Two oversight channels left different gaps
How much assurance did the federal government have that the centers answering 988 crisis contacts had documented their cybersecurity safeguards? A comparison of two monitoring mechanisms in a September 17 federal audit shows missing information at both stages: a voluntary survey and a mandatory document checklist.
What’s the Scoop With Broach calculated that 72 of 218 crisis contact centers—33.0%—had not completed the network administrator’s optional cybersecurity survey as of March 2026. Separately, in the Government Accountability Office’s randomly selected sample of 12 compliance checklists, none showed all three required security documents submitted before the November 1, 2024 deadline. Seven centers submitted after the deadline; five still had incomplete submissions as of March 2026.
| Measure | Observed result | Scope and date |
|---|---|---|
| Optional cybersecurity survey | 146 completed; 72 missing | All 218 centers, March 2026 |
| Required checklist documents submitted on time | 0 of 12 | GAO checklist sample |
| Required documents submitted late | 7 of 12 | Same checklist sample |
| Required submissions still incomplete | 5 of 12 (41.7%) | Same sample, March 2026 |
A mandatory requirement did not ensure timely evidence
The checklist called for a business continuity analysis, a cybersecurity policy and an incident response policy. The five incomplete cases remained unresolved roughly 16 months after the deadline. That is a documentation and enforcement finding: it does not prove that those centers had no safeguards, or that a missing submission caused a service interruption.
The survey measured a different requirement and covered the full network. Because it was optional, a missing answer was not itself a violation of a mandatory survey rule. The administrator told GAO it planned to require completion in the next network-agreement revision. The two mechanisms cannot be merged into a single failure rate; the report does not establish their overlap center by center.
Independence of local centers complicates enforcement
HHS’s Substance Abuse and Mental Health Services Administration told GAO that the crisis centers are independent organizations, participation in the network agreement is voluntary, and responsibility for implementing safeguards primarily rests with the centers. Officials described removal from the network as their main recourse for noncompliance. That explains a limitation in enforcement authority, but it does not supply the missing records.
GAO also documented functioning protections. The network administrator and sampled centers fully implemented the selected continuous-monitoring control. The administrator fully implemented four selected incident-response controls. Those findings rule out a blanket claim that the Lifeline had no cybersecurity controls.
For its detailed control testing, GAO used a separate nongeneralizable sample of 10 centers. That group is not the 12-checklist sample, and this investigation does not project either sample’s percentages across all 218 centers. The distinction matters because the report combines several kinds of evidence under one oversight conclusion.
The response is agreement; completion remains unconfirmed
HHS concurred with GAO’s ten recommendations, including better agreements, full use of the checklist process, updated password guidance and stronger incident-response and contingency planning requirements. GAO’s public tracker listed all ten as open when checked October 3. An open recommendation means GAO has not confirmed completion; it does not establish that HHS has taken no action.
This original public-record analysis cross-checks the report’s monitoring findings against its sampling appendix and calculates the missing-survey and incomplete-checklist proportions. It establishes that two separate evidence channels failed to give complete, timely assurance. It does not identify a new outage or measure current service availability. The audit’s historical December 2022 cyberattack must not be confused with a present disruption. Interviews described in the source were conducted by GAO, not by Billy Roach or this publication.
Sources and further reading
GAO-26-108836, September 17, 2026; recommendations checked October 3 ↗
Full report, oversight findings and Appendix I methodology ↗
