_key":"congress_us","verdict":{"relevance":"hit","score":21,"topics":["Кибербезопасность"],"need_body":3,"authorities":[],"evidence":[{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":23,"ctx":"summary 9-8-8 lifeline cybersecurity responsibility act this bill requires the substance abuse and mental health services admi","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":219,"ctx":"tration (samhsa) to undertake efforts to protect the 9-8-8 suicide & crisis lifeline from cybersecurity threats. (the lifeline is a three-digit number that connects callers in suicidal crisis o","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":527,"ctx":"irements. specifically, the network administrator for the lifeline must report identified cybersecurity incidents and vulnerabilities to samhsa, and local and regional crisis centers that parti","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":676,"ctx":"local and regional crisis centers that participate in the lifeline must report identified cybersecurity incidents and vulnerabilities to the network administrator. additionally, the government","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":837,"ctx":"r. additionally, the government accountability office must conduct a study that evaluates cybersecurity risks and vulnerabilities associated with the lifeline and report the findings to congres","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":1213,"ctx":"d title v of the public health service act to secure the suicide prevention lifeline from cybersecurity incidents, and for other purposes.  _____________________________________________________","zone":"текст","weight":1}],"dropped":[{"topic":"Персональные данные","term":"privacy","weak":true,"pos":3117,"ctx":"ubsection (a) shall report to the assistant secretary, in a manner that protects personal privacy, consistent with applicable federal and state privacy laws-- ``(i) any identified cyberse","why":"только многозначные термины"},{"topic":"Персональные данные","term":"privacy","weak":true,"pos":3171,"ctx":"in a manner that protects personal privacy, consistent with applicable federal and state privacy laws-- ``(i) any identified cybersecurity vulnerabilities to the program within 24 hours","why":"только многозначные термины"},{"topic":"Персональные данные","term":"privacy","weak":true,"pos":3651,"ctx":"s network administrator described in subparagraph (a), in a manner that protects personal privacy, consistent with applicable federal and state privacy laws-- ``(i) any identified cyberse","why":"только многозначные термины"},{"topic":"Персональные данные","term":"privacy","weak":true,"pos":3705,"ctx":"in a manner that protects personal privacy, consistent with applicable federal and state privacy laws-- ``(i) any identified cybersecurity vulnerabilities to the program within 24 hours","why":"только многозначные термины"}]},"last_changed":"2026-09-11","meta":{"congress":"119","billType":"S","number":"1007","policyArea":"Health","subjects":["Computer security and identity theft","Congressional oversight","Emergency communications systems","Government information and archives","Government studies and investigations","Mental health"],"latestAction":"2025-12-01 Became Public Law No: 119-44.","textVersion":"is"},"source_url":"https://www.congress.gov/bill/119-congress/s/1007","text":"SUMMARY\n9-8-8 Lifeline Cybersecurity Responsibility Act\nThis bill requires the Substance Abuse and Mental Health Services Administration (SAMHSA) to undertake efforts to protect the 9-8-8 Suicide & Crisis Lifeline from cybersecurity threats. (The lifeline is a three-digit number that connects callers in suicidal crisis or mental health distress to a national network of crisis centers.)\nThe bill also establishes related reporting requirements. Specifically, the network administrator for the lifeline must report identified cybersecurity incidents and vulnerabilities to SAMHSA, and local and regional crisis centers that participate in the lifeline must report identified cybersecurity incidents and vulnerabilities to the network administrator.\nAdditionally, the Government Accountability Office must conduct a study that evaluates cybersecurity risks and vulnerabilities associated with the lifeline and report the findings to Congress.\n\nFULL TEXT\n[Congressional Bills 119th Congress]\n[From the U.S. Government Publishing Office]\n[S. 1007 Introduced in Senate (IS)]\n\n<DOC>\n\n119th CONGRESS\n1st Session\nS. 1007\n\nTo amend title V of the Public Health Service Act to secure the suicide\nprevention lifeline from cybersecurity incidents, and for other\npurposes.\n\n_______________________________________________________________________\n\nIN THE SENATE OF THE UNITED STATES\n\nMarch 12, 2025\n\nMr. Mullin (for himself and Mr. Padilla) introduced the following bill;\nwhich was read twice and referred to the Committee on Health,\nEducation, Labor, and Pensions\n\n_______________________________________________________________________\n\nA BILL\n\nTo amend title V of the Public Health Service Act to secure the suicide\nprevention lifeline from cybersecurity incidents, and for other\npurposes.\n\nBe it enacted by the Senate and House of Representatives of the\nUnited States of America in Congress assembled,\n\nSECTION 1. SHORT TITLE.\n\nThis Act may be cited as the ``9-8-8 Lifeline Cybersecurity\nResponsibility Act''.\n\nSEC. 2. PROTECTING SUICIDE PREVENTION LIFELINE FROM CYBERSECURITY\nINCIDENTS.\n\n(a) National Suicide Prevention Lifeline Program.--Section 520E-\n3(b) of the Public Health Service Act (42 U.S.C. 290bb-36c(b)) is\namended--\n(1) in paragraph (4), by striking ``and'' at the end;\n(2) in paragraph (5), by striking the period at the end and\ninserting ``; and''; and\n(3) by adding at the end the following:\n``(6) coordinating with the Chief Information Security\nOfficer of the Department of Health and Human Services to take\nsuch steps as may be necessary to ensure the program is\nprotected from cybersecurity incidents and eliminates known\ncybersecurity vulnerabilities.''.\n(b) Reporting.--Section 520E-3 of the Public Health Service Act (42\nU.S.C. 290bb-36c) is amended--\n(1) by redesignating subsection (f) as subsection (g); and\n(2) by inserting after subsection (e) the following:\n``(f) Cybersecurity Reporting.--\n``(1) In general.--\n``(A) In general.--The program's network\nadministrator receiving Federal funding pursuant to\nsubsection (a) shall report to the Assistant Secretary,\nin a manner that protects personal privacy, consistent\nwith applicable Federal and State privacy laws--\n``(i) any identified cybersecurity\nvulnerabilities to the program within 24 hours\nof identification of such a vulnerability; and\n``(ii) any identified cybersecurity\nincidents to the program within 24 hours of\nidentification of such incident.\n``(B) Local and regional crisis centers.--Local and\nregional crisis centers participating in the program\nshall report to the program's network administrator\ndescribed in subparagraph (A), in a manner that\nprotects personal privacy, consistent with applicable\nFederal and State privacy laws--\n``(i) any identified cybersecurity\nvulnerabilities to the program within 24 hours\nof identification of such vulnerability; and\n``(ii) any identified cybersecurity\nincidents to the program within 24 hours of\nidentification of such incident.\n``(2) Notification.--If the program's network administrator\nreceiving funding pursuant to subsection (a) discovers, or is\ninformed by a local or regional crisis center pursuant to\nparagraph (1)(B) of, a cybersecurity vulnerability or incident\ndescribed in such paragraph, within 24 hours of such discovery\nor receipt of information, such entity shall report the\nvulnerability or incident to the Assistant Secretary.\n``(3) Clarification.--\n``(A) Oversight.--\n``(i) Local and regional crisis center.--\nExcept as provided in clause (ii), local and\nregional crisis centers participating in the\nprogram shall oversee all technology each\ncenter employs in the provision of services as\na participant in the program.\n``(ii) Network administrator.-- The\nprogram's network administrator receiving\nFederal funding pursuant to subsection (a)\nshall oversee the technology each crisis center\nemploys in the provision of services as a\nparticipant in the program if such oversight\nresponsibilities are established in the\napplicable network participation agreement.\n``(B) Supplement, not supplant.--The cybersecurity\nincident reporting requirements under this subsection\nshall supplement, and not supplant, cybersecurity\nincident reporting requirements under other provisions\nof applicable Federal law that are in effect on the\ndate of the enactment of the 9-8-8 Lifeline\nCybersecurity Responsibility Act.''.\n(c) Study.--Not later than 180 days after the date of the enactment\nof this Act, the Comptroller General of the United States shall--\n(1) conduct and complete a study that evaluates\ncybersecurity risks and vulnerabilities associated with the 9-\n8-8 National Suicide Prevention Lifeline; and\n(2) submit a report of the findings of such study to the\nCommittee on Energy and Commerce of the House of\nRepresentatives and the Committee on Health, Education, Labor,\nand Pensions of the Senate.\n<all>","changes":[],"passport":{"data":{"act":{"jurisdiction":"США","title_official":"SUPPORT for Patients and Communities Reauthorization Act of 2025","title_short":"","level":"Закон","date_adopted":"2025-03-12","date_in_force":"","date_version":"","phased":"","status":"Действует","sunset":"","regulator":"Substance Abuse and Mental Health Services Administration (SAMHSA)","related":""},"goal":{"problem":"Обеспечение безопасности национальной службы предотвращения самоубийств от киберугроз.","goal":"Защита службы от кибератак и обеспечение отчетности о выявленных инцидентах и уязвимостях.","targets":"","scope":"Национальная служба предотвращения самоубийств.","exclusions":""},"subjects_note":{"protected":"Потребители услуг службы предотвращения самоубийств."},"subjects":[{"role":"Программа национального суицидального телефонного номера, операторы кризисных центров, администратор сети программы.","who":"Программа национального суицидального телефонного номера, местные и региональные центры оказания кризисной помощи.","criteria":"Получение федерального финансирования.","count":"нет данных"}],"norms":[{"address":"SEC. 2.(b)","addressee":"Программа национального суицидального телефонного номера","essence":"В течение 24 часов после выявления сообщать администрации программы о выявленных киберугрозах и инцидентах.","type":"Обязанность","mechanism":"Информирование","cost_channel":"Содержательный","cost_kind":"Регулярные","trigger":"Выявление угрозы или инцидента","sanction":"Требует проверки","refs":"","form":"","in_force":"","ru_analog":""}]},"made_by":"GigaChat-2","made_at":"2026-09-16 07:24:59","edited_at":null,"edited_by":null}}