Breadcrumb

Inspection of Information Security at the Lovell Federal Healthcare System in Illinois

Report Information

Issue Date
Report Number
25-04267-174
VISN
3
State
Illinois
District
VA Office
Information and Technology (OIT)
Veterans Health Administration (VHA)
Report Author
Office of Audits and Evaluations
Report Type
Information Security Inspection
Report Topic
Information Technology and Security
Major Management Challenges
Information Systems and Innovation
Recommendations
7
Questioned Costs
$0
Better Use of Funds
$0
Congressionally Mandated
No

Summary

Summary

The VA Office of Inspector General’s (OIG) information security inspection program assesses whether VA facilities are meeting federal security requirements related to three high-risk control areas: configuration management, security management, and access control. For this inspection, the OIG selected the Lovell Federal Healthcare System in Illinois and found deficiencies in all three areas.

For configuration management, VA staff did not remediate multiple high- and critical-severity vulnerabilities within VA-defined time frames and had not developed required action plans. Also, some devices were not configured according to approved security baselines. These issues increase the risk of unauthorized access and operational disruption.

Security management had one deficiency: The healthcare system did not set access to network accounts to be automatically removed for temporary staff (specifically, student accounts) in line with VA and federal requirements. This could affect veteran care or the healthcare system’s operations. It could also result in a breach of personal health information, which could lead to a financial and reputational loss to VA, an agency entrusted to protect sensitive veteran data. In February 2026, after the OIG team notified the facility of this issue, facility staff entered correct expiration dates for individuals. They also created standard operating procedures for establishing appropriate expiration dates for these temporary accounts.

Finally, regarding access control, the OIG found the Lovell Federal Healthcare System in Illinois can improve boundary protection, physical key management, emergency power, electrical grounding, and temporary records destruction. Inadequate access controls can result in unauthorized access to, modification of, or disclosure of sensitive data and programs and disruption of critical operations.

The OIG made seven recommendations to improve the healthcare system’s information security, two of which were closed based on sufficient evidence provided by VA’s Office of Information and Technology.

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 9/10/2026

Improve vulnerability management processes so that all vulnerabilities are identified and mitigated; for vulnerabilities that cannot be mitigated by VA deadlines, create plans of action and milestones.

No. 2
Open Recommendation Image, Square
to Information and Technology (OIT)

Improve the baseline configuration process to make sure network devices and databases are running authorized software that is configured to approved baselines and free of vulnerabilities.

No. 3
Open Recommendation Image, Square
to Information and Technology (OIT)

Confirm appropriate network isolation and protections for all medical devices and special‑purpose systems hosted on the Lovell Federal Healthcare System networks.

No. 4
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT),Veterans Health Administration (VHA)
Closure Date: 9/10/2026

Separate the duties of maintaining physical blank key stock and making keys to improve physical access controls over key inventories.

No. 5
Open Recommendation Image, Square
to Information and Technology (OIT),Veterans Health Administration (VHA)

Improve the process for monitoring and servicing uninterruptible power supplies that support the network infrastructure.

No. 6
Open Recommendation Image, Square
to Information and Technology (OIT),Veterans Health Administration (VHA)

Complete the installation of grounding measures for all communications closets.

No. 7
Open Recommendation Image, Square
to Information and Technology (OIT),Veterans Health Administration (VHA)

Establish a process to make sure a witness observes the destruction of temporary paper files that contain personally identifiable information and protected health information.