FHA issues reporting requirements on significant cybersecurity incidents

Orrick, Herrington & Sutcliffe LLP
Contact

Orrick, Herrington & Sutcliffe LLP

On May 23, HUD issued Mortgagee Letter (ML) 2024-10 titled “Significant Cybersecurity Incident (Cyber Incident) Reporting Requirements” which required FHA-approved mortgagees to notify HUD when a “Cyber Incident” occurs. A Cyber Incident would be any unauthorized event that could harm information or computer systems, breaching security rules, and affecting a mortgagee’s ability to meet FHA program requirements. It also would include actions that threaten data confidentiality, integrity, or availability, potentially disrupting mortgage operations. Mortgagees must report all suspected Cyber Incidents to HUD's FHA Resource Center and Security Operations Center within 12 hours of detection. The report must include several details, including the mortgagee's name and ID, contact information, a description of the incident (including the date, cause, and impact to PII, login credentials, and IT systems), any affected subsidiary or parent companies, and the status of the mortgagee’s incident response, including whether law enforcement has been notified. The provisions of this ML are effective immediately and will be reflected in a forthcoming update to the HUD Handbook 4000.1.
 

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Orrick, Herrington & Sutcliffe LLP | Attorney Advertising

Written by:

Orrick, Herrington & Sutcliffe LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Orrick, Herrington & Sutcliffe LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide