TOPICS

An information technology specialist at the Veterans Affairs Department misled investigators in an attempt to cover up the extent of a data breach early this year that jeopardized personal information on more than a million people, according to a recent audit report.

In an interview with auditors, the specialist gave inaccurate information about the Jan. 22 loss of an external computer hard drive from VA's Birmingham, Ala., research facility, the report from the department's inspector general stated. The information ended up in a press release about the incident, the investigators found.

The specialist also encrypted and deleted multiple files from his computer shortly after he reported the data missing, making it more difficult to determine what was stored on his desktop, the IG said. He initially denied this when confronted by investigators, the report said. But an IG computer forensic analysis prompted him to admit to taking actions to hide the extent of the missing data.


RELATED STORIES

As of February, the IT specialist, who was not named in the report, had been placed on administrative leave pending the outcome of the investigation. The VA did not respond to requests for an update Monday on the specialist's employment status.

Michael Kussman, VA's undersecretary for health, concurred with the IG's recommendation that "appropriate administrative action [be] taken against the IT specialist for his inappropriate actions during the course of the investigation and for failing to properly safeguard personally identifiable information on his missing external hard drive." Kussman said the "target completion" date for this was Oct. 1, following a review of the evidence.

The specialist had used the hard drive to back up research data he kept on a desktop computer and to store other data from a shared network. The drive is thought to have contained personally identifiable information for more than 250,000 veterans and 1.3 million medical providers. The data on medical providers came from the Centers for Medicare and Medicaid Services and the Health and Human Services Department.

If the specialist had protected the information in accordance with the terms under which it was provided, the breach might have been avoided, the report said. The IG also criticized managers for failing to follow proper procedures to safeguard data stored on external hard drives.

An Aug. 7, 2006, VA policy prohibits employees from storing sensitive data on portable devices without encryption, and assigns responsibility to local supervisors for protecting sensitive information. The Birmingham facility's director did not request encryption software and depended on employees to store external hard drives in a locked office safe when not in use, the audit found.

According to the report, several employees decided not to put the hard drives in the safe, and at least one took home a hard drive that contained privacy protected information concerning VA employees. The facility did not keep records of when the safe was accessed or whether there was an inventory of its contents.

The director of the Birmingham Medical Center moved the research facility into new office space without ensuring that its information security needs were sufficiently evaluated, the IG added. The director told investigators that when he made the decision, he was not aware that employees stored large amounts of sensitive data on external hard drives.

Kussman also agreed with the IG that the center's director should have "appropriate administrative action" taken against him "for failing to take adequate security measures to protect personally identifiable information."

The FBI has joined the investigation in coordination with the Birmingham Police Department. A $25,000 reward has been posted. The VA's technology chief said last month that the data breach would cost the department $20 million.

Investigators have considered "all possible leads," the report stated. Those include a burglary of the office; the IT specialist taking the hard drive out of the office and losing it or having it stolen; a co-worker hiding the hard drive for vengeful reasons; or the accidental disposal of the hard drive during routine housekeeping.

Investigators have visited local computer repair shops, contacted eBay and questioned many individuals working or living near the office, including homeless individuals who frequent the area, the report stated. Fingerprints have been taken and two homes and five vehicles of employees were searched, according to the IG.

COMMENTS

  • This article states: "The VA's technology chief said last month that the data breach would cost the department $20 million." I wonder does this amount include the bonsus the director got for a pat on the back for doing a good job. Let's don't forget how the VA spends the mney alloted to the Department by Congress. The money could be better spent on our veterans, widows, and orphans instead the VA Department's employees, federal employees, waste taxpayers money and get rewarded for it - or it seems that away with them getting these bonsuses. I have been fighting for a claim that was found at the USCAVC in l998 as being overlooked in the file since l983 and the Court trusted the Secretary to finalize it posthaste. Yet, today it is still not finalized and as a matter of fact, the Montgomery Regional Office closed this remand directive of the Board of Veterans Appeals and violated l9.38 but no one will address this issue and arguments of the VA's own failure to assist in preparation of the claim and now the issue is l983 - 2007 some almost 24 years overdue. They had rather waste taxpayers money than keep the promise to our veterans, their widows and orphans which has long been carved in stone: "To care for those who borne the battle and their widows and orphans. (Abraham Lincoln)" When does this injustice STOP! We can get an investigation into a theft of a computer drive, but we can't get an investigation into the misstating and mishandling of a claim. WHY NOT?
  • With respect to Gary L. There is nothing like over generalizing from two comments (incorrectly I might add) to all of society. One earlier commenter said the employee should probably lose the job, but that the supervisor should have a more serious penalty than is likely to be levied. The other commenter does not defend the employee in the first sentence. So how is calling for the supervisor to be accountable too the same as calling for no personal responsibility? I'm confused by your logic. Probably the employee and his/her supervisor failed to read the rules or pay attention to the training they were given. There are rules about sensitive data...which are ignored. And there are environments created by supervisors which make following the rules and not getting fired virtually impossible. Both are culpable. How is blaming the employee but not the supervisor creating a world of personal responsbility? Again your logic is not clear to me. As for the story, I'd just like to see the practices at private universities and research firms, or even moreso at private commercial firms.
  • I must be missing something,I was under the impression that he was being paid by the goverment and had the responsibility of safeguarding the data. I guarntee that he's the guy that makes everyone change their password every 30 days and no 2 passswords can be the same. This has nothing to do with "bossess" its about a jerk not following directives he needs to be gone. The point is the VETERANS are the ones who will end up having to deal with his poor judgement