Lawmakers propose giving 2015 OPM breach victims identity protection for life

Sen. Mark Warner (D-VA) speaks at the confirmation hearing for Jay Clayton before the Senate Intelligence Committee during his nomination hearing on Capitol Hill July 15, 2026 in Washington, DC.

Sen. Mark Warner (D-VA) speaks at the confirmation hearing for Jay Clayton before the Senate Intelligence Committee during his nomination hearing on Capitol Hill July 15, 2026 in Washington, DC. Aaron Schwartz/Getty Images

The federal government’s coverage for 22.1 million people hoovered up in the China-linked breaches is scheduled to end Sept. 30.

Federal employees and contractors whose sensitive personal data was stolen in the massive Office of Personnel Management breaches disclosed a decade ago would receive identity protection for the rest of their lives under new bicameral legislation.

Senate Intelligence Committee Vice Chair Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., plan to introduce the RECOVER PII Act on Monday, aiming to prevent the federal government’s identity-protection program for victims from expiring Sept. 30, according to bill text first seen by Nextgov/FCW. Sens. Tim Kaine, D-Va.; Angela Alsobrooks, D-Md.; and Chris Van Hollen, D-Md., are also Senate cosponsors.

Just over 10 years after the OPM breaches compromised personal information belonging to roughly 22 million people, the identity-protection services provided to affected federal workers, contractors and their families have begun expiring. People who enrolled in OPM’s MyIDCare program are receiving notices that their complimentary coverage will end 10 years after their individual enrollment date. Some notices began arriving late last year and will continue through September, when OPM plans to conclude the services at the end of the federal fiscal year.

“More than ten years after the OPM data breach exposed the personal information of millions of federal employees, the threat remains,” Warner said in the statement. “The data stolen included workers’ most sensitive and personal information — from Social Security numbers to security clearance records — and once that information is in the hands of a bad actor, you don’t get it back.”

The two breaches compromised information belonging to some 22.1 million current, former and prospective federal employees, contractors and others. One intrusion exposed personnel records for roughly 4.2 million people, while a second compromised 21.5 million background-investigation records. About 3.6 million people were affected in both incidents, according to the Government Accountability Office.

Foreign intelligence services can hold onto these OPM records for years, combine them with information from other cyber intrusions and use the fuller picture to identify or target government personnel and their families.

Those risks can also grow over time. Data stolen from a lower-level employee in 2015 could become far more valuable if that person later moves into a more sensitive national security role. GAO warned last year that adversaries can combine publicly available data to identify military personnel and their families or disrupt Defense Department operations.

Congress responded to the breach in a 2017 appropriations law by requiring OPM to provide victims with at least 10 years of complimentary identity protection and no less than $5 million in identity-theft insurance. The new bill would replace that limit with coverage lasting for the remainder of each affected person’s life while retaining the insurance requirement.

“We have a responsibility to stand by the federal workers who were put at risk through no fault of their own,” Warner said. “This legislation will ensure those affected continue to receive the identity protection they need, while helping better safeguard personal information from future exploitation.”

The bill would also allow agencies to reimburse federal employees and contractors for privacy tools and services, such as those that remove or limit their personal information online. Agencies would decide whether to offer the reimbursements, which would not be limited to OPM breach victims and would come from their salary-and-expense budgets.

Norton has introduced legislation in the past seeking lifetime protection for OPM victims, beginning after the breaches were disclosed. Similar bills introduced over the years have not become law. 

“Lifetime identity protection is the only solution that will give the workers whose data was compromised the peace of mind they deserve,” Norton said in a statement. “Because there is no limit on how long personal information can be exploited, Congress must protect these federal employees and contractors in perpetuity. Thank you to Senator Warner for working with me to secure this vital protection for those affected.”