Last Updated: August 19, 2026 Reading Time: 7 min

The identity-protection coverage that 22.1 million OPM breach victims have had since 2015 expires September 30, 2026. A bill introduced this month, the RECOVER PII Act, would make that coverage permanent, for life. Most coverage of the bill stops at the headline. The bill text does something narrower than 'lifetime coverage' suggests, it contains a second provision with a much bigger reach, and its odds of passing in the 41 days left deserve an honest read rather than a hopeful one.

What the Bill Actually Changes

The RECOVER PII Act targets one sentence of existing law. The current coverage exists because of Section 633(a) of the Consolidated Appropriations Act, 2017, which required OPM to provide breach victims "complimentary identity protection coverage" through fiscal year 2026. The RECOVER PII Act does one surgical thing: it strikes that sunset and substitutes coverage "effective for the remainder of the life of the affected individual."

Note what it does not do:

  • It does not name or extend the IDX contract. The current vendor's contract concludes on schedule. Read the bill text yourself at Congress.gov; it is short.
  • It does not appropriate new money by itself.
  • If enacted, OPM would have to run a new procurement to deliver the lifetime coverage.

That distinction matters for timing, and it is the part of the RECOVER PII Act most coverage gets wrong. Even in the best case, a gap between the September 30 contract end and any new coverage is plausible.

Who's Behind It (and Why That Predicts Its Odds)

  • Senate: Mark Warner (D-VA), with Tim Kaine (D-VA), Angela Alsobrooks (D-MD), and Chris Van Hollen (D-MD). Referred to Homeland Security and Governmental Affairs.
  • House: Eleanor Holmes Norton (D-DC), with Don Beyer (D-VA), James Walkinshaw (D-VA), and Steny Hoyer (D-MD). Referred to three committees.

All eight are Democrats from the DC-Maryland-Virginia federal workforce corridor. No Republican has signed on. Norton has introduced versions of lifetime breach coverage since 2015 without one reaching a floor vote. With no markup scheduled and Congress consumed by the FY2027 funding fight, the standalone path is effectively closed before September 30.

The realistic vehicle is a rider on the continuing resolution Congress must pass by October 1. That requires Republican leadership assent, and as of mid-August there's no public signal of it. We track the CR itself in our government shutdown tracker.

The Provision Nobody's Covering: Privacy Tools for All 2.3 Million Feds

Buried in the RECOVER PII Act is a second authority that has received almost no press attention: any federal agency could reimburse its employees and contractors, up to 100%, for "privacy-enhancing services." Think data-broker removal subscriptions, the tools that scrub your home address and phone number from people-search sites.

Two things make this bigger than the headline provision:

  1. It covers everyone. Every current federal employee and contractor would be eligible if their agency opts in, whether or not they were in the 2015 breach population.
  2. It uses existing agency budgets, so it doesn't need a new appropriation.

For a workforce that's faced doxxing concerns from years of workforce turmoil, an agency-funded data-broker removal benefit would be a genuinely new category of federal benefit. If the bill stalls, watch for this provision to resurface in the NDAA or an appropriations package; it's the kind of low-cost item that survives when headline provisions die.

The Number to Get Right: 22.1 Million, Not 26 Million

Some coverage says 26 million people are covered. The correct figure is 22.1 million unique individuals: 21.5 million from the background-investigation breach and 4.2 million from the personnel-file breach, minus the 3.6 million hit by both. If you're citing this story, or explaining it to a coworker, use 22.1 million.

Coverage also extends beyond employees: applicants who underwent background investigations, contractors, and in many cases spouses and cohabitants named on SF-86 forms are covered individuals.

What to Do Before September 30 (Bill or No Bill)

The practical checklist doesn't depend on Congress:

  1. Log into your coverage account now and download any monitoring alerts, resolution case records, and credit reports stored there. Access ends when the contract does.
  2. Freeze your credit at all three bureaus if you haven't. It's free, permanent until you lift it, and replaces the single most valuable thing the paid coverage did.
  3. Set calendar reminders to pull your free weekly credit reports through AnnualCreditReport.com.
  4. Watch for official OPM communication about any transition or replacement coverage. Treat unsolicited "coverage transfer" emails as phishing; the breach population is a prime phishing target this fall.

One more step worth 15 minutes: inventory what the coverage actually did for you. If you have used the identity-restoration service, there may be open case files worth exporting. If you never logged in at all, you are in the majority, and the credit freeze plus free weekly reports will replace most of what you were getting. The paid layer you genuinely lose is the up-to-$5-million identity-theft insurance and the managed restoration service; no free substitute exists for those, which is exactly the gap the RECOVER PII Act argues should not reopen for people whose SF-86 files, fingerprints, and family details are permanently in hostile hands.

Our companion guide to the September 30 expiration walks through the full replacement checklist step by step.

Frequently Asked Questions

What is the RECOVER PII Act?

S. 5217 and H.R. 10034, introduced August 3, 2026, would amend the 2017 appropriations law to make identity-protection coverage for 2015 OPM breach victims last for life instead of expiring at the end of fiscal year 2026.

Who is covered by the current OPM breach identity protection?

About 22.1 million unique individuals affected by the 2015 OPM breaches, including employees, applicants, contractors, and family members whose SF-86 data was exposed. The 26 million figure sometimes cited double-counts people hit by both breaches.

When does OPM breach identity protection expire?

September 30, 2026. OPM's FY2027 budget justification states the program concludes in September 2026 and requests no funding beyond it.

Will the RECOVER PII Act pass before the deadline?

The realistic odds are low. All eight sponsors are Democrats from Virginia, Maryland, and DC, no markup is scheduled, and similar bills have been introduced since 2015 without success. The only fast path is a rider on a continuing resolution.

What is the agency reimbursement provision in the bill?

A little-noticed section would let any federal agency reimburse employees and contractors up to 100% of the cost of privacy-enhancing services like data-broker removal tools, paid from existing agency budgets. It covers the whole federal workforce, not just breach victims.

Sources: Congress.gov (H.R. 10034, S. 5217); OPM FY2027 Congressional Budget Justification, Revolving Fund Activities; GovExec, Nextgov, Cyberscoop, FedSmith coverage, August 4-8, 2026; IAPP breach-population analysis.