MAR 8, 2013 5:05pm ET

Related Links

Medical Loss Ratio Rules Finalized for Medicare Advantage & Drug Programs
May 20, 2013
Rule Sets Pre-existing Coverage Rates
May 20, 2013
Quick Turnaround on Breach Notification
May 17, 2013
California Developing Guidance for Patient Consent of HIE
May 17, 2013
OCR Seminars to Walk through Omnibus HIPAA Rule
May 16, 2013
Hacker Gets Patient Credit Cards from North Carolina Providers
May 16, 2013
AMA Report: EHRs in Exam Rooms Need Not be Disruptive
May 15, 2013

VA Watchdog: Department Transmits Unencrypted Data Over Internet

Print
Reprints
Email

The Department of Veterans Affairs in at least Nebraska and South Dakota routinely transmits unencrypted personally identifiable information on beneficiaries, including medical information and Social Security numbers, among medical centers, clinics and business partners such as teleradiologists, according to the VA’s Office of Inspector General.

“VA has not implemented technical configuration controls to ensure encryption of sensitive data despite VA and Federal information security requirements,” the OIG notes in a report issued on March 6 and available here. Moreover, VA Office of Information and Technology Management “acknowledged this practice and formally accepted the security risk of potentially losing or misusing the sensitive information, exchanged via a waiver; however, the use of a system security waiver was not appropriate,” according to the report.

The OIG has investigated allegations of unencrypted transmissions since receiving a complaint in May 2012. The transmissions are being made in the Nebraska and South Dakota regions. The medical centers studied in the report are Fort Meade and Sioux Falls in South Dakota and in Omaha, Nebraska. The centers are part of the VA Midwest Health Care Network, called VISN 23, which serves more than 400,000 veterans in all of Iowa, Minnesota, Nebraska, North Dakota, and South Dakota, and parts of Illinois, Kansas, Missouri, Wisconsin and Wyoming.

OIG notes that Roger Baker, CIO at VA and assistant secretary for information and technology, did not agree with its assertion that protected and sensitive information was being transmitted over unsecured Internet connections. “He nonetheless acknowledged that VA transmits protected identifiable information over privately segmented networks to support service to veterans,” according to OIG. Backer said the department uses Multiprotocol Label Switching network links to provide a segmented network, and his office acknowledged to OIG that these links are not currently using encryption.

Now, Baker has agreed with OIG recommendations to identify VA networks transmitting sensitive data over unencrypted networks and employ encryption; and to ensure I.T. personal receive “complete specialized training emphasizing the importance of encrypting sensitive VA data transmitted across public Internet connections,” according to OIG.

Comments (1)
We should all be using internet with encryption. Skip the expense of building HIEs.
Posted by Michael A | Monday, March 11 2013 at 2:35PM ET
Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn

As the feds ramp up enforcement of privacy and security rules, providers look to fill protection gaps.

Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Already a subscriber? Log in here
Please note you must now log in with your email address and password.