Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • ELECTRONIC HEALTH RECORDS—N.D. Ill.: Help at Home must face core claims over patient data breach
    • ADMINISTRATION OF FDC ACT—FDA GUIDANCE NOTICES: Protein efficiency ratio rat bioassay studies to demonstrate new infant formula supports quality factor
    • ADMINISTRATION OF MEDICARE/MEDICAID PROGRAMS—DAB DECISIONS: CMS revocation authority for failure to timely report license suspension
    • CIVIL MONEY PENALTIES—DAB DECISIONS: Failure to post machine-readable file listing standard charges lead to imposition of CMP
    • CONTROLLED SUBSTANCES—PROPOSED RULES: Placement of diphenidine in Schedule I
    • DURABLE MEDICAL EQUIPMENT—DAB DECISIONS: CMS properly determined effective date of enrollment of Medicare durable medical equipment supplier
    • ELECTRONIC HEALTH RECORDS—GAO REPORTS: VA has made progress on health information privacy
    • MEDICAL DEVICES NEWS—Cotton Warns FDA About Cyber Vulnerabilities in Chinese-Made Medical Devices
    • STRATEGIC PERSPECTIVES—The Future Ready Lawyer: Experts share insights on making legal AI work
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Health Law Daily Wrap Up, ELECTRONIC HEALTH RECORDS—GAO REPORTS: VA has made progress on health information privacy, (May 27, 2026)

    Organizations Mentioned:Veterans Health Administration

    By Steven Melendez

    The GAO found Veterans Health Administration data sharing agreements comply with HIPAA and ongoing progress in other areas.

    A report from the Government Accountability Office (GAO) gave mostly high marks to health information security controls at the ...

    By Steven Melendez

    The GAO found Veterans Health Administration data sharing agreements comply with HIPAA and ongoing progress in other areas.

    A report from the Government Accountability Office (GAO) gave mostly high marks to health information security controls at the Veterans Health Administration (VHA), finding a random sample of protected health information (PHI) sharing agreements with business associates complied with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule. Additionally, the Department of Veterans Affairs (VA) is addressing risks around its Million Veteran Program (MVP) pointed out by GAO in September 2025.

    The report is an updated public version of a “sensitive report with limited distribution” issued in September 2025 examining VHA’s information sharing and confidentiality provisions around the MVP. In that report, GAO had made 13 recommendations to address security control issues around the MVP. So far, VA has implemented nine of them and partially implemented another three.

    Information sharing agreements. The VHA relies on a variety of external entities known as business associates (BAs), which can be given access to PHI. The agency works with about 450 national BAs, set up by first asking the entity to respond to a questionnaire. If a BA must work with PHI, the VA and the entity enter into a business associate agreement (BAA), which among other things requires the BA to adhere to the requirements of the HIPAA Privacy Rule. BAAs are renewed every two years after verifying the entities still require access to PHI and making any needed updates.

    As part of its review, GAO reviewed agreements with 73 randomly selected national business associates—excluding internal VA entities, other federal agencies, and ones that don’t have access to PHI—and looked to see whether they complied with 12 requirements from the HIPAA Privacy Rule. The review found that 100 percent of the agreements included clauses covering all 12 requirements. Based on the biennial review process, agreements are updated to a current template every two years, according to the GAO report.

    The review also found the VHA documented responsibilities for conducting independent performance audits to verify national BAs are meeting obligations. The VHA is also working on an approach to select business associates for “independent performance audits based on risk,” according to the report.

    Million Veteran Program. The Million Veteran Program tracks effects of genetics, lifestyle, military experiences, and various exposures on the health and wellness of veterans, including about 1 million veterans who have joined the program since its inception in 2011. “The cybersecurity of these systems and the data in them is imperative to the protection of veterans’ health information,” the GAO said in a letter to Rep. Mark Takano (D-California), the ranking Democrat on the House Committee on Veterans Affairs, accompanying the report.

    Steps are taken to de-identify veterans in the sample for research, but the program still collects PHI as needed. The GAO report found that the VA did take steps to protect health information used in the program specifically “assessed potential risks and secured data in transit and at rest in the selected system.” But the department did not “fully implement all security controls related to risk management, configuration management, identity and access management, and continuous monitoring,” meaning it had “less assurance that the controls over confidentiality and integrity are effective.”

    In its limited distribution September report, the GAO made recommendations as to how it could improve. The public report does not disclose the full findings and recommendations out of security concerns, but it does broadly address the recommendations and VA response.

    The GAO found that the VA “did not fully establish system-level procedures, conduct risk or security control assessments, or implement remedial action plans;” that it categorized sensitive information appropriately; that it secured data at rest and in transit; that it “partially documented system-level procedures” related to security and privacy; that its “risk assessment showed its analysis of some but not all threats and vulnerabilities to the system,” excluding issues like potential vulnerabilities in system components; and that that it documented but did not fully implement a remedial action management process. Policies around account management were documented but not fully implemented, according to the report, and the VA didn’t review all user accounts in accordance with its procedures, nor did it “fully implement user authentication and authorization controls to access system resources.”

    Since the September report, the VA has addressed nine of 13 recommendations, partially addressed another three, and not addressed one, according to the GAO report.

    “VA values the effort by GAO to evaluate privacy and cybersecurity protections implemented to protect the Million Veteran Program,” wrote Curt Cashour, the VA’s chief of staff, in a letter included with the report. “VA takes security very seriously and works to ensure Veterans data is always protected in the continuously changing threat scenarios.”

    ReportsLetters: GAOReports CMSNews EHRNews HITNews HIPAANews MilitaryNews

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use