Breadcrumb

Records Management Center Disclosed Third-Party Personally Identifiable Information to Privacy Act Requesters

Report Information

Issue Date
Report Number
19-05960-244
VA Office
Veterans Benefits Administration (VBA)
Report Author
Office of Audits and Evaluations
Report Type
Review
Recommendations
5
Questioned Costs
$0
Better Use of Funds
$0
Congressionally Mandated
No

Summary

Summary
The VA Office of Inspector General (OIG) conducted this review to determine whether the Veterans Benefits Administration’s (VBA) Records Management Center disclosed third-party information (including social security numbers of other service members and medical professionals) when responding to Privacy Act requests. The act requires VBA to let beneficiaries review their claims files and have copies made. Many VBA records include third-party information, which had been redacted until a May 2016 policy change. VBA changed the policy that month because the redaction requirement was a major contributor to its massive requests backlog. Redaction also interfered with VBA’s plans to give veterans online access to their records. The May 2016 policy change did not require third parties to be notified when their information was released, meaning individuals at risk of identity theft might not be aware of that risk. VBA also did not communicate the policy change to veterans and service members. The OIG also found VBA put individuals at risk by not following procedures to encrypt sensitive information on discs mailed to veterans. The review of a random sample of 30 Privacy Act responses found 1,027 unrelated third party names and social security numbers. The OIG determined those disclosures raised legal concerns and estimated that responses under the May 2016 policy put millions of people at risk of identity theft. VA’s Office of General Counsel, however, had provided VBA with legal support for the policy change, despite the risk. The OIG asked the under secretary for benefits in a December 11, 2018, memo to immediately suspend VBA’s release policy and reevaluate the Privacy Act request program. After initially rejecting the request, the under secretary responded on June 19, 2019, saying VBA concluded that a policy update was necessary, and redactions would resume by October 1, 2019.

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Closed and Implemented Recommendation Image, Checkmark
to Veterans Benefits Administration (VBA)
The Under Secretary for Benefits implements the Veterans Benefits Administration’s commitment to update its Privacy Act release policy and begin redacting third-party personally identifiable information.
No. 2
Closed and Implemented Recommendation Image, Checkmark
to Veterans Benefits Administration (VBA)
The Under Secretary for Benefits ensures VA’s website is updated to reflect current Veterans Benefits Administration policy regarding release of third-party personally identifiable information.
No. 3
Closed and Implemented Recommendation Image, Checkmark
to Veterans Benefits Administration (VBA)
The Under Secretary for Benefits implements a plan to ensure the Records Management Center complies with requirements for mailing Privacy Act responses in accordance with VA Directive 6609.
No. 4
Closed and Implemented Recommendation Image, Checkmark
to Veterans Benefits Administration (VBA)
The Under Secretary for Benefits establishes a plan to ensure that Records Management Center management receives a report for any site visit of the Records Management Center completed by the Veterans Benefits Administration and takes corrective action as needed.
No. 5
Closed and Implemented Recommendation Image, Checkmark
to Veterans Benefits Administration (VBA)
The Records Management Center director implements a plan to improve quality reviews and ensures staff are held accountable for the accuracy of their Privacy Act releases.