Federal data breach victims get identity protection—if agencies fund it
H.R. 10034 — RECOVER PII Act · Filed by Eleanor Norton (D-DC) · 4 cosponsors · Introduced Aug 3, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill extends identity protection coverage to federal employees and contractors whose personal information was compromised in data breaches at federal agencies (notably the 2015 OPM breach). It mandates at least $5 million in identity theft insurance for affected individuals and allows federal agencies to reimburse employees and contractors for privacy-enhancing software and services (up to 100% of costs) starting in fiscal year 2026.
Why we flagged it
The bill's core function is to provide identity protection remedies to federal employees and contractors harmed by government data breaches, funded through agency budgets. It is a targeted victim-compensation and privacy-protection measure, not a broad appropriation or deregulation.
What the text implies
- The bill allows agencies to reimburse contractors' employees for privacy services, creating a potential indirect subsidy to cybersecurity and privacy-software vendors if agencies elect to cover contractor costs at 100%.
- The phrase 'for other purposes' in the title is boilerplate, but the bill's operative text is narrowly scoped; however, the amendment structure (cross-referencing the 2017 and 2018 Consolidated Appropriations Acts) may obscure the full scope of changes to Section 633.
The full analysis lists 4 implications of this text.
Who stands to gain
identity theft insurance providers; cybersecurity and privacy-software vendors; privacy-enhancing technology companies