Recommendations

2166
533
Open Recommendations
876
Closed in Last Year
Age of Open Recommendations
373
Open Less Than 1 Year
146
Open Between 1-5 Years
14
Open More Than 5 Years
Key
Open Less Than 1 Year
Open Between 1-5 Years
Open More Than 5 Years
Closed
Total Recommendations found,
Total Reports found.
ID Report Number Report Title Type
25-01698-70 Federal Information Security Modernization Act Audit for Fiscal Year 2025 Audit

1
We recommended the Assistant Secretary for Information and Technology consistently implement an improved continuous monitoring program in accordance with the NIST Risk Management Framework. Specifically, regarding the independent evaluation of the effectiveness of security controls prior to granting authorization decisions. 
2
We recommended the Assistant Secretary for Information and Technology implement improved processes for reviewing and updating key security documentation, including Security Control Assessments and Privacy Impact Assessments as needed. Such updates will ensure all required information is included and accurately reflects the current environment, new security risks, and applicable Federal standards.
3
We recommended the VA Office of Personnel Security, Human Resources, and Contract Offices strengthen processes to ensure appropriate levels of background investigations are performed timely and completed for applicable VA employees and contractors. 
4
We recommended the Assistant Secretary for Information and Technology ensure contingency plans for all systems and applications are updated and tested in accordance with VA requirements.
5
We recommended the Assistant Secretary for Information and Technology implement improved procedures to ensure that system outages are resolved within stated recovery time objectives. 
6
We recommended the Assistant Secretary for Information and Technology ensure backups are conducted periodically and tested in accordance with established standards for VA system and application data. 
7
We recommended the Assistant Secretary for Information and Technology ensure system owners consistently implement processes for periodic reviews of user account access and maintain access authorization documentation. Remove unnecessary and inactive accounts on systems and networks. 
8
We recommended the Assistant Secretary for Information and Technology ensure system owners consistently follow termination procedures for the timely disablement of user accounts and the proper completion of termination checklists for separated personnel.
9
We recommended the Assistant Secretary for Information and Technology work with system owners and change implementers to improve adherence to standards and best practices across the Systems Development Lifecycle (SDLC) for testing and approval of system changes for VA systems and networks. 
10
We recommended the Assistant Secretary for Information and Technology work with system owners and application teams to implement and enforce standards for processes related to preventing and detecting potential unauthorized changes across all platforms and applications in the environment.
11
We recommended the Assistant Secretary for Information and Technology ensure that all systems and platforms are monitored for compliance with documented VA standards for baseline configurations. Ensure that system owners consistently implement and monitor their configurations. 
12
We recommended the Assistant Secretary for Information and Technology implement automated software management processes on all agency platforms to identify and prevent the use of unauthorized software on agency devices.
13
We recommended the Assistant Secretary for Information and Technology work with system owners to ensure adherence to established procedures for maintaining, documenting, and monitoring an accurate software and logical hardware inventory for system boundaries across the enterprise.
14
We recommended the Assistant Secretary for Information and Technology implement improved processes for monitoring and analyzing significant system audit events for unauthorized or unusual activities across all systems and platforms in accordance with VA policy. 
15
We recommended the Assistant Secretary for Information and Technology enable system audit logs on all critical systems and platforms and conduct centralized reviews of security violations across the enterprise.
16
We recommended the Assistant Secretary for Information and Technology implement improved mechanisms to continuously identify and remediate security deficiencies on VA’s network infrastructure, database platforms, and Web application servers in accordance with established policy timeframes. If patches cannot be applied or are unavailable, other protections or mitigations should be documented and implemented to address the specific risks.
17
We recommended the Assistant Secretary for Information and Technology continue to implement controls that restrict vulnerable medical devices from unnecessary access from the general network. 
18
We recommended the Assistant Secretary for Information and Technology implement improved processes to require system owners and management to provide adequate credentials to ensure security scans are authenticated to end devices where feasible and the subsequent vulnerabilities are remediated in a timely manner.
19
We recommended the Assistant Secretary for Information and Technology improve the process for tracking and resolving vulnerabilities that cannot be addressed by enterprise processes within policy timeframes. Implement mitigations for identified security deficiencies by applying security patches, system software updates, or configuration changes to reduce applicable security risks. Additionally, VA should enhance their process for updating baseline images to ensure aged vulnerabilities are not introduced into the environment. 
25-01584-123 Audit of the Education Service’s Compliance Surveys Review

1
Update the appropriate manual to ensure all statutorily required VA educational benefit programs are included in active student counts.
Closure Date:
2
Ensure contractor performance is measured in accordance with the contract and that a quality assurance surveillance plan is developed for future contracts for compliance surveys with clear roles and responsibilities of Veterans Benefits Administration staff and with measurable, documented surveillance procedures and outcomes.
3
Develop, document, and implement procedures for identifying, waiving, and assigning compliance survey workload to ensure all education and training institutions are scheduled and surveyed as required, and update the Veterans Benefits Administration Manual 22‑4 as necessary.
Closure Date:
4
Evaluate the effectiveness of quality control activities for Veterans Benefits Administration and contracted compliance survey specialists and implement improved or additional controls where needed.
5
Ensure continued focus on collaboration and communication between Approvals, Compliance, and Liaison regions and evaluate the organization’s regional structure to ensure compliance surveys are consistently and effectively scheduled and assigned.
Closure Date:
6
Ensure Approvals, Compliance, and Liaison leaders develop and continue to implement policy and procedures for using waivers for compliance surveys and develop metrics to evaluate record of compliance criteria so waivers maintain the intent of the statute.
Closure Date:
Total Monetary Impact of All Recommendations
Open: $19,386,671
Closed: $0
Total: $19,386,671
25-02440-122 Review of the Fiduciary Program’s Misuse Allegation Process Review

1
Review and update applicable sections of the VA Fiduciary Program Manual to clarify how to properly evaluate an allegation, including detailing what constitutes a misuse allegation that must be documented and reviewed, and when an investigation is needed, in coordination with the VA Office of General Counsel if necessary.
2
Clarify in the VA Fiduciary Program Manual how potential misuses of beneficiary funds, such as red flag indicators, must be addressed and documented, and reinforce with training or resources as needed.
3
Clearly communicate the evidentiary standard staff should use in the allegation phase to help ensure application of different standards is accurate and easily understood and results in consistent compliance with how investigations are initiated, and consider consulting with the VA Office of General Counsel if necessary.
4
Develop a plan to implement or enhance the national quality review program to ensure compliance with procedural guidance for processing all phases of misuse allegations.
Closure Date:
25-03621-145 Review of Medical Facilities’ Management of Specialty Care Calls Review

1
Create a process for facilities to regularly update and verify specialty care clinics’ phone numbers listed in internal facility directories and on websites.
2
Annually evaluate and verify that automated interactive phone systems route veterans directly to the correct specialty care clinic and assess whether the phone systems support first-call resolution.
3
Reconfigure specialty care clinics’ phone lines to be able to collect required call performance data and assess whether centralized queues enhance the efficiency of phone management.
4
Provide guidance to specialty care clinics on how they should manage and respond to voicemails, including for routine reviews of voicemail data.
5
Provide guidance that assigns both the responsibility for and the frequency of routine monitoring of call performance data and analyses of complaint data trends from the patient advocate system to identify and address veterans’ phone access issues for specialty care clinics.
25-02887-107 Review of Open Obligations in VBA’s General Operating Expenses Account Review

1
Standardize and enforce a documented monthly process for reviewing and validating open obligations—including undelivered orders and accruals—with defined staff roles, responsibilities, and communication protocols, in alignment with VA financial policy.
2
In conjunction with the Office of Acquisition, Logistics, and Construction, establish and document procedures that define roles and communication requirements with requesting and contracting offices to ensure timely end-date modifications and deobligation of funds that are no longer needed.
3
In coordination with the VA Office of Financial Policy, develop VBA‑specific procedures aligned with appendix F of VA Financial Policy, “Obligations,” and confirm those procedures are consistently implemented to support reconciliation, documentation, and closure of open obligations in the Integrated Financial and Acquisition Management System.
Total Monetary Impact of All Recommendations
Open: $895,257,953
Closed: $0
Total: $895,257,953
25-00253-156 Healthcare Facility Inspection of the VA San Diego Healthcare System in California Healthcare Facility Inspection

1
Facility leaders ensure staff follow procedures to properly separate and store soiled and clean equipment.
Closure Date:
2
Facility leaders ensure environmental management services staff clean ice machines daily to help prevent infection risk.
Closure Date:
3
Facility leaders ensure staff properly label and store oxygen tanks.
Closure Date:
4
Facility leaders ensure staff update the facility policy to include all elements to communicate test results to patients, as required in Veterans Health Administration Directive 1088(1), Communicating Test Results to Providers and Patients.
25-00193-155 Healthcare Facility Inspection of the VA El Paso Healthcare System in Texas Healthcare Facility Inspection

1
Executive leaders ensure staff maintain a clean and safe environment.
2
The Medical Center Director ensures providers complete secondary toxic exposure screenings within 30 days.
25-01781-71 Audit of Security and Access Controls for the Patient Advocate Tracking System-Replacement Audit

1
Ensure that authorizations are reassessed when a significant change affects the security or privacy posture of an application, consistent with the requirements of VA Handbook 6500.
Closure Date:
2
Reevaluate the risk determination for the Patient Advocate Tracking System‑Replacement and determine the appropriate security categorization level and system classification based on (1) the sensitive personal information maintained in the system and (2) the System Security Categorization Report.
3
Reevaluate whether there is a continued business need to maintain access to veterans’ medical records in the Patient Advocate Tracking System-Replacement.
4
Institute a process to ensure user roles are regularly reviewed for continued access and evaluate the effectiveness of the access control principle of least privilege to ensure roles for the Patient Advocate Tracking System-Replacement are correctly configured and allow access only for authorized users.
5
Update the Patient Advocate Tracking System-Replacement user guides and training materials.
25-02402-83 Follow-Up Inspection of Information Security at the VA Southern Oregon Healthcare System Information Security Inspection

1
Improve the existing vulnerability management process to make sure all vulnerabilities are identified, plans of action and milestones are created for vulnerabilities that cannot be mitigated by VA deadlines, and software is updated before vendor support ends.
2
Implement a baseline configuration process to make sure network devices and databases are running authorized software that is configured to approved baselines and free of vulnerabilities.
3
Implement a process to disable access to the active directory and the electronic health record when temporary staff leave before their expected end date.
Closure Date:
4
Separate the duties of maintaining physical blank key stock and making keys to improve physical access controls over key inventories.
Closure Date:
5
Secure network infrastructure in accordance with VA environmental protection standards.
6
Complete the installation of grounding measures for all telecommunication closets to protect information technology equipment.
7
Routinely monitor and service uninterruptible power supplies that support the network infrastructure.
8
Establish a process to make sure a witness observes the destruction of temporary paper files that contain personally identifiable information and protected health information.
Closure Date:
25-02487-143 Audit of Pharmaceutical Purchases Made Outside the Prime Vendor Contract Audit

1
Develop and establish guidance detailing how medical facility staff must document evidence to support their decisions when they make pharmaceutical purchases through the open market.
2
Ensure medical facility leaders conduct routine assessments of pharmaceutical purchases made through the open market so purchases are made in accordance with policy.
3
Develop a mechanism, in coordination with VHA’s purchase card program office and VA’s Office of General Counsel, that provides visibility into all pharmaceutical purchases, including purchases outside the prime vendor contract.
15520