All Reports
The VA Portland Health Care System Director ensures the Community Reintegration Services director and Health Care for Homeless Veterans program coordinator establish a process to monitor and verify case managers comply with monthly veteran contacts as required by the facility’s HCHV Case Management Workflow Guide, and takes action as warranted.
The VA Portland Health Care System Director ensures Health Care for Homeless Veterans staff discharge veterans from the Health Care for Homeless Veterans program in accordance with the facility’s HCHV Case Management Workflow Guide.
The VA Portland Health Care System Director reviews the quality management evaluations, once completed, for Veteran A’s and Veteran B’s care, and takes action as warranted.
The VA Portland Health Care System Director evaluates the Community Reintegration Services reporting structure and resources to determine if the current structure allows for effective oversight of essential homeless programs, and makes modifications if needed.
The VA Portland Health Care System Director ensures the Community Reintegration Services director monitors and verifies Grant and Per Diem liaisons’ compliance with Veterans Health Administration Directive 1162.01 requirements related to conducting veteran contacts.
Consult with the VA Office of General Counsel to establish a clear and consistent interpretation of 38 C.F.R. § 4.59, to include clarification of whether pain alone without painful motion is sufficient to warrant a compensable evaluation.
Based on the clarified interpretation of 38 C.F.R. § 4.59, consider revising the Adjudication Procedures Manual to improve consistency of terms, and notify claims processors of the revision.
Assess whether guidance is clear to claims processors regarding the requirement to review all evidence, including both objective and subjective evidence, as well as the proper weight that should be given to each piece of evidence.
Determine what actions are necessary to the evaluation builder tool to mitigate confusion and ensure decision consistency for all musculoskeletal joint conditions.
The Under Secretary for Health reviews the comprehensive traumatic brain injury evaluation referral process for veterans with positive traumatic brain injury screens and ensures veterans interested in further evaluation are referred for a comprehensive traumatic brain injury evaluation.
The Under Secretary for Health considers the development of a uniform referral method for the utilization of Polytrauma System of Care resources.
The Under Secretary for Health reviews the one-time use limitation of the comprehensive traumatic brain injury evaluation template to allow documentation of additional evaluations whenever a veteran screens positive for deployment-related traumatic brain injury after a subsequent separation.
The Under Secretary for Health ensures the Veterans Health Administration continues plans toward a sustainable workforce model, enterprise-wide image-sharing capabilities, and standardization of clinical workflows and workload distribution.
The Under Secretary for Health ensures that leaders at Veterans Health Administration facilities experiencing interruptions in radiology services (1) conduct comprehensive, proactive assessments of the clinical impact to patients awaiting completion of radiology studies; and (2) report any incidents of harm or potential harm from incomplete radiologic studies to facility quality management leaders for local tracking to reduce patient safety risks.
The VA Washington DC Healthcare System Director ensures that any incidents of harm or potential harm from incomplete radiologic studies are reported to facility quality management leaders for local tracking to reduce patient safety risks.
We recommended the Assistant Secretary for Information and Technology consistently implement an improved continuous monitoring program in accordance with the NIST Risk Management Framework. Specifically, regarding the independent evaluation of the effectiveness of security controls prior to granting authorization decisions.
We recommended the Assistant Secretary for Information and Technology implement improved processes for reviewing and updating key security documentation, including Security Control Assessments and Privacy Impact Assessments as needed. Such updates will ensure all required information is included and accurately reflects the current environment, new security risks, and applicable Federal standards.
We recommended the VA Office of Personnel Security, Human Resources, and Contract Offices strengthen processes to ensure appropriate levels of background investigations are performed timely and completed for applicable VA employees and contractors.
We recommended the Assistant Secretary for Information and Technology ensure contingency plans for all systems and applications are updated and tested in accordance with VA requirements.
We recommended the Assistant Secretary for Information and Technology implement improved procedures to ensure that system outages are resolved within stated recovery time objectives.
We recommended the Assistant Secretary for Information and Technology ensure backups are conducted periodically and tested in accordance with established standards for VA system and application data.
We recommended the Assistant Secretary for Information and Technology ensure system owners consistently implement processes for periodic reviews of user account access and maintain access authorization documentation. Remove unnecessary and inactive accounts on systems and networks.
We recommended the Assistant Secretary for Information and Technology ensure system owners consistently follow termination procedures for the timely disablement of user accounts and the proper completion of termination checklists for separated personnel.
We recommended the Assistant Secretary for Information and Technology work with system owners and change implementers to improve adherence to standards and best practices across the Systems Development Lifecycle (SDLC) for testing and approval of system changes for VA systems and networks.
We recommended the Assistant Secretary for Information and Technology work with system owners and application teams to implement and enforce standards for processes related to preventing and detecting potential unauthorized changes across all platforms and applications in the environment.
We recommended the Assistant Secretary for Information and Technology ensure that all systems and platforms are monitored for compliance with documented VA standards for baseline configurations. Ensure that system owners consistently implement and monitor their configurations.
We recommended the Assistant Secretary for Information and Technology implement automated software management processes on all agency platforms to identify and prevent the use of unauthorized software on agency devices.
We recommended the Assistant Secretary for Information and Technology work with system owners to ensure adherence to established procedures for maintaining, documenting, and monitoring an accurate software and logical hardware inventory for system boundaries across the enterprise.
We recommended the Assistant Secretary for Information and Technology implement improved processes for monitoring and analyzing significant system audit events for unauthorized or unusual activities across all systems and platforms in accordance with VA policy.
We recommended the Assistant Secretary for Information and Technology enable system audit logs on all critical systems and platforms and conduct centralized reviews of security violations across the enterprise.
We recommended the Assistant Secretary for Information and Technology implement improved mechanisms to continuously identify and remediate security deficiencies on VA’s network infrastructure, database platforms, and Web application servers in accordance with established policy timeframes. If patches cannot be applied or are unavailable, other protections or mitigations should be documented and implemented to address the specific risks.
We recommended the Assistant Secretary for Information and Technology continue to implement controls that restrict vulnerable medical devices from unnecessary access from the general network.
We recommended the Assistant Secretary for Information and Technology implement improved processes to require system owners and management to provide adequate credentials to ensure security scans are authenticated to end devices where feasible and the subsequent vulnerabilities are remediated in a timely manner.
We recommended the Assistant Secretary for Information and Technology improve the process for tracking and resolving vulnerabilities that cannot be addressed by enterprise processes within policy timeframes. Implement mitigations for identified security deficiencies by applying security patches, system software updates, or configuration changes to reduce applicable security risks. Additionally, VA should enhance their process for updating baseline images to ensure aged vulnerabilities are not introduced into the environment.
Update the appropriate manual to ensure all statutorily required VA educational benefit programs are included in active student counts.
Ensure contractor performance is measured in accordance with the contract and that a quality assurance surveillance plan is developed for future contracts for compliance surveys with clear roles and responsibilities of Veterans Benefits Administration staff and with measurable, documented surveillance procedures and outcomes.
Develop, document, and implement procedures for identifying, waiving, and assigning compliance survey workload to ensure all education and training institutions are scheduled and surveyed as required, and update the Veterans Benefits Administration Manual 22‑4 as necessary.
Evaluate the effectiveness of quality control activities for Veterans Benefits Administration and contracted compliance survey specialists and implement improved or additional controls where needed.
Ensure continued focus on collaboration and communication between Approvals, Compliance, and Liaison regions and evaluate the organization’s regional structure to ensure compliance surveys are consistently and effectively scheduled and assigned.
Ensure Approvals, Compliance, and Liaison leaders develop and continue to implement policy and procedures for using waivers for compliance surveys and develop metrics to evaluate record of compliance criteria so waivers maintain the intent of the statute.
Review and update applicable sections of the VA Fiduciary Program Manual to clarify how to properly evaluate an allegation, including detailing what constitutes a misuse allegation that must be documented and reviewed, and when an investigation is needed, in coordination with the VA Office of General Counsel if necessary.
Clarify in the VA Fiduciary Program Manual how potential misuses of beneficiary funds, such as red flag indicators, must be addressed and documented, and reinforce with training or resources as needed.
Clearly communicate the evidentiary standard staff should use in the allegation phase to help ensure application of different standards is accurate and easily understood and results in consistent compliance with how investigations are initiated, and consider consulting with the VA Office of General Counsel if necessary.
Develop a plan to implement or enhance the national quality review program to ensure compliance with procedural guidance for processing all phases of misuse allegations.
Create a process for facilities to regularly update and verify specialty care clinics’ phone numbers listed in internal facility directories and on websites.
Annually evaluate and verify that automated interactive phone systems route veterans directly to the correct specialty care clinic and assess whether the phone systems support first-call resolution.
Reconfigure specialty care clinics’ phone lines to be able to collect required call performance data and assess whether centralized queues enhance the efficiency of phone management.
Provide guidance to specialty care clinics on how they should manage and respond to voicemails, including for routine reviews of voicemail data.
Provide guidance that assigns both the responsibility for and the frequency of routine monitoring of call performance data and analyses of complaint data trends from the patient advocate system to identify and address veterans’ phone access issues for specialty care clinics.
Standardize and enforce a documented monthly process for reviewing and validating open obligations—including undelivered orders and accruals—with defined staff roles, responsibilities, and communication protocols, in alignment with VA financial policy.
In conjunction with the Office of Acquisition, Logistics, and Construction, establish and document procedures that define roles and communication requirements with requesting and contracting offices to ensure timely end-date modifications and deobligation of funds that are no longer needed.
In coordination with the VA Office of Financial Policy, develop VBA‑specific procedures aligned with appendix F of VA Financial Policy, “Obligations,” and confirm those procedures are consistently implemented to support reconciliation, documentation, and closure of open obligations in the Integrated Financial and Acquisition Management System.
Facility leaders ensure staff follow procedures to properly separate and store soiled and clean equipment.
Facility leaders ensure environmental management services staff clean ice machines daily to help prevent infection risk.
Facility leaders ensure staff properly label and store oxygen tanks.
Facility leaders ensure staff update the facility policy to include all elements to communicate test results to patients, as required in Veterans Health Administration Directive 1088(1), Communicating Test Results to Providers and Patients.
Executive leaders ensure staff maintain a clean and safe environment.
The Medical Center Director ensures providers complete secondary toxic exposure screenings within 30 days.
Ensure that authorizations are reassessed when a significant change affects the security or privacy posture of an application, consistent with the requirements of VA Handbook 6500.
Reevaluate the risk determination for the Patient Advocate Tracking System‑Replacement and determine the appropriate security categorization level and system classification based on (1) the sensitive personal information maintained in the system and (2) the System Security Categorization Report.
Reevaluate whether there is a continued business need to maintain access to veterans’ medical records in the Patient Advocate Tracking System-Replacement.
Institute a process to ensure user roles are regularly reviewed for continued access and evaluate the effectiveness of the access control principle of least privilege to ensure roles for the Patient Advocate Tracking System-Replacement are correctly configured and allow access only for authorized users.
Update the Patient Advocate Tracking System-Replacement user guides and training materials.
Improve the existing vulnerability management process to make sure all vulnerabilities are identified, plans of action and milestones are created for vulnerabilities that cannot be mitigated by VA deadlines, and software is updated before vendor support ends.
Implement a baseline configuration process to make sure network devices and databases are running authorized software that is configured to approved baselines and free of vulnerabilities.
Implement a process to disable access to the active directory and the electronic health record when temporary staff leave before their expected end date.
Separate the duties of maintaining physical blank key stock and making keys to improve physical access controls over key inventories.
Secure network infrastructure in accordance with VA environmental protection standards.
Complete the installation of grounding measures for all telecommunication closets to protect information technology equipment.
Routinely monitor and service uninterruptible power supplies that support the network infrastructure.
Establish a process to make sure a witness observes the destruction of temporary paper files that contain personally identifiable information and protected health information.
Develop and establish guidance detailing how medical facility staff must document evidence to support their decisions when they make pharmaceutical purchases through the open market.
Ensure medical facility leaders conduct routine assessments of pharmaceutical purchases made through the open market so purchases are made in accordance with policy.
Develop a mechanism, in coordination with VHA’s purchase card program office and VA’s Office of General Counsel, that provides visibility into all pharmaceutical purchases, including purchases outside the prime vendor contract.
Update the local inventory procedure to include a process for securing information technology equipment when temporary space is needed and for tracking and distributing this equipment, in accordance with federal and VA requirements.
Assess the age of all unused information technology inventory to determine what should be used and what should be disposed of based on federal and VA requirements, and take action to address the results.