
Millions of current and former federal employees across the Washington region are staring down a deadline: the identity theft protection they've relied on since the 2015 hacks of the U.S. Office of Personnel Management is set to expire on September 30, 2026. Lawmakers in both chambers of Congress have introduced legislation that would replace that temporary safeguard with lifetime coverage instead.
Sen. Mark Warner introduced Senate Bill 5217 on August 3, while Del. Eleanor Holmes Norton introduced companion legislation, House Resolution 10034, in the House, according to BillTrack50. The bill, formally called the Cyberattack on OPM Victims Enduring Response and Protecting Identifiable Information Act, or RECOVER PII Act, would swap out the current 10-year identity protection mandate for permanent, lifetime coverage. As Cleveland.com reports, the measure directly responds to two cyberattacks OPM identified in 2015 that compromised personal data belonging to roughly 22.1 million federal employees, contractors, and their family members.
Two Breaches, One Sweeping Data Loss
The first intrusion exposed personal records of about 4.2 million federal employees, including Social Security numbers, addresses, and financial details, per the same Cleveland.com report. The second, larger breach compromised background investigation records tied to roughly 21.5 million individuals, including security clearance files submitted through SF-86 forms — documents that ask applicants to disclose deeply personal information about themselves and their associates.
Those clearance files matter well beyond the initial breach. Intelligence officials warn that stolen SF-86 data lets foreign intelligence agencies cross-reference personnel records for decades to help identify undercover operatives, according to Federal News Network. Government Accountability Office data cited in that reporting puts the number of individuals affected by both OPM breaches at approximately 3.6 million. Separately, official OPM disclosures from September 2015 confirmed that hackers stole 5.6 million sets of biometric fingerprint records, a detail first reported by The Washington Post, which noted initial government estimates had put the figure at just 1.1 million. Unlike a stolen password or Social Security number, a fingerprint cannot be changed.
A Clock Already Running Out
The urgency behind the bill traces back to a very specific expiration date. Federal identity protection vendor IDX has been sending expiration notices to enrollees in the government's MyIDCare program since late 2025, warning that coverage terminates on a rolling basis 10 years after each person's enrollment, with all program funding lapsing entirely by September 30, 2026, according to My Federal Retirement. OPM has since transferred contract management for the program to the General Services Administration ahead of that expiration window.
That 10-year window and its $5 million insurance floor were established under the Consolidated Appropriations Act of 2017. Norton had previously introduced earlier bills attempting to make the coverage permanent before this year's push. The RECOVER PII Act would preserve that $5 million insurance floor for lifetime coverage and, starting in fiscal year 2026, would let federal agencies reimburse employees and contractors for up to 100% of the cost of online privacy software used to scrub personal data from data brokers, according to FedSmith.com.
“Lifetime identity protection is the only solution that will give the workers whose data was compromised the peace of mind they deserve,” Norton said, per Cleveland.com's reporting.
Why Northern Virginia and Maryland Feel It Most
The bill's local stakes are hard to overstate in the D.C. suburbs. Warner noted that victims of the 2015 OPM breaches are heavily concentrated in the Washington metropolitan area, including Northern Virginia and Maryland suburbs with dense populations of active and retired federal workers, according to InsideNoVa. Regional co-sponsors include Sen. Tim Kaine of Virginia and Sens. Chris Van Hollen and Angela Alsobrooks of Maryland.
A Settlement That Left Most Victims Empty-Handed
Congress isn't the only branch that has grappled with the fallout. In October 2022, U.S. District Judge Amy Berman Jackson granted final approval to a $63 million class-action settlement meant to compensate breach victims who suffered documented out-of-pocket financial harm or identity theft, according to FedScoop.
But court records filed in late 2024 showed OPM and the U.S. Treasury Department ultimately distributed only $4.7 million of that $63 million to roughly 5,000 approved claimants, with the remaining $58.2 million returned to the Treasury, according to reporting cited by Federal News Network. Strict proof-of-harm requirements meant only about 7% of the settlement money ever reached victims, leaving government-provided identity monitoring as the primary safeguard for the millions who never filed a successful claim.
Leadership Fallout That Followed the Hack
The 2015 breaches also reshaped OPM's leadership at the time. OPM Director Katherine Archuleta resigned in July 2015, followed by Chief Information Officer Donna Seymour in February 2016, amid severe congressional backlash over the agency's IT security failures, according to background compiled by Wikipedia. OPM, headquartered in the Theodore Roosevelt Federal Building near the National Mall, has remained under scrutiny in the years since — Hoodline previously reported on a plan to collect health claims data from insurers covering 8 million workers, an effort that also cited the 2015 breaches as a cautionary precedent.
For now, the RECOVER PII Act remains a proposal working its way through both chambers, with the September 30 expiration date looming over federal workers who have spent more than a decade living with the consequences of two breaches they had no role in causing.









