The national suicide and crisis line still has cybersecurity gaps to close, according to a federal audit of the 988 service.
Auditors faulted the hotline on two fronts: it had not adopted updated password and identity controls, and its cybersecurity contingency planning needs improvement. The report warns that, left as is, the service risks longer outages that could keep people in crisis from reaching help.
The concern rests on precedent. A 2022 ransomware attack interrupted 988 service for several hours. The line, built by the Substance Abuse and Mental Health Services Administration and the Mental Health Association of New York City, later grew into the nationwide three-digit number for suicide prevention, with nearly 220 local contact centers in a federated network. Demand keeps climbing: the accountability office counted 8 million contacts by call, text, or chat in 2025 alone.
Congress required the line to report cybersecurity incidents and vulnerabilities under the SUPPORT for Patients and Communities Reauthorization Act of 2025, which also prompted the review. Auditors credited HHS with some oversight actions but said more is needed.
The finding lands in a sector under sustained pressure. Behavioral health providers, crisis services, and clinical operations all sit inside the same target set that ransomware crews favor, which makes contingency planning a patient-safety control rather than a back-office task.