Inspection of Information Security at the Lovell Federal Healthcare System in Illinois
Report Information
Summary
The VA Office of Inspector General’s (OIG) information security inspection program assesses whether VA facilities are meeting federal security requirements related to three high-risk control areas: configuration management, security management, and access control. For this inspection, the OIG selected the Lovell Federal Healthcare System in Illinois and found deficiencies in all three areas.
For configuration management, VA staff did not remediate multiple high- and critical-severity vulnerabilities within VA-defined time frames and had not developed required action plans. Also, some devices were not configured according to approved security baselines. These issues increase the risk of unauthorized access and operational disruption.
Security management had one deficiency: The healthcare system did not set access to network accounts to be automatically removed for temporary staff (specifically, student accounts) in line with VA and federal requirements. This could affect veteran care or the healthcare system’s operations. It could also result in a breach of personal health information, which could lead to a financial and reputational loss to VA, an agency entrusted to protect sensitive veteran data. In February 2026, after the OIG team notified the facility of this issue, facility staff entered correct expiration dates for individuals. They also created standard operating procedures for establishing appropriate expiration dates for these temporary accounts.
Finally, regarding access control, the OIG found the Lovell Federal Healthcare System in Illinois can improve boundary protection, physical key management, emergency power, electrical grounding, and temporary records destruction. Inadequate access controls can result in unauthorized access to, modification of, or disclosure of sensitive data and programs and disruption of critical operations.
The OIG made seven recommendations to improve the healthcare system’s information security, two of which were closed based on sufficient evidence provided by VA’s Office of Information and Technology.
Improve vulnerability management processes so that all vulnerabilities are identified and mitigated; for vulnerabilities that cannot be mitigated by VA deadlines, create plans of action and milestones.
Improve the baseline configuration process to make sure network devices and databases are running authorized software that is configured to approved baselines and free of vulnerabilities.
Confirm appropriate network isolation and protections for all medical devices and special‑purpose systems hosted on the Lovell Federal Healthcare System networks.
Separate the duties of maintaining physical blank key stock and making keys to improve physical access controls over key inventories.
Improve the process for monitoring and servicing uninterruptible power supplies that support the network infrastructure.
Complete the installation of grounding measures for all communications closets.
Establish a process to make sure a witness observes the destruction of temporary paper files that contain personally identifiable information and protected health information.