Sunday, September 13, 2026
Inspection of Information Security at the Lovell Federal Healthcare System in Illinois Inbox Veterans Affairs Office of Inspector General (OIG) Unsubscribe Thu, Sep 10, 7:06 AM (3 days ago) to me New Rebranded Header Inspection of Information Security at the Lovell Federal Healthcare System in Illinois 9/10/2026 10:00 AM EDT The Office of Inspector General (OIG) is committed to helping improve VA operations. The OIG information security inspection program assesses whether VA facilities are meeting federal security requirements related to three high-risk control areas: configuration management, security management, and access control. For this inspection, the OIG selected the Lovell Federal Healthcare System in Illinois and found deficiencies in all three areas. For configuration management, VA staff did not remediate multiple high- and critical-severity vulnerabilities within VA-defined time frames and had not developed required action plans. Also, some devices were not configured according to approved security baselines. These issues increase the risk of unauthorized access and operational disruption. Security management had one deficiency: The healthcare system did not set access to network accounts to be automatically removed for temporary staff (specifically, student accounts) in line with VA and federal requirements. This could affect veteran care or the healthcare system’s operations. It could also result in a breach of personal health information, which could lead to a financial and reputational loss to VA, an agency entrusted to protect sensitive veteran data. In February 2026, after the OIG team notified the facility of this issue, facility staff entered correct expiration dates for individuals. They also created standard operating procedures for establishing appropriate expiration dates for these temporary accounts. Finally, regarding access control, the OIG found the Lovell Federal Healthcare System in Illinois can improve boundary protection, physical key management, emergency power, electrical grounding, and temporary records destruction. Inadequate access controls can result in unauthorized access to, modification of, or disclosure of sensitive data and programs and disruption of critical operations. The OIG made seven recommendations to improve the healthcare system’s information security, two of which were closed based on sufficient evidence provided by VA’s Office of Information and Technology.
Inspection of Information Security at the Lovell Federal Healthcare System in Illinois
Inbox
Veterans Affairs Office of Inspector General (OIG) Unsubscribe
Thu, Sep 10, 7:06 AM (3 days ago)
to me
New Rebranded Header
Inspection of Information Security at the Lovell Federal Healthcare System in Illinois
9/10/2026
10:00 AM EDT
The Office of Inspector General (OIG) is committed to helping improve VA operations.
The OIG information security inspection program assesses whether VA facilities are meeting federal security requirements related to three high-risk control areas: configuration management, security management, and access control. For this inspection, the OIG selected the Lovell Federal Healthcare System in Illinois and found deficiencies in all three areas.
For configuration management, VA staff did not remediate multiple high- and critical-severity vulnerabilities within VA-defined time frames and had not developed required action plans. Also, some devices were not configured according to approved security baselines. These issues increase the risk of unauthorized access and operational disruption.
Security management had one deficiency: The healthcare system did not set access to network accounts to be automatically removed for temporary staff (specifically, student accounts) in line with VA and federal requirements. This could affect veteran care or the healthcare system’s operations. It could also result in a breach of personal health information, which could lead to a financial and reputational loss to VA, an agency entrusted to protect sensitive veteran data. In February 2026, after the OIG team notified the facility of this issue, facility staff entered correct expiration dates for individuals. They also created standard operating procedures for establishing appropriate expiration dates for these temporary accounts.
Finally, regarding access control, the OIG found the Lovell Federal Healthcare System in Illinois can improve boundary protection, physical key management, emergency power, electrical grounding, and temporary records destruction. Inadequate access controls can result in unauthorized access to, modification of, or disclosure of sensitive data and programs and disruption of critical operations.
The OIG made seven recommendations to improve the healthcare system’s information security, two of which were closed based on sufficient evidence provided by VA’s Office of Information and Technology.
Subscribe to:
Post Comments (Atom)
SEC Charges Founder and His Two New Jersey-Based Companies in Alleged $16 Million Ponzi Scheme Inbox Securities and Exchange Commission <sec@service.govdelivery.com> Unsubscribe Thu, Sep 10, 1:32 PM (3 days ago) to me You are subscribed to receive Press Releases from the Securities and Exchange Commission. A new press release has been posted and is now available ... SEC Charges Founder and His Two New Jersey-Based Companies in Alleged $16 Million Ponzi Scheme The Securities and Exchange Commission today charged Ernest Ossei Boateng and two New Jersey-based companies he controls, Intercontinental Wealth Network LLC and I Wealth Network LP, for allegedly raising approximately $16 million from more than 200… Follow the SEC on X, Facebook, Instagram, Truth Social, and YouTube. You can update your subscriptions, modify your password or e-mail address, or stop subscriptions at any time on your Subscriber Preferences Page. For more information on collecting personally identifiable information, please read the SEC's privacy policy. SEC Seal This email was sent to osirioas0043@gmail.com using Granicus Communications Cloud on behalf of: Securities and Exchange Commission · 100 F Street, NE · Washington, DC 20549 · 202-551-4120 Granicus Communications logo
SEC Charges Founder and His Two New Jersey-Based Companies in Alleged $16 Million Ponzi Scheme Inbox Securities and Exchange Commission Un...
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.