본문 바로가기 주메뉴 바로가기
국회도서관 홈으로 정보검색 소장정보 검색

결과 내 검색

동의어 포함

목차보기

Title page 1

Contents 3

Highlights 2

Letter 5

Background 9

HIPAA Established Safeguards for Protected Health Information 10

VHA Shares Information with National Business Associates 10

The Million Veteran Program Collects Sensitive Health Information 13

Federal Law, Policy, and Guidance Establish Requirements for Protecting PHI and Securing Federal Systems and Information 14

Previous GAO and VA OIG Work Highlights Need for Controls over PHI and Management of EHRM 16

VHA Developed and Documented PII and PHI Policies in Accordance with NIST Guidance 17

VHA Oversees the Privacy of Shared Health Information and Plans to Improve Its Performance Audit Approach 19

VHA Ensured That National BAAs Addressed HIPAA Privacy Rule Requirements 19

VHA Monitored Changes in PHI Processing Through Biennial Reviews of BAAs 21

VHA Documented Audit Responsibilities and is Developing a Risk-Based Approach for Performance Audits 22

VA Took Steps to Protect Health Information in Its Million Veteran Program, but Work Remains 23

VA Implemented Asset and Risk Management Controls but Further Actions Needed 23

VA Partially Implemented Configuration Management Guidance 25

VA Encrypted in Transit and at Rest Data, but Shortcomings Exist in Other Identity and Access Management Controls 26

VA Partially Implemented Continuous Monitoring and Logging Controls in the Selected System 29

VA Has Made Progress in Addressing GAO Recommendations to Resolve Security Control Weaknesses 29

Agency Comments 30

Appendix I: Objectives, Scope, and Methodology 32

Appendix II: Comments from the Department of Veterans Affairs 39

Appendix III: GAO Contact and Staff Acknowledgments 40

Figures 3

Figure 1. National Business Associate Agreement Establishment and Review Process 12

Figure 2. Million Veteran Program 13

Figure 3. Health Insurance Portability and Accountability Act Privacy Rule Requirements to be Addressed in Business Associate Agreements 20

Figure 4. Status of Efforts by the Department of Veterans Affairs to Implement GAO's Recommendations for the Selected System's Security... 30