VA doctors' foray into cloud causes potential breach

Yahoo calendar held patient names, surgeries

The Veterans Affairs Department has ordered an immediate shutdown of a cloud application on the Yahoo website that VA doctors were using to store patients’ medical information without appropriate data security controls, officials said.

Notifications of a possible security breach will be sent to 878 patients, according to VA’s "Monthly Report to Congress on Data Incidents" for November, released by the department Dec. 22.

The breach, which is referred to as a mishandling of electronic information, came to the attention of VA's information security authorities on Nov. 23 when they discovered that physicians and employees in a VA hospital orthopedics department were maintaining a calendar of patient medical data on a Yahoo.com cloud application.


Related stories:

Unencrypted thumb drive causes breach at VA

VA data breach reports available online


The calendar has existed since 2007 and was protected by a single password shared by a number of people. The password had not been changed in the three years of operation.

The calendar contained full names, dates and types of surgery, and the last four digits of Social Security numbers for nearly 900 patients, the report states.

VA’s National Security Operations Center ordered the calendar to be closed Nov. 24. All entries were deleted, and the patients are to be notified of the possible breach.

Roger Baker, VA's assistant secretary for information and technology, said Dec. 22 the incident was an example of the need for better and more secure IT tools for VA employees, including cloud-based tools.

The report notes that all VA doctors have access to a secure VA network to store patient information and a Microsoft Excel application to schedule appointments and surgeries.

About the Author

Alice Lipowicz is a staff writer covering government 2.0, homeland security and other IT policies for Federal Computer Week.

Featured

  • Defense
    The Pentagon (Photo by Ivan Cholakov / Shutterstock)

    DOD CIO hits pause on JEDI cloud acquisition

    Dana Deasy set cloud as his office's top priority. But when it comes to the JEDI request for proposal, he's directed staff to "pause" to compile a comprehensive review.

  • Cybersecurity
    By Gorodenkoff shutterstock ID 761940757

    Waging cyber war without a rulebook

    As the U.S. looks to go on the offense in the cyber domain, critical questions remain unanswered around who will take the lead and how clearly to draw the rules of engagement.

  • Government Innovation Awards
    Government Innovation Awards - https://governmentinnovationawards.com

    Deadline extended for Rising Star nominations

    You now have until July 18 to help us identify the early-career innovators and change agents in government IT.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.