Sunday, September 13, 2026

Inspection of Information Security at the Lovell Federal Healthcare System in Illinois Inbox Veterans Affairs Office of Inspector General (OIG) Unsubscribe Thu, Sep 10, 7:06 AM (3 days ago) to me New Rebranded Header Inspection of Information Security at the Lovell Federal Healthcare System in Illinois 9/10/2026 10:00 AM EDT The Office of Inspector General (OIG) is committed to helping improve VA operations. The OIG information security inspection program assesses whether VA facilities are meeting federal security requirements related to three high-risk control areas: configuration management, security management, and access control. For this inspection, the OIG selected the Lovell Federal Healthcare System in Illinois and found deficiencies in all three areas. For configuration management, VA staff did not remediate multiple high- and critical-severity vulnerabilities within VA-defined time frames and had not developed required action plans. Also, some devices were not configured according to approved security baselines. These issues increase the risk of unauthorized access and operational disruption. Security management had one deficiency: The healthcare system did not set access to network accounts to be automatically removed for temporary staff (specifically, student accounts) in line with VA and federal requirements. This could affect veteran care or the healthcare system’s operations. It could also result in a breach of personal health information, which could lead to a financial and reputational loss to VA, an agency entrusted to protect sensitive veteran data. In February 2026, after the OIG team notified the facility of this issue, facility staff entered correct expiration dates for individuals. They also created standard operating procedures for establishing appropriate expiration dates for these temporary accounts. Finally, regarding access control, the OIG found the Lovell Federal Healthcare System in Illinois can improve boundary protection, physical key management, emergency power, electrical grounding, and temporary records destruction. Inadequate access controls can result in unauthorized access to, modification of, or disclosure of sensitive data and programs and disruption of critical operations. The OIG made seven recommendations to improve the healthcare system’s information security, two of which were closed based on sufficient evidence provided by VA’s Office of Information and Technology.

Inspection of Information Security at the Lovell Federal Healthcare System in Illinois Inbox Veterans Affairs Office of Inspector General (OIG) Unsubscribe Thu, Sep 10, 7:06 AM (3 days ago) to me New Rebranded Header Inspection of Information Security at the Lovell Federal Healthcare System in Illinois 9/10/2026 10:00 AM EDT The Office of Inspector General (OIG) is committed to helping improve VA operations. The OIG information security inspection program assesses whether VA facilities are meeting federal security requirements related to three high-risk control areas: configuration management, security management, and access control. For this inspection, the OIG selected the Lovell Federal Healthcare System in Illinois and found deficiencies in all three areas. For configuration management, VA staff did not remediate multiple high- and critical-severity vulnerabilities within VA-defined time frames and had not developed required action plans. Also, some devices were not configured according to approved security baselines. These issues increase the risk of unauthorized access and operational disruption. Security management had one deficiency: The healthcare system did not set access to network accounts to be automatically removed for temporary staff (specifically, student accounts) in line with VA and federal requirements. This could affect veteran care or the healthcare system’s operations. It could also result in a breach of personal health information, which could lead to a financial and reputational loss to VA, an agency entrusted to protect sensitive veteran data. In February 2026, after the OIG team notified the facility of this issue, facility staff entered correct expiration dates for individuals. They also created standard operating procedures for establishing appropriate expiration dates for these temporary accounts. Finally, regarding access control, the OIG found the Lovell Federal Healthcare System in Illinois can improve boundary protection, physical key management, emergency power, electrical grounding, and temporary records destruction. Inadequate access controls can result in unauthorized access to, modification of, or disclosure of sensitive data and programs and disruption of critical operations. The OIG made seven recommendations to improve the healthcare system’s information security, two of which were closed based on sufficient evidence provided by VA’s Office of Information and Technology.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.