All Reports

Date Issued
|
Report Number
16-00007-206

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 8/1/2016
We recommended that managers monitor hand hygiene compliance at the 46th Street VA Mental Health and Eye Clinics.
No. 2
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 8/1/2016
We recommended that the Facility Director ensures the development and implementation of a policy for the management of clinical and mental health emergencies at the 46th Street South VA Eye Clinic.
No. 3
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 8/1/2016
We recommended that the Facility Director ensures documentation of a Hazard Vulnerability Assessment to identify potential emergencies at the Forty Sixth Street South VA Mental Health Clinic.
No. 4
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 10/13/2016
We recommended that clinic managers ensure that sterile commercial supplies at the 46th Street South VA Eye Clinic are not expired.
No. 5
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 8/1/2016
We recommended that clinic managers review the Forty Sixth Street South VA Mental Health Clinic’s hazardous materials inventory twice within a 12-month period.
No. 6
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 3/23/2016
We recommended that clinic managers provide feminine hygiene disposal bins in women’s public restrooms at the 46th Street South VA Mental Health Clinic.
No. 7
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 8/1/2016
We recommended that clinic managers at the 46th Street South VA Mental Health and Eye Clinics ensure the information technology server closet is maintained according to information technology safety and security standards.
No. 8
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 10/13/2016
We recommended that providers sign Home Telehealth assessments and treatment plans.
No. 9
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 10/13/2016
We recommended that clinicians consistently notify patients of their laboratory results within the timeframe set by local policy.
Date Issued
|
Report Number
15-04709-208

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 10/21/2016
We recommended that facility clinical managers consistently review Ongoing Professional Practice Evaluation data every 6 months and that facility managers monitor compliance.
No. 2
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 3/23/2016
We recommended that facility managers ensure damaged equipment in patient care areas is repaired or removed from service and stained/missing ceiling tiles are replaced.
No. 3
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 8/4/2016
We recommended that clinicians validate patient and/or caregiver understanding of the discharge instructions provided.
No. 4
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 8/4/2016
We recommended that the Radiation Safety Officer ensure all computed tomography technologists have documented training on safe procedures for operating the types of computed tomography equipment they use.
No. 5
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 10/21/2016
We recommended that the facility ensure new employees complete suicide prevention training and new clinical employees complete suicide risk management training within the required timeframe and that facility managers monitor compliance.
No. 6
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
Closure Date: 8/4/2016
We recommended that clinicians ensure patients and/or caregivers receive a copy of the Suicide Prevention Safety Plan and that facility managers monitor compliance.
Date Issued
|
Report Number
15-01957-100

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology fully implement an agency-wide risk management governance structure, along with mechanisms to identify, monitor, and manage risks across the enterprise. (This is a modified repeat recommendation from prior years.)
No. 2
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology formally authorize Health Eligibility Center systems to operate in accordance with VA information security standards. (This is a new recommendation.)
No. 3
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement clear roles, responsibilities, and accountability for developing, maintaining, completing, and reporting Plans of Action and Milestones. (This is a repeat recommendation from prior years.)
No. 4
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement mechanisms to ensure Plans of Action and Milestones are updated to accurately reflect current status information. (This is a repeat recommendation from prior years.)
No. 5
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement mechanisms to ensure sufficient supporting documentation is captured in the central Governance Risk and Compliance tool to justify closure of Plans of Action and Milestones. (This is a repeat recommendation from last year.)
No. 6
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement improved processes to ensure that all identified weakness are incorporated into Governance Risk and Compliance tool, in a timely manner, and corresponding POA&Ms are developed to track corrective actions and remediation. (This is a new recommendation.)
No. 7
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement system enhancements to the Governance Risk and Compliance tool to prevent the automatic re-opening of closed Plans of Action and Milestones and update Enterprise Operation¿s version of the tool to reflect NIST 800-53 Revision 4 controls. (This is a new recommendation.)
No. 8
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology develop mechanisms to ensure system security plans reflect current operational environments, including accurate system interconnections, boundary, control, and ownership information. (This is a repeat recommendation from last year.)
No. 9
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement improved processes for reviewing and updating key security documents such as risk assessments, privacy impact assessments, and security control assessments on an annual basis and ensure all required information accurately reflects the current environment. (This is a repeat recommendation from last year.)
No. 10
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement mechanisms to enforce VA password policies and standards on all operating systems, databases, applications, and network devices. (This is a repeat recommendation from prior years.)
No. 11
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement periodic access reviews to minimize access by system users with incompatible roles, permissions in excess of required functional responsibilities, and unauthorized accounts. (This is a repeat recommendation from prior years.)
No. 12
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology enable system audit logs and conduct centralized reviews of security violations on mission-critical systems. (This is a repeat recommendation from prior years.)
No. 13
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology fully implement two-factor authentication for all local and remote access methods throughout the agency. (This is a repeat recommendation from prior years.)
No. 14
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement mechanisms to ensure all remote access computers have updated security patches and antivirus definitions prior to connecting to VA information systems. (This is a repeat recommendation from prior years.)
No. 15
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement more effective automated mechanisms to continuously identify and remedy security deficiencies on VA¿s network infrastructure, database platforms, and Web application servers. (This is a repeat recommendation from last year.)
No. 16
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement a more effective patch and vulnerability management program to address security deficiencies identified during our assessments of VA¿s Web applications, database platforms, network infrastructure, and work stations. (This is a repeat recommendation from last year.)
No. 17
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology maintain complete and accurate baseline configurations and ensure all baselines are appropriately implemented and checked for compliance with established VA security standards. (This is a modified repeat recommendation from last year.)
No. 18
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement improved network access controls to ensure medical devices and non-OI&T managed networks are appropriately segregated from general networks and mission-critical systems. (This is a repeat recommendation from last year.)
No. 19
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology consolidate the security responsibilities for non-OI&T networks present under a common control for each site and ensure vulnerabilities are remedied in a timely manner. (This is a modified repeat recommendation from last year.)
No. 20
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement procedures to enforce a standardized system development and change control framework that integrates information security throughout the life cycle of each system. (This is a repeat recommendation from last year.)
No. 21
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement processes to ensure information system contingency plans are updated with the required information. (This is a repeat recommendation from last year.)
No. 22
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology develop and implement a process for ensuring the encryption of backup data prior to transferring the data offsite for storage. (This is a repeat recommendation from prior years.)
No. 23
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement improved processes for the testing of contingency plans and failover capabilities for major applications and general support systems to ensure that critical components can be recovered at an alternate site in the event of a system failure or disaster. (This is a new recommendation.)
No. 24
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology perform and document a Business Impact Analysis for all systems and incorporate the results into an overall strategy development effort for contingency planning. (This is a new recommendation.)
No. 25
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement more effective agency-wide incident response procedures to ensure timely resolution of computer security incidents in accordance with VA set standards. (This is a repeat recommendation from prior years.)
No. 26
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology identify all external network interconnections and implement improved processes for monitoring all VA internal networks, systems, and exchanges for unauthorized activity. (This is a repeat recommendation from last year.)
No. 27
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement improved safeguards to prevent data exfiltration from VA networks. (This is a new recommendation.)
No. 28
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology fully develop a comprehensive list of approved and unapproved software and implement continuous monitoring processes to identify and prevent the use of unauthorized software on agency devices. (This is a repeat recommendation from prior years.)
No. 29
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology develop a comprehensive software inventory process to identify major and minor software applications used to support VA programs and operations. (This is a repeat recommendation from prior years.)
No. 30
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement procedures for overseeing contractor-managed cloud-based systems and ensuring information security controls adequately protect VA sensitive systems and data. (This is a repeat recommendation from last year.)
No. 31
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology implement mechanisms for updating the Federal Information Security Modernization Act systems inventory, including contractor-managed systems and interfaces, and annually review the systems inventory for accuracy. (This is a repeat recommendation from last year.)
No. 32
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology update all applicable position descriptions to better describe position sensitivity levels, and improve documentation of personnel records of ¿Rules of Behavior¿ and annual privacy training certifications.
No. 33
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology ensure appropriate levels of background investigations be completed for all personnel in a timely manner, implement processes to monitor and ensure timely reinvestigations on all applicable employees and contractors, and monitor the status of the requested investigations.
No. 34
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology reduce wireless security vulnerabilities by ensuring sites have up-to-date mechanisms to protect against interception of wireless signals and unauthorized access to the network, and ensure the wireless network is segmented from the general network.
No. 35
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 6/21/2017
We recommended the Assistant Secretary for Information and Technology identify and deploy solutions to encrypt sensitive data and resolve clear text protocol vulnerabilities.