All Reports
Update guidance mandating use of an effective date builder for rating veterans service representatives to consider earlier effective dates when granting entitlement to individual unemployability.
Develop standardized language and prioritize incorporation into the Veterans Benefits Management System to assist rating veterans service representatives in addressing all required information/elements within an individual unemployability rating narrative.
Establish additional system controls to ensure rating veterans service representatives address competency when individual unemployability has been awarded based solely on a mental condition.
Update the Veterans Benefits Administration’s procedures manual to ensure consistency among staff and clarify the language needed to satisfy the analysis requirement when granting entitlement to individual unemployability benefits.
Develop practical learning exercises for rating veterans service representatives related to individual unemployability for Virtual and In-Person Progression training.
Require rating veterans service representatives and veterans service representatives to process and demonstrate individual unemployability claim competency on veterans’ claims.
Evaluate the workload distribution methods for individual unemployability claims to increase claims processing consistency and knowledge retention.
Implement controls to allow for the capability to identify and monitor potential scheduling delays and to ensure family preferences are being met at national cemeteries.
For future acquisitions that involve stakeholders from multiple offices, establish governance to ensure all relevant administrations and staff offices are represented in key decision roles.
For future acquisitions, establish and implement a process to promote stakeholders’ understanding of system capabilities and support buy-in.
Complete the hiring actions necessary to staff the Office of Acquisition and Logistics Project Management Office.
Resolve key Integrated Financial and Acquisition Management System challenges and ongoing concerns identified by officials from the Office of Acquisition, Logistics, and Construction and the Office of Acquisition and Logistics before further deployment of the acquisition module.
The Under Secretary for Health requires facilities to review designated time for Maternity Care Coordinator caseload, and assigned collateral duties, to determine if additional staffing resources are needed to support Veterans Health Administration Maternity Care Coordination, and takes action as appropriate.
The Under Secretary for Health reviews timeliness of facility community care maternity care referrals to ensure timely access for routine and expedited (high-risk and late term) referrals, and takes action as appropriate.
Ensure Veterans Benefits Administration staff use improved methodologies similar to the Office of Inspector General’s review to identify eligible veterans, readjudicate claims, and send outreach letters to potential Nehmer class members who could qualify for retroactive benefits under the National Defense Authorization Act.
Ensure claims processors at screening sites understand the need to identify any claims that may warrant readjudication by meeting the Nehmer consent decree and subsequent court orders.
Update the standard operating procedures to have staff consider whether veterans’ medical records show a diagnosis of the now-covered herbicide-related diseases at the time of any prior disability benefits claim before January 1, 2021, regardless of whether a current claim is for a disease recognized by the National Defense Authorization Act.
Ensure facility staff place all orders for eligible items through the Medical/Surgical Prime Vendor program, including those that are identified as on back order.
Implement tracking mechanisms for back orders to assist the facilities in not obtaining excess supplies.
Ensure that logistics staff receive training and use the Prime Vendor Conversion and Recommendation Tool to identify commonly purchased open market items and convert those items to Medical/Surgical Prime Vendor purchases.
Identify and implement an efficient way to transfer product list updates to the inventory ordering system.
In collaboration with the Strategic Acquisition Center, identify a VA-owned system for staff to check product information, such as availability and pricing, and ensure applicable facility staff are aware of this location.
Implement a standardized, routine review of open market purchases.
Ensure that reporting tools are effective and consistently applied, and that reported issues are resolved.
Ensure that logistics staff receive relevant Medical/Surgical Prime Vendor program guidance and training.
Ensure the product list includes items that facilities need and regularly purchase so the Veterans Health Administration can expand the savings and benefits the Medical/Surgical Prime Vendor program offers.
Establish a plan to use VA’s cost accounting system information to identify alternative ways to reduce costs, enhance efficiency, and inform business decisions as identified by VA financial policy.
Ensure healthcare system staff responsible for labor cost and workload mapping are responding in a timely manner to the results of managerial cost accounting audits and correcting all identified issues.
Consider a plan to align VA North Texas Health Care System financial management practices with federal financial accounting standard practices. This could include using cost information for performance measurement, budgeting, and cost control, and making economic choices.
Ensure that healthcare system staff are made aware of policy requirements and the responsible finance office conducts monthly reviews and reconciliations on all open obligations for financial validity and take appropriate actions as required by VA Financial Policy, vol. 2, chap. 5, “Obligations” (2020), updated May 2023.
Consult with Office of General Counsel and Office of Acquisitions, Logistics and Construction to determine if any further actions are necessary, including contract modifications, to remedy and prevent future purpose statute and bona fide needs rule violations.
Establish controls to ensure cardholders comply with record retention requirements, confirm approving officials and cardholders review purchases for VA policy compliance, and ensure contracting is used when it is in the best interest of the government.
Require cardholders to submit a request for ratification for any unauthorized commitments identified.
Develop and implement a plan to ensure data accuracy and reliability in the Generic Inventory Package in accordance with Veterans Health Administration policy.
Continue to develop and implement processes to ensure all necessary reports are monitored routinely and appropriate steps are taken to ensure all supply chain performance measures are maintained in compliance with policy.
Obtain an inventory of locally managed databases, perform configuration compliance scans, provide the facility with a copy of the scan results, and monitor the facility’s remediation efforts.
Implement a process to verify system owners review user account access to locally managed databases.
Implement effective system life-cycle processes to ensure network devices meet standards mandated by the VA Office of Information and Technology Configuration Control Board.
Develop and approve an authorization to operate for the special-purpose systems.
Include system personnel during the security categorization process to ensure that all necessary information types are considered when determining the security categorization for special-purpose systems.
Implement controls to ensure the accuracy of user locations supporting the Lynx Duress system.
Implement the appropriate physical security controls to restrict and monitor access to the facility, its server room, and communication closets.
Implement and monitor emergency power and uninterruptible power supplies in all communication closets.
Implement grounding equipment in all communication closets.
Implement a more effective vulnerability management program to address security deficiencies identified during the inspection. (This is a repeat recommendation from the prior inspection.)
Ensure vulnerabilities are remediated within OIT’s established time frames. (This is a repeat recommendation from the prior inspection.)
Ensure all servers and databases are part of the automated scanning process.
Implement approved baseline configurations for databases and document justifications and approvals for any deviations.
Implement more effective configuration control processes to ensure network devices maintain vendor support and receive security updates.
Implement an improved inventory process to ensure the accuracy of network ranges managed within the Enterprise Mission Assurance Support Service. (This is a repeat recommendation from the prior inspection.)
Implement an effective audit and monitoring process for all servers and databases. (This is a repeat recommendation from the prior inspection.)
Ensure that physical access logs for the data center and communication rooms are reviewed on a quarterly basis.
Consider taking appropriate steps to implement redundant distribution paths between the uninterruptible power supplies and the information technology equipment at the Hines Information Technology Center.
Implement steps to prevent the inadvertent activation of the main circuit breaker at the Hines Information Technology Center, such as installing a protective covering over the circuit breaker with an explicit warning label indicating the breaker’s function to help prevent power outages at the facility.
Implement steps to prevent the inadvertent activation of circuit breakers at all VA data centers, such as updating the physical security controls policy to require protective covers and explicit warning labels.
Update the Hines Information Technology Center information system contingency plan to help ensure the efficient restoration of data center power and critical applications in the event of a power outage.
Implement annual testing of Hines Information Technology Center contingency and restoration procedures following a power loss to ensure all stakeholders are aware of their responsibilities in accordance with revised information system contingency plan procedures.
Reduce improper and unknown payments to below 10 percent for the Pension Program. This is a repeat recommendation from the OIG’s FY 2022 report.
Reduce improper and unknown payments to below 10 percent for the Purchased Long-Term Services and Supports Program. This is a repeat recommendation from the OIG’s FY 2022 report.
We recommended the Assistant Secretary for Information and Technology consistently implement an improved continuous monitoring program in accordance with the NIST Risk Management Framework. Specifically, implement an independent security control assessment process to evaluate the effectiveness of security controls prior to granting authorization decisions.
We recommended the Assistant Secretary for Information and Technology implement improved mechanisms to ensure system stewards and Information System Security Officers follow procedures for establishing, tracking, and updating Plans of Action and Milestones for all known risks and weaknesses including those identified during security control assessments.
We recommended the Assistant Secretary for Information and Technology implement controls to ensure that system stewards and responsible officials obtain appropriate documentation prior to closing Plans of Action and Milestones.
We recommended the Assistant Secretary for Information and Technology develop mechanisms to ensure system security plans reflect current operational environments, include an accurate status of the implementation of system security controls, and all applicable security controls are properly evaluated.
We recommended the Assistant Secretary for Information and Technology implement improved processes for reviewing and updating key security documentation, including control assessments on a risk-based rotation or as needed. Such updates will ensure all required information is included and accurately reflects the current environment.
We recommended the Assistant Secretary for Information and Technology implement improved processes to ensure compliance with VA password policy and security standards on domain controls, operating systems, databases, applications, and network devices.
We recommended the Assistant Secretary for Information and Technology implement periodic reviews to minimize accounts and permissions in excess of required functional responsibilities, and to remove unauthorized or unnecessary accounts.
We recommended the Assistant Secretary for Information and Technology enable system audit logs on all critical systems and platforms and conduct centralized reviews of security violations across the enterprise.
We recommended the Office of Personnel Security, Human Resources, and Contract Offices implement improved processes for establishing and maintaining accurate investigation data within VA systems used for background investigations.
We recommended the Office of Personnel Security, Human Resources, and Contract Offices strengthen processes to ensure appropriate levels of background investigations are completed for applicable VA employees and contractors.
We recommended the Assistant Secretary for Information and Technology implement more effective automated mechanisms to continuously identify and remediate security deficiencies on VA’s network infrastructure, database platforms, and web application servers.
We recommended the Assistant Secretary for Information and Technology implement improved processes for tracking and resolving vulnerabilities that cannot be addressed within policy timeframes. Implement more effective patch and vulnerability management processes to mitigate identified security deficiencies and reduce applicable security risks.
We recommended the Assistant Secretary for Information and Technology maintain a complete and accurate security baseline configuration for all platforms and ensure all baselines are appropriately monitored for compliance with established VA security standards.
We recommended the Assistant Secretary for Information and Technology implement improved controls that restrict vulnerable medical devices from unnecessary access to the general network.
We recommended the Assistant Secretary for Information and Technology enhance procedures for tracking security responsibilities for networks, devices, and components not managed by the Office of Information and Technology to ensure vulnerabilities are remediated in a timely manner.
We recommended the Assistant Secretary for Information and Technology implement improved processes to ensure that all devices and platforms are evaluated using credentialed vulnerability assessments.
We recommended the Assistant Secretary for Information and Technology implement improved procedures to enforce standardized system development and change control processes that integrates information security throughout the life cycle of each system.
We recommended the Assistant Secretary for Information and Technology implement improved procedures to ensure that system outages and disruptions are tracked to specific system boundaries and that interdependent systems are considered for the purposes of tracking and measuring against stated system recovery time objectives.
We recommended the Assistant Secretary for Information and Technology ensure contingency plans for all systems and applications are updated and tested in accordance with VA requirements.
We recommended the Assistant Secretary for Information and Technology ensure that systems and applications are adequately logged and monitored to facilitate an agency-wide awareness of information security events.
We recommended the Assistant Secretary for Information and Technology implement improved safeguards to identify and prevent unauthorized vulnerability scans on VA networks.
We recommended the Assistant Secretary for Information and Technology implement improved measures to ensure that all security controls are assessed in accordance with VA policy and that identified issues or weaknesses are adequately documented and tracked within POA&Ms.
We recommended the Assistant Secretary for Information and Technology implement improved processes to monitor for unauthorized changes to system components and the installation of prohibited software on all agency devices and platforms.
We recommended the Assistant Secretary for Information and Technology develop a comprehensive inventory process to identify connected hardware, software, and firmware used to support VA applications and operations.
We recommended the Assistant Secretary for Information and Technology implement improved procedures for monitoring contractor-managed systems and services and ensure information security controls adequately protect VA sensitive systems and data.
The Secretary of Veterans Affairs directs the assistant secretary for Human Resources and Administration/Operations, Security, and Preparedness should update Policy Notice 23-03 and Form 10017-A to address the deficiencies noted in this report, including the overly broad definitions of groups, failure to provide adequate support for high-demand skill CSIs, and lack of needs analyses for recruitment and retention.
The Secretary of Veterans Affairs designates a responsible official to review the critical skill incentives that have been paid to any member of the Senior Executive Service (SES), SES-equivalent, or other Senior Leader (including Veterans Health Administration’s medical center directors and Veterans Integrated Service Network directors and the Veterans Benefits Administration’s regional office and district directors) for the deficiencies identified in this report and to ensure compliance with all applicable statutory criteria and VA policy, and take any corrective action needed.
The Secretary of Veterans Affairs designates a responsible official to review any critical skill incentive payments based on a high-demand skills justification made to all nonexecutive groups of employees, if any, to ensure compliance with all applicable statutory criteria and VA policy, and take any corrective action needed.
In consultation with the Office of General Counsel’s Ethics Specialty Team, the Secretary of Veterans Affairs or his designee takes appropriate action to determine whether individuals involved in the decision-making process for awarding CSIs had any actual or apparent conflicts of interest and develop a process to ensure all decision-makers are free from conflicts when awarding future incentives.
The Secretary of Veterans Affairs directs the assistant secretary for Human Resources and Administration/Operations, Security, and Preparedness to revise policies regarding critical skills incentives to ensure that recommending and approving officials are accountable for their determinations that each CSI recipient meets all established criteria, and that the roles and responsibilities of a technical reviewer and human resources reviewer are clearly established.
The Secretary of Veterans Affairs delegates to a responsible official the development of a formal concurrence process to provide reasonable assurance that a senior attorney within the Office of General Counsel (with sufficient experience and expertise to consider all relevant facts and perspectives) is accountable for providing legal advice before and during the implementation of any new authority that carries the potential for significant reputational or financial harm to VA.
The Secretary of Veterans Affairs delegates to a responsible official a review of existing governance board policies to determine whether additional guidance is needed to define their role in reviewing proposals for implementing new pay authorities affecting senior executive compensation.
The Secretary of Veterans Affairs takes whatever administrative actions, if any, he deems appropriate related to personnel involved in the process for granting critical skill incentives for VA central office executives based on the findings in this report.
Formalize the executive director’s intent by requiring the submission to the OIG of a related plan and documentation of progress on implementing VA’s maintenance of an independent and updated list of contract facilities.
Comply with the requirements of the customer satisfaction survey contract to route exam comment cards directly between the survey vendor and veteran.
Develop and implement formal standard operating procedures for the contract exam facility site visits detailing roles, responsibilities, objectives, and monitoring.
Update the Medical Disability Examination Office site visit checklist to include a focus on specific ADA and OSHA criteria required by contracts with exam vendors.
Complete a standardized training plan for staff who conduct site visits at contract exam facilities to include ADA and OSHA compliance.
Ensure the Medical Disability Examination Office is conducting complaint-based contract facility inspections.
Enforce contractual requirements for vendors to conduct inspections and recertify all facilities to ensure ADA and OSHA compliance.
Review and analyze all veteran complaints related to exam facilities received through all entities and perform complaint-based site visits or create action plans, as necessary.
Make certain that the Medical Disability Examination Office develops a plan with the vendors to determine if each veteran seeking an exam requires accessibility arrangements prior to scheduling.
Implement a plan to strengthen the National Work Queue division’s monitoring of claims awaiting decision at its own location to ensure its rules are operating as intended and make adjustments as needed.
Ensure the Office of Field Operations includes the National Work Queue division’s functioning in its annual internal controls assessment and statement of assurance.
The Under Secretary for Health considers the need for a national policy establishing the inclusion of social determinants of health/health-related social needs into discharge assessment and planning.
The Under Secretary for Health considers the implementation of a standardized electronic health record template, such as the Assessing Circumstances and Offering Resources for Needs tool, that includes the assessment of social determinants of health/health-related social needs of hospitalized patients.
The Under Secretary for Health evaluates barriers to assessing social determinants of health/health-related social needs when patients are discharged from VA medical centers.
The Under Secretary for Health promotes the use of health equity tools across VA medical centers
The Under Secretary for Health promotes the establishment of partnerships of VA medical centers with community resources to address social determinants of health/health-related social needs.