Breadcrumb

Follow-Up Inspection of Information Security at the VA Southern Oregon Healthcare System

Report Information

Issue Date
Report Number
25-02402-83
VISN
20
State
Oregon
District
VA Office
Information and Technology (OIT)
Veterans Health Administration (VHA)
Report Author
Office of Audits and Evaluations
Report Type
Information Security Inspection
Report Topic
Information Technology and Security
Major Management Challenges
Information Systems and Innovation
Recommendations
8
Questioned Costs
$0
Better Use of Funds
$0
Congressionally Mandated
No

Summary

Summary

The VA Office of Inspector General (OIG) conducted a follow-up information security inspection of the Southern Oregon Healthcare System to assess three high-risk control areas: configuration management, security management, and access controls. The site was selected again due to its recent launch of the federal Electronic Health Record (EHR) system. The OIG reported VA made progress on recommendations from the 2022 inspection but found deficiencies in all three areas in this follow-up.

Configuration management controls had two deficiencies. Critical vulnerabilities persisted beyond VA’s deadline without required action plans, and servers were improperly configured against baseline security standards. These weaknesses exposed outdated, exploitable software, creating immediate risks to system security.

Security management controls had two deficiencies. The OIG identified temporary staff accounts that were not promptly disabled, and some volunteers and clerks had broad access to information in the EHR system, increasing the likelihood of data breaches.

Access controls had five critical deficiencies at the White City VA Medical Center: inadequate controls over physical key creation, unsecured network infrastructure, improperly grounded spaces and rooms, lack of backup power in multiple spaces, and improper oversight of a contractor destroying sensitive paper records. These issues threaten operations, data integrity, and VA’s reputation.

To address deficiencies, the OIG made eight recommendations to VA, four of which are similar to recommendations from the 2022 inspection. By February 2026, the Office of Information and Technology had fully addressed three recommendations, which the OIG considers closed. VA concurred with all eight recommendations.

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Open Recommendation Image, Square
to Information and Technology (OIT)

Improve the existing vulnerability management process to make sure all vulnerabilities are identified, plans of action and milestones are created for vulnerabilities that cannot be mitigated by VA deadlines, and software is updated before vendor support ends.

No. 2
Open Recommendation Image, Square
to Information and Technology (OIT)

Implement a baseline configuration process to make sure network devices and databases are running authorized software that is configured to approved baselines and free of vulnerabilities.

No. 3
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT),Veterans Health Administration (VHA)
Closure Date: 6/25/2026

Implement a process to disable access to the active directory and the electronic health record when temporary staff leave before their expected end date.

No. 4
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT),Veterans Health Administration (VHA)
Closure Date: 6/25/2026

Separate the duties of maintaining physical blank key stock and making keys to improve physical access controls over key inventories.

No. 5
Open Recommendation Image, Square
to Information and Technology (OIT),Veterans Health Administration (VHA)

Secure network infrastructure in accordance with VA environmental protection standards.

No. 6
Open Recommendation Image, Square
to Information and Technology (OIT),Veterans Health Administration (VHA)

Complete the installation of grounding measures for all telecommunication closets to protect information technology equipment.

No. 7
Open Recommendation Image, Square
to Information and Technology (OIT),Veterans Health Administration (VHA)

Routinely monitor and service uninterruptible power supplies that support the network infrastructure.

No. 8
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT),Veterans Health Administration (VHA)
Closure Date: 6/25/2026

Establish a process to make sure a witness observes the destruction of temporary paper files that contain personally identifiable information and protected health information.