Breadcrumb

Inspection of Information Security at the Battle Creek Healthcare System in Michigan

Report Information

Issue Date
Report Number
24-02575-50
VISN
State
Michigan
District
VA Office
Information and Technology (OIT)
Veterans Health Administration (VHA)
Report Author
Office of Audits and Evaluations
Report Type
Information Security Inspection
Report Topic
Information Technology and Security
Major Management Challenges
Information Systems and Innovation
Recommendations
6
Questioned Costs
$0
Better Use of Funds
$0
Congressionally Mandated
No

Summary

Summary

The VA Office of Inspector General’s information security inspection program assesses whether VA facilities are meeting federal security requirements related to three control areas the OIG determined to be at highest risk: configuration management controls, security management controls, and access controls. For this inspection, the OIG selected the Battle Creek Healthcare System in Michigan. The OIG found deficiencies in all three areas inspected.

Configuration management controls, which identify and manage security features for all hardware and software components of an information system, were deficient in vulnerability remediation, system baseline configurations, and unauthorized software remediation.

Security management controls had one deficiency. The OIG found biomedical staff relied on incomplete security remediation reports to manage vulnerabilities on medical devices. The inspection team identified 25 vulnerabilities on seven biomedical devices that were not tracked in security remediation reports used by biomedical staff.

Access controls had three deficiencies. The OIG found the Battle Creek facility was deficient in physical access, environmental controls, and network segmentation. As a result, the facility risks unauthorized access, disruption, and destruction of critical information technology resources.

The OIG made three recommendations to the assistant secretary for information and technology and chief information officer to improve vulnerability management processes, implement a more effective baseline configuration process, and improve the remediations reporting process for the Continuous Readiness in Information Security Program. The OIG also made three recommendations to the healthcare system’s director, in conjunction with the assistant secretary for information and technology and chief information officer, to implement improved physical access controls, ensure network segmentation controls are applied as appropriate, and implement improved, consistent environmental controls for network communications closets.

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 8/21/2025

Improve vulnerability management processes to ensure all vulnerabilities are identified and plans of action and milestones are created for vulnerabilities that cannot be mitigated by VA deadlines.

No. 2
Open Recommendation Image, Square
to Information and Technology (OIT)

Implement a more effective baseline configuration process to ensure network devices are running authorized software that is configured to approved baselines and free of vulnerabilities.

No. 3
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 5/1/2025

Improve the remediations reporting process for the Continuous Readiness in Information Security Program to verify that corrective actions are taken to fully mitigate vulnerabilities for biomedical devices at the Battle Creek facility.

No. 4
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT),Veterans Health Administration (VHA)
Closure Date: 5/1/2025

Implement improved physical access controls to restrict access to the server room and communications closets.

No. 5
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT),Veterans Health Administration (VHA)
Closure Date: 5/1/2025

Ensure network segmentation controls are applied to all network segments hosting special-purpose systems or medical devices.

No. 6
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT),Veterans Health Administration (VHA)
Closure Date: 5/1/2025

Implement improved, consistent environmental controls for network communications closets.