§4. Enhanced cybersecurity for EBT cards
This section requires the Secretary of Agriculture, not later than two years after enactment and with reviews every five years thereafter, to promulgate cybersecurity and digital service regulations for electronic benefit transfer (EBT) cards and mobile payments in the Supplemental Nutrition Assistance Program (SNAP)—which provides food purchase benefits to eligible low-income households—ensuring such measures match private-sector and federal standards for credit, debit, and other payment cards.
The regulations must require (1) each state to operate required user interfaces from a Secretary-maintained list (including a web-based portal, mobile application, free application programming interface for third-party software, and—for 10 years—text messaging, voice telephone service, and nondigital options), which must be available in required languages, achieve 99% uptime, and—for web portals—be mobile friendly; (2) states to offer households opt-in access via digital interfaces to timely transaction notices, 12 months of searchable transaction history (including amount, merchant, location, and delivery details), and fraud reporting, with notifications about prior fraud reimbursements and restrictions; and (3) states to enable households to restrict EBT cards for online transactions to virtual card numbers or tokenization technology. (Thus, these measures aim to reduce EBT fraud, such as card skimming and cloning, by mandating chip-enabled cards resistant to cloning and NIST-compliant PIN/password standards.)