Breadcrumb

Review of Alleged Unsecured Patient Database at the VA Long Beach Healthcare System

Report Information

Issue Date
Report Number
15-04745-48
VISN
State
California
District
VA Office
Veterans Health Administration (VHA)
Information and Technology (OIT)
Report Author
Office of Audits and Evaluations
Report Type
Audit
Recommendations
4
Questioned Costs
$0
Better Use of Funds
$0
Congressionally Mandated
No

Summary

Summary
In July 2015, the VA Office of Inspector General (OIG) received allegations stating that an unauthorized Microsoft Access database was operating at the VA Long Beach Healthcare System (LBHCS). The allegations stated that the unauthorized database hosted Sensitive Personal Information (SPI) and all of the Veterans Health Administration’s 24 Spinal Cord Injury (SCI) Centers had access to the database through a SharePoint intranet portal. The anonymous complainants also stated that unsecured veteran SPI was stored on a server outside of VA’s protected network environment. The OIG substantiated the allegation that an unauthorized Microsoft Access database was created by LBHCS SCI employees to capture patient demographics and to provide a repository for all SCI Centers to track patient data. Consistent with the allegation, the OIG team found multiple instances of databases that hosted SPI in violation of VA policy. It also substantiated that veteran SPI was hosted on an external server at the University of Southern California without a formal Data Use Agreement authorizing the activity. In addition, the OIG team noted this server could be accessed from the internet using default logon credentials. The OIG recommended the Under Secretary for Health ensure that the Spinal Cord Injury and Disorders program staff comply with VA’s Privacy Program and information security requirements for all veteran sensitive data collected. In addition, the OIG recommended the Executive Director for the National Spinal Cord Injury Program Office discontinue storing SPI in unauthorized Microsoft Access databases. The OIG also recommended the Acting Assistant Secretary for Information Technology ensure that Field Security Services and VA’s Privacy Service implement improved procedures to identify unauthorized uses of SPI and take appropriate corrective actions. The Executive in Charge, Office of the Under Secretary for Health, and the Executive in Charge for the Office of Information and Technology concurred with the recommendations.

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
The OIG recommended the Under Secretary for Health ensure the Spinal Cord Injury program complies with VA’s Privacy Program and information security requirements for all veteran sensitive data collected.
No. 2
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
The OIG recommended the Executive Director for the National Spinal Cord Injury Program Office discontinue the use of unauthorized versions of Microsoft Access for the storage of Spinal Cord Injury program data and implement an approved system to support its data storage and analysis needs.
No. 3
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
The OIG recommended the Acting Assistant Secretary for Information Technology ensure that VA’s Field Security Services and Privacy Service implement improved procedures to identify unauthorized uses of Sensitive Personal Information and train the facility information security officers and privacy officer to ensure that appropriate corrective actions are taken.
No. 4
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
The OIG recommended VA’s Field Security Services and Privacy Service conduct a formal review of Spinal Cord Injury projects to identify acceptable disclosures of veteran Sensitive Personal Information and ensure that appropriate safeguards are implemented to protect the confidentiality of veteran data.