All Reports

Date Issued
|
Report Number
25-00975-234
|
Topics:  Information Technology and Security

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Open Recommendation Image, Square
to Information and Technology (OIT)

Implement vulnerability management processes to ensure all vulnerabilities are identified and plans of action and milestones are created for vulnerabilities that cannot be mitigated by VA deadlines.

No. 2
Open Recommendation Image, Square
to Information and Technology (OIT)

Implement a more effective baseline configuration process to ensure network devices and databases are running authorized software that is configured to approved baselines and free of vulnerabilities.

No. 3
Open Recommendation Image, Square
to Information and Technology (OIT)

Perform a cost-benefit analysis and implement appropriate controls within the federal Electronic Health Record to limit disclosure of veteran personally identifiable information based on job responsibility.

No. 4
Open Recommendation Image, Square
to Information and Technology (OIT),Veterans Health Administration (VHA)

Segregate the duties of maintaining key stock and making keys.

No. 5
Open Recommendation Image, Square
to Information and Technology (OIT),Veterans Health Administration (VHA)

Place network infrastructure equipment in a communications closet or approved enclosure to restrict access to only authorized personnel.

No. 6
Open Recommendation Image, Square
to Information and Technology (OIT),Veterans Health Administration (VHA)

Complete the installation of grounding measures for all telecommunications closets to protect information technology equipment against electromagnetic pulse attack or electrostatic discharge. Ensure the work completed by contractors adheres to the requirements as defined in the work order.

No. 7
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT),Veterans Health Administration (VHA)
Closure Date: 2/18/2026

Add anti-ram barriers to protect all sides of a fueling station’s fuel tank.

Date Issued
|
Report Number
25-00529-219
|
Topics:  Financial Management ● Information Technology and Security

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Open Recommendation Image, Square
to Office of Management (OM)

Implement a plan with the Office of Acquisition and Logistics Project Management Office to ensure system access is more granular and the intent of the principle of least privilege is met.

No. 2
Open Recommendation Image, Square
to Office of Management (OM)

Ensure all roles and accesses, including those provided by default access, are reviewed and certified periodically as required.

No. 3
Open Recommendation Image, Square
to Office of Management (OM)

Implement a permanent solution to provide supervisors and information owners with visibility of all roles and accesses, including those provided by default access, granted to users.

Date Issued
|
Report Number
25-00214-61
|
Topics:  Information Technology and Security ● Patient Care Services Operations ● Staffing ● Supplies and Equipment

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Open Recommendation Image, Square
to Veterans Health Administration (VHA)

The Executive Director ensures staff receive education about badge holders’ responsibilities in preventing unauthorized access to VA facilities and computer systems and safeguarding electronic databases including electronic health care records.

No. 2
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 2/12/2026

The Executive Director ensures signs are present and accurate throughout the facility.

No. 3
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 2/12/2026

The Executive Director ensures staff maintain privacy curtains, preventive maintenance on medical equipment, and splash resistant bottom shelves on supply carts.

No. 4
Open Recommendation Image, Square
to Veterans Health Administration (VHA)

The Executive Director ensures staff monitor patient care areas for expired, damaged, and contaminated medications and remove them as needed.

No. 5
Open Recommendation Image, Square
to Veterans Health Administration (VHA)

The Executive Director ensures staff store medications in pharmaceutical grade refrigerators.

No. 6
Open Recommendation Image, Square
to Veterans Health Administration (VHA)

The Executive Director ensures primary care staffing is sufficient for patients to receive appropriate health care.

No. 7
Open Recommendation Image, Square
to Veterans Health Administration (VHA)

The Executive Director reviews staffing levels for the Housing and Urban Development–Veterans Affairs Supportive Housing program and takes action as needed.

Date Issued
|
Report Number
24-00568-38
|
Topics:  Information Technology and Security

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Open Recommendation Image, Square
to Veterans Health Administration (VHA)

The Executive Director of Operations for a national cancer testing program ensures the project has met the requirements for Institutional Review Board review for research with human subjects and takes action as needed.

No. 2
Open Recommendation Image, Square
to Veterans Health Administration (VHA)

The Executive Director of Operations for a national cancer testing program ensures national cancer prevention, treatment, and research program staff are trained on Institutional Review Board project submission and privacy requirements. 

No. 3
Open Recommendation Image, Square
to Veterans Health Administration (VHA)

The National Specialty Care Program Office Chief Officer ensures the national cancer prevention, treatment, and research program staff reviews and provides required approvals before the release of protected health information for research. 

No. 4
Open Recommendation Image, Square
to Veterans Health Administration (VHA)

The National Specialty Care Program Office Chief Officer, in conjunction with the Office of Research & Development ensures that VA privacy officers report privacy incidents involving data obtained from or for national cancer prevention, treatment, and research program activities timely and monitors for compliance.

No. 5
Open Recommendation Image, Square
to Veterans Health Administration (VHA)

The Office of Research Oversight Executive Director in conjunction with the Chief Research and Development Officer, VHA Office of Research & Development, reviews the national cancer prevention, treatment, and research program final mitigation plan and ensures corrective actions address system-wide issues for determining whether a national cancer prevention, treatment, and research program project constitutes research, safeguarding privacy when data is shared for projects, and ensuring data security requirements are met. 

No. 6
Open Recommendation Image, Square
to Veterans Health Administration (VHA)

The National Specialty Care Program Office Chief Officer ensures the national cancer prevention, treatment, and research program has safeguards in place including biostatistician expertise to ensure that data containing sensitive patient information and protected health information is deidentified before sharing outside of VA as required.

Date Issued
|
Report Number
24-03708-141
|
Topics:  Information Technology and Security

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Open Recommendation Image, Square
to Information and Technology (OIT)

Implement vulnerability management processes to ensure all vulnerabilities are identified and plans of action and milestones are created for vulnerabilities that cannot be mitigated by VA deadlines.

No. 2
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 1/29/2026

Develop and approve an authorization to operate for the special-purpose systems.

No. 3
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 1/29/2026

Include facility personnel during the security categorization process to ensure all necessary information types are considered when determining the security categorization for special-purpose systems.

No. 4
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 1/29/2026

Segregate the pharmacy application administrative access from individuals who are custodians of the pharmaceutical inventory.

No. 5
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 1/29/2026

Ensure a witness observes the destruction of temporary paper files that contain personally identifiable information and protected health information.