FHA publishes revised cyber incident reporting requirements

Orrick, Herrington & Sutcliffe LLP
Contact

Orrick, Herrington & Sutcliffe LLP

On December 2, the FHA issued Mortgagee Letter 2024-23, outlining revised requirements for reporting cyber incidents by FHA-approved mortgagees. According to the letter, the revisions aim to align FHA reporting requirements with federal standards and address the increase in cyber incidents affecting FHA mortgagees. The letter required mortgagees to notify HUD within 36 hours of determining that a “Reportable Cyber Incident” has occurred. A reportable cyber incident is an event that has “materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the FHA-approved Mortgagee’s ability to meet its operational obligations for originating or servicing FHA-insured Mortgages.” Reports must be sent to HUD’s FHA Resource Center and Security Operations Center and include specific details such as the mortgagee’s name, ID, contact information, a description of the incident, and the status of the response. These updates will be incorporated into the FHA Single Family Housing Policy Handbook. The letter superseded a previous letter (ML 2024-10) and goes into effect immediately, applying to all FHA insurance programs.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Orrick, Herrington & Sutcliffe LLP

Written by:

Orrick, Herrington & Sutcliffe LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Orrick, Herrington & Sutcliffe LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide