Most Popular Stories
- Top FAA execs lack institutional knowledge, says official; agency must be prepared for cuts
- Air traffic control training gaps will be exacerbated by NextGen, says OIG
- Agencies plan for governmentwide FOIA portal
- FAA reauthorization would create NextGen czar UPDATED
- Obama administration announces immigrant visa waiver change
Events
- IBM Global Business Services Career Expo
February 16, 2012 — Huntsville, AL 11am - 8pm - AFCEA Bethesda Monthly Breakfast Series
February 24, 2012 — Bethesda, MD - Learn With Your Peers at the Federal Senior Management Conference
April 15-18 — Cambridge, MD - IBM Global Business Services Career Expo
February 16, 2012 — Linthicum Heights, MD 10am - 3pm
Sponsored Links
HOT TOPICS >> Cloud computing | Cybersecurity | Gov 2.0 | Fiscal 2012 | Mobile | Transparency | GAO reports
AGENCY NEWS >> Defense | NASA | Homeland Security | NIST | OMB | Veterans Affairs | NARA | GSA
Latest News
Free Newsletter
About | View Sample | Privacy
Popular Topics
Whitepapers
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
- Inside the Federal Cloud: Master the Challenges, Seizing the Opportunities
- End-of-life solution management for mobile devices reduces MNCs' security, compliance and sustainability risks
- The E-discovery Toolbox: What you should look for in a unified e-discovery solution
- Business Intelligence: It's All in the Data
- Virtual Game Changer
No easy solutions for VA information assurance
Information assurance isn't as simple as a contract clause requiring safeguards such as encryption and policies limiting access to personal data, Veterans Affairs Department officials told a House panel May 19.
Although such a clause has routinely been included in all VA contracts since November 2008, contractors may not necessarily follow it and even might have legitimate reasons for doing so.
"Many of the medical devices are certified by the FDA, in a particular configuration to operate in a certain way," said VA Chief Information Officer Roger Baker, speaking before the House Veterans' Affairs oversight and investigations subcommittee.
As a result, operating system patches and malware protection updates can't be routinely applied. A patch could also have unknown effects on the performance of medical devices, Baker said.
In his prepared testimony, Baker wrote that more than 122 medical devices have been infected by malware in the past 14 months. The VA mandated in 2009 that medical devices at VA medical facilities connected the VA network do so using a virtual local area network structure.
Much of the hearing was taken up by discussion of the VA's most recent electronic data loss incident, a VA contractor's stolen laptop containing personal data of 644 veterans.
Rep. Steve Buyer (R-Ind.), the senior Republican member of the Veterans Affairs committee and a force behind the 2006 law that gave the VA's CIO operational authority for networks across the entire department, laid at least some of the blame for the event at what he said is still a decentralized department.
The Veterans Health Administration "has done everything imaginable, in my personal opinion, to derail the centralized effort. They also have not been as forthcoming with security compliance and assurance as I think they should," Buyer said.
The VA should tie bonus payments to compliance with cybersecurity standards, Buyer said. "Boy, you can get somebody's attention pretty quick" by doing that, Buyer said. "We don't have to legislate that, the executive branch can lean forward on it," he added.
Some amount of data loss is inevitable, no matter how good cybersecurity standards may be, Baker said. However, he said that more information is now lost through paper documents rather than electronically.
A displaced binder containing records on 3,265 veterans records went missing from a Texas laboratory testing facility on April 24.
"Paper is slower, but paper is also harder to detect from an informational reach standpoint," Baker said.
For more:
- check out the hearing web page, complete with prepared testimony and a video recording
Related Articles:
Data loss deja vu at the VA
Industry group urges VA to embrace open source
Once unplugged, VA medical system needed a year to re-connect
Related Stories
- Auditors fault VA cybersecurity in teleradiology contracts
- VA reviews FOIA process after veteran record breach on Ancestry.com
- VA refines its security and privacy processes
- VA reports few data breach incidents in monthly report
- VA reports stolen laptops, BlackBerries and hints at health data policy changes
- VA caps iOS device deployment, eyes BYOD
- Audio: VA CIO Roger Baker's January IT report
- VA studies VistA refactoring
- Audio: VA CIO Roger Baker's November IT report
- Spotlight: Baker says no unauthorized iTunes on VA desktops
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |


