
If you were affected by the 2015 Office of Personnel Management data breaches, your free government-funded identity theft protection may already have ended or may be scheduled to expire soon. The coverage is ending on a rolling basis as participants reach 10 years from their enrollment dates, and the federally funded program is scheduled to end entirely no later than September 30, 2026.
A new bill in Congress would replace that temporary protection with lifetime coverage. Similar proposals have been introduced before without becoming law, but this effort arrives after some participants have already lost coverage and less than two months before the current program is scheduled to shut down.
What’s Actually Expiring, and When
The identity protection program tied to the 2015 breaches is administered through MyIDCare. Coverage is not ending for everyone on a single date. Instead, participants are receiving expiration notices as they reach 10 years from their individual enrollment dates.
Some notices began going out in late 2025, and expirations have continued during fiscal 2026. If you enrolled early, your government-funded coverage may already have ended. If you enrolled later, your individual expiration date may fall later in the fiscal year, but the program is scheduled to end no later than September 30, 2026.
Participants should review any notice they receive directly from MyIDCare for details on their specific enrollment date and what, if anything, is available once their government-funded coverage period ends.
How We Got Here
In 2015, OPM disclosed two major cyberattacks that U.S. officials and intelligence assessments have linked to actors associated with the Chinese government.
The first breach exposed personnel records for approximately 4.2 million current and former federal employees. The compromised information included names, birth dates, addresses and Social Security numbers. The second and larger breach exposed background-investigation records for approximately 21.5 million people. Those records included Social Security numbers, employment and residency histories, information about relatives and associates, and financial and health-related details. Approximately 5.6 million sets of fingerprints were also compromised.
Because federal background investigations collect information about spouses, relatives, roommates and other associates, the approximately 22.1 million people affected by the two breaches were not limited to federal employees and contractors. The total included many people who had never applied for a federal position or security clearance themselves. The fallout led to leadership changes and continuing congressional scrutiny. OPM Director Katherine Archuleta resigned in July 2015, and Chief Information Officer Donna Seymour resigned the following February.
Congress later required OPM to provide affected individuals with at least 10 years of identity monitoring and other protective services, along with a statutory identity theft insurance floor of at least $5 million. Those requirements were included in the Consolidated Appropriations Act, 2017. That government-funded protection is now expiring.
This Isn’t the First Attempt to Make It Permanent
Congresswoman Eleanor Holmes Norton has introduced legislation seeking lifetime identity protection for OPM breach victims multiple times since the breaches, including a version in the previous Congress. Earlier proposals did not advance far enough to become law. The basic argument has remained consistent: stolen Social Security numbers, fingerprint records and background-investigation information do not lose their value to criminals or foreign intelligence services simply because 10 years have passed.
This attempt arrives under more immediate pressure. Some participants have already lost their government-funded coverage, and the remaining program is scheduled to end entirely on September 30, 2026. Whether that deadline produces broader support remains uncertain.
What the RECOVER PII Act Would Do
The legislation was introduced in the Senate as S. 5217 by Senator Mark Warner of Virginia and in the House as H.R. 10034 by Congresswoman Norton. As of August 5, 2026, Senate cosponsors include Tim Kaine of Virginia, Angela Alsobrooks of Maryland and Chris Van Hollen of Maryland. The House bill also has Democratic cosponsors. At that point, all listed sponsors and cosponsors of the House and Senate bills were Democrats.
As written, the legislation would:
- Convert the protection to lifetime coverage. Instead of ending after 10 years, qualifying identity protection services would continue for the remainder of each affected person’s life.
- Preserve at least $5 million in identity theft insurance. The bill would retain the existing statutory insurance floor while extending the duration of the protection.
- Authorize reimbursement for certain privacy services. Agencies would be permitted, but not required, to reimburse employees and qualifying contractor employees for services designed to reduce the public availability of their personal information, including some data-removal or data-broker privacy services.
The reimbursement provision would not be limited to confirmed OPM breach victims, and it would not create a separate, dedicated fund. Instead, it would allow agencies to draw on their existing salary-and-expense budgets to cover qualifying reimbursements, at each agency’s discretion.
Why Lawmakers Say the Risk Hasn’t Faded
In announcing the legislation, its sponsors pointed to Government Accountability Office findings that foreign adversaries are increasingly able to piece together scattered public and commercially available data sources to identify military personnel and their families, or to interfere with Defense Department operations. The same kind of data-aggregation risk applies to the civilian federal workforce whose OPM records remain in circulation.
The lawmakers also cited the 2025 attacks on Minnesota elected officials, in which the alleged gunman reportedly used people-search or data-broker information to locate potential targets. Their argument is that exposed personal information can create risks that extend beyond financial fraud and identity theft.
There is also a long-term national security concern. Someone who held a junior position when the OPM breach occurred may now occupy a more sensitive role. Information stolen a decade ago may become more useful to a foreign intelligence service as that person’s responsibilities, access and professional relationships expand.
What This Means for You
A few practical points apply regardless of whether the legislation advances:
- Check your own expiration notice. Your individual coverage date depends on when you enrolled, although the government-funded program is scheduled to end no later than September 30, 2026. Review notices from MyIDCare rather than assuming you are covered through the end of September.
- Do not assume the bill will become law. Similar legislation has failed to pass in earlier Congresses, and the current bills had only Democratic sponsors and cosponsors as of August 5, 2026.
- Consider freezing your credit. Credit freezes are free and generally must be placed separately with Equifax, Experian and TransUnion. The Federal Trade Commission explains how credit freezes and fraud alerts work.
- Continue monitoring financial and government accounts. Watch for unfamiliar credit activity, tax filings, benefit claims, account changes or authentication attempts involving your personal information.
What To Watch
The key question is whether the approaching September 30 deadline will generate enough support for the legislation to advance. Previous versions did not become law, and the current bills had not attracted bipartisan sponsorship as of August 5, 2026.
Readers can follow the official legislative records here:

