TechNewsReel
Live

Lawmakers Propose Lifetime Identity Protection for OPM Breach Victims

The RECOVER PII Act seeks to extend security coverage indefinitely for millions of federal employees and contractors affected by the 2015 data breach.

TechNewsReel Newsroom · August 4, 2026

Bipartisan legislators are introducing the RECOVER PII Act to provide lifetime identity theft protection to federal employees and contractors impacted by the 2015 Office of Personnel Management (OPM) data breaches. The move aims to secure a permanent safety net for government personnel whose most sensitive data remains vulnerable to exploitation.

Led by Sen. Mark Warner (D-VA) and Del. Eleanor Holmes Norton (D-D.C.), the proposed legislation would replace the existing 10-year limit on complimentary identity protection with lifetime coverage. The bill maintains a requirement for identity-theft insurance of at least $5 million. Additionally, the act would authorize agencies to reimburse employees and contractors for privacy tools and services designed to limit personal information online, a benefit extending to all eligible personnel regardless of whether they were victims of the OPM breach.

The Legacy of the 2015 Breach

The 2015 OPM breaches stand as one of the most severe compromises of government personnel data in U.S. history, affecting approximately 22.1 million people. The stolen data included Social Security numbers and highly sensitive security clearance records. In 2017, Congress passed an appropriations law requiring OPM to provide victims with at least 10 years of identity protection.

As that decade-long window closes, victims enrolled in the MyIDCare program have begun receiving notices that their coverage is ending. While the overall program is set to conclude at the end of the federal fiscal year on September 30, individual coverage expires exactly 10 years from each person's specific enrollment date.

Permanent Risks in a Digital Age

This legislative push acknowledges that the threat from stolen personally identifiable information (PII) does not expire. Because Social Security numbers cannot be changed, the risk of identity theft and espionage persists indefinitely. The stolen background investigation records are particularly valuable to foreign intelligence services, who can use them to target government personnel as they move into more sensitive national security roles over time.

"The data stolen included workers’ most sensitive and personal information — from Social Security numbers to security clearance records — and once that information is in the hands of a bad actor, you don’t get it back," Sen. Warner stated. Del. Norton emphasized the necessity of the extension, noting that because there is no limit on how long personal information can be exploited, Congress must protect these individuals in perpetuity.

Future Outlook

Supporters of the RECOVER PII Act argue that the government has a continuing obligation to those whose data was lost under its watch. The bill's success will depend on whether legislators view the 2015 breach as a closed chapter or a permanent liability. Observers will be watching to see if the act is integrated into upcoming appropriations or passed as standalone legislation before the current coverage windows fully lapse.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.