38 CFR 75.116
§ 75.116 Secretary determination.
United States · 38 CFR — Pensions, Bonuses, and Veterans' Relief · Status: effective
Cite this
- Citation
- 38 CFR 75.116, § 75.116 Secretary determination, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/166321
- Permanent ID
ys:prov:166321@1- SHA-256
a2dfe0876eba2493d9bb5dfdfc571c3cbfc49a992f7d75ddc08fc22d59c77e09
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
(a) Upon receipt of a risk analysis prepared under this subpart, the Secretary will consider the findings and other information contained in the risk analysis to determine whether the data breach caused a reasonable risk for the potential misuse of sensitive personal information. If the Secretary finds that such a reasonable risk does not exist, the Secretary will take no further action under this subpart. However, if the Secretary finds that such a reasonable risk exists, the Secretary will take responsive action as specified in this subpart based on the potential harms to individuals subject to a data breach.
(b) In determining whether the data breach resulted in a reasonable risk for the potential misuse of the compromised sensitive personal information, the Secretary shall consider all factors that the Secretary, in his or her discretion, considers relevant to the decision, including:
(1) The likelihood that the sensitive personal information will be or has been made accessible to and usable by unauthorized persons;
(2) Known misuses, if any, of the same or similar sensitive personal information;
(3) Any assessment of the potential harm to the affected individuals provided in the risk analysis;
(4) Whether the credit protection services that VA may offer under 38 U.S.C. 5724 may assist record subjects in avoiding or mitigating the results of identity theft based on the VA sensitive personal information that had been compromised;
(5) Whether private entities are required under Federal law to offer credit protection services to individuals if the same or similar data of the private entities had been similarly compromised; and
(6) The recommendations, if any, concerning the offer of, or benefits to be derived from, credit protection services in this case that are in the risk analysis report.
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.