38 U.S.C. § 5724

Provision of credit protection and other services

Read at: OLRCuscode.house.gov CornellLII GovInfogovinfo.gov JustiaTitle 38 CasesGoogle Scholar
(a)Independent Risk Analysis.—(1) In the event of a data breach with respect to sensitive personal information that is processed or maintained by the Secretary, the Secretary shall ensure that, as soon as possible after the data breach, a non-Department entity or the Office of Inspector General of the Department conducts an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach.(2) If the Secretary determines, based on the findings of a risk analysis conducted under paragraph (1), that a reasonable risk exists for the potential misuse of sensitive personal information involved in a data breach, the Secretary shall provide credit protection services in accordance with the regulations prescribed by the Secretary under this section.(b)Regulations.—Not later than 180 days after the date of the enactment of the Veterans Benefits, Health Care, and Information Technology Act of 2006, the Secretary shall prescribe interim regulations for the provision of the following in accordance with subsection (a)(2):(1) Notification.(2) Data mining.(3) Fraud alerts.(4) Data breach analysis.(5) Credit monitoring.(6) Identity theft insurance.(7) Credit protection services.(c)Report.—(1) For each data breach with respect to sensitive personal information processed or maintained by the Secretary, the Secretary shall promptly submit to the Committees on Veterans’ Affairs of the Senate and House of Representatives a report containing the findings of any independent risk analysis conducted under subsection (a)(1), any determination of the Secretary under subsection (a)(2), and a description of any services provided pursuant to subsection (b).(2) In the event of a data breach with respect to sensitive personal information processed or maintained by the Secretary that is the sensitive personal information of a member of the Army, Navy, Air Force, Marine Corps, or Space Force or a civilian officer or employee of the Department of Defense, the Secretary shall submit the report required under paragraph (1) to the Committee on Armed Services of the Senate and the Committee on Armed Services of the House of Representatives in addition to the Committees on Veterans’ Affairs of the Senate and House of Representatives.(Added Pub. L. 109–461, title IX, § 902(a), Dec. 22, 2006, 120 Stat. 3455; amended Pub. L. 116–283, div. A, title IX, § 926(h), Jan. 1, 2021, 134 Stat. 3831.)Editorial NotesReferences in Text

The date of the enactment of the Veterans Benefits, Health Care, and Information Technology Act of 2006, referred to in subsec. (b), is the date of enactment of Pub. L. 109–461, which was approved Dec. 22, 2006.

Amendments

2021—Subsec. (c)(2). Pub. L. 116–283 substituted “Marine Corps, or Space Force” for “or Marine Corps”.

Notes of Decisions
Cited in 2 cases (2 in the last 5 years), 2024–2024 · leading case: Crandall v. McDonough (E.D. Pa. 2024).
Crandall v. McDonough (E.D. Pa. 2024). · cites it 2× “” 38 U.S.C. § 5724 (a)(1). The VBHCITA further states: If the Secretary determines, based on the findings of a risk analysis conducted under paragraph (1), that a reasonable risk exists for the potential misuse of sensitive personal information involved in a data breach, the…”
Ruell v. Mcdonough (E.D. Pa. 2024). · cites it 2× “38 U.S.C. § 5724 (a)(1). If the Secretary determines that a reasonable risk exists for the potential misuse of sensitive personal information involved in a data breach, then the statute requires the Secretary to provide credit protection services consistent with accompanying…”
Annotations are extracted automatically from the opinions in the Syfert caselaw corpus and ranked by authority, recency, and treatment. Dots show Syfertize treatment of the citing case itself.