VA doctors' foray into cloud causes potential breach

Yahoo calendar held patient names, surgeries

The Veterans Affairs Department has ordered an immediate shutdown of a cloud application on the Yahoo website that VA doctors were using to store patients’ medical information without appropriate data security controls, officials said.

Notifications of a possible security breach will be sent to 878 patients, according to VA’s "Monthly Report to Congress on Data Incidents" for November, released by the department Dec. 22.

The breach, which is referred to as a mishandling of electronic information, came to the attention of VA's information security authorities on Nov. 23 when they discovered that physicians and employees in a VA hospital orthopedics department were maintaining a calendar of patient medical data on a Yahoo.com cloud application.


Related stories:

Unencrypted thumb drive causes breach at VA

VA data breach reports available online


The calendar has existed since 2007 and was protected by a single password shared by a number of people. The password had not been changed in the three years of operation.

The calendar contained full names, dates and types of surgery, and the last four digits of Social Security numbers for nearly 900 patients, the report states.

VA’s National Security Operations Center ordered the calendar to be closed Nov. 24. All entries were deleted, and the patients are to be notified of the possible breach.

Roger Baker, VA's assistant secretary for information and technology, said Dec. 22 the incident was an example of the need for better and more secure IT tools for VA employees, including cloud-based tools.

The report notes that all VA doctors have access to a secure VA network to store patient information and a Microsoft Excel application to schedule appointments and surgeries.

About the Author

Alice Lipowicz is a staff writer covering government 2.0, homeland security and other IT policies for Federal Computer Week.

The Fed 100

Read the profiles of all this year's winners.

Featured

  • Then-presidential candidate Donald Trump at a 2016 campaign event. Image: Shutterstock

    'Buy American' order puts procurement in the spotlight

    Some IT contractors are worried that the "buy American" executive order from President Trump could squeeze key innovators out of the market.

  • OMB chief Mick Mulvaney, shown here in as a member of Congress in 2013. (Photo credit Gage Skidmore/Flickr)

    White House taps old policies for new government makeover

    New guidance from OMB advises agencies to use shared services, GWACs and federal schedules for acquisition, and to leverage IT wherever possible in restructuring plans.

  • Shutterstock image (by Everett Historical): aerial of the Pentagon.

    What DOD's next CIO will have to deal with

    It could be months before the Defense Department has a new CIO, and he or she will face a host of organizational and operational challenges from Day One

  • USAF Gen. John Hyten

    General: Cyber Command needs new platform before NSA split

    U.S. Cyber Command should be elevated to a full combatant command as soon as possible, the head of Strategic Command told Congress, but it cannot be separated from the NSA until it has its own cyber platform.

  • Image from Shutterstock.

    DLA goes virtual

    The Defense Logistics Agency is in the midst of an ambitious campaign to eliminate its IT infrastructure and transition to using exclusively shared, hosted and virtual services.

  • Fed 100 logo

    The 2017 Federal 100

    The women and men who make up this year's Fed 100 are proof positive of what one person can make possibile in federal IT. Read on to learn more about each and every winner's accomplishments.

Reader comments

Sat, Oct 1, 2011 GBOGH Annandale, VA

No wonder doctors where using a cloud based calendar. Why is Microsoft Excel being used at the VA for scheduling appointments and surguries? $3.2 billion a year in discretionary IT budget should allow for building or buying a better patient scheduling application.

Fri, Jan 21, 2011 Tom Boston

So when are the monetary fines and punishments promised by HIPAA going to kick in and actually penalize the staff for flagrant violations of compliance??? HIPAA has raised the cost of healthcare, ostensibly for the public good, why not start collecting? Now.

Tue, Jan 4, 2011

Seriously? Of course IT is a pain with their security requirements, governments and businesses require us to be that way. That doesn't give the right for providers to do reckless things that their HIPAA training told them not to do.
Imagine if your bank issued everyone the same pin number for each debit card they issued, and then shared all kinds of account information with anyone who might happen to have the pin.
How about throwing your payroll, dob, ssn, and other personal data out on a Yahoo account and play share the password. What is more appalling is that people that pull these kinds of stunts usually use passwords like 12345. Hmmm wonder how many hackers have seen the data?

Wed, Dec 29, 2010

I'm sure there are lots of such things going on. Perhaps that "IT dept. is a pain with their security requirements" syndrome.

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group