Investigators find VA employee, supervisors at fault in data loss

By Hope Yen, Associated Press Writer
Wednesday, July 12, 2006 | No comments posted.

Font Size: Shrink Font Enlarge Font | Submit your news
WASHINGTON - The Veterans Affairs data analyst who lost sensitive information on 26.5 million veterans showed poor judgment by taking the data home, but his supervisors are also to blame for lax policies, investigators said Tuesday.

The FBI has determined with a high degree of confidence that the sensitive files were neither compromised nor accessed, the VA announced. The bureau recently completed a full forensic analysis of the stolen laptop and external drive, which were recovered on June 29.

In a blistering report, Veterans Affairs inspector general George Opfer detailed a series of missteps, inadequate security measures and a general lack of concern in the events leading to the May 3 burglary at the data analyst's suburban Maryland home.

Opfer found that the data analyst, whose name was being withheld, did not have permission to take the data home and had stored the data on his personal equipment for a project that he initiated and worked on at home on his own time.

However, a chain of the employee's supervisors, leading up to Deputy Secretary Gordon Mansfield, unreasonably put veterans at risk by failing to publicize the May 3 burglary until nearly three weeks later, the report found. The laptop has since been recovered.

“At nearly every step, VA information security officials with responsibility for receiving, assessing, investigating or notifying higher-level officials of the data loss reacted with indifference and little sense of urgency or responsibility,” the report stated.

It urged VA Secretary Jim Nicholson to take “whatever administrative action” deemed appropriate to punish the individuals involved and prevent future data losses. “More needs to be done,” it said.

In his written response, Nicholson acknowledged the information weaknesses and pledged to turn the department around. “All employees will be held accountable for safeguarding the private information entrusted to us by veterans and beneficiaries,” he said.

Lawmakers immediately called on Nicholson to take decisive action. In recent weeks, two of the data analyst's supervisors, VA deputy assistant secretary Michael McLendon and Dennis Duffy, the acting head of the division in which the data analyst worked, have resigned or been put on administrative leave.

“The IG report released today on VA's data theft reiterated what we learned in our recent hearings - weak information security policies and a lack of central authority over information management left the department vulnerable to massive breaches,” said Rep. Steve Buyer, R-Ind., chairman of the House Veterans Affairs Committee.

Rep. Lane Evans of Illinois, the top Democrat on the panel, said the secretary “should follow up with bold and decisive administrative action.”

The theft, which involved names, birth dates and Social Security numbers of veterans and active-duty troops, spread fear of identity theft in what had become the government's worst information security breach.

According to the IG's report, the data analyst had received permission to take veterans' sensitive information home on a VA laptop since 2003. But in January, he turned in the government computer and began storing information on his personal laptop and external drive.

The employee, who had been praised in evaluations for outstanding work and for being “hardworking” and motivated, then began using the information for a work-related project on his own initiative without his supervisors' knowledge.

“The loss of VA data was possible because the employee used extremely poor judgment when he decided to take personal information pertaining to millions of veterans out of the office and store it in his house without password protecting and encrypting the data,” the report stated.

After the theft, the data analyst immediately notified an information security officer. But in a series of delays, the officer waited two days to write a report, which was then submitted to McLendon, who asked for a rewrite of the report and waited several days before telling his supervisor, Duffy.

By May 10, deputy secretary Mansfield and chief of staff Thomas Bowman had been told but waited for a legal assessment before finally informing Nicholson on May 16. The public was notified on May 22.

The report recommended a clear, concise VA policy on safeguarding protected information; a VA-wide policy for contracts for services that requires access to protected information; and consistent criteria for reporting, investigating and tracking reports of data thefts.

---

On the Net:

A copy of the report can be found at: http://www.va.gov/oig/
Tags »
Previous
Next

Have you checked out The World Link Forums?

Comments

The comments below are from users of theworldlink.com and do not necessarily represent the views of The World or Lee Enterprises. Participation Guidelines

Note: There is a maximum of 200 words per comment. If you wish to post more, please visit our forum.
Comment Policy

The World welcomes your comments about stories, and we encourage a robust dialogue on this site. All comments must meet reasonable standards of decency and civility.

Please follow these basic rules:

  • No defamatory comments about individuals or businesses.
  • No deliberately false information.
  • No obscenity or racially offensive language.
  • No harassment, verbal abuse, threats or personal attacks.
  • No information that invades another person's privacy.
  • No business solicitations or charitable solicitations.
Comments that violate these standards will not be posted. Users with repeated violations may be banned from future posting.

Comments will be approved throughout the day during business hours. After hours and weekend comments may not appear until the following business day. It may take a couple of hours before comments are approved.

The World generally does not edit comments, but we reserve the right to edit any comment that does not meet our standards.

Close Guidelines

No comments posted.


*Member ID:
*Password:
 

Not already registered?

Do not use usernames or passwords from your financial accounts!

Note: Fields marked with an asterisk (*) are required!



*Create a Member ID:
*Choose a password:
*Re-enter password:
*E-mail Address:
*Year of Birth:
 

(children under 13 cannot register)

*First Name:
*Last Name:
Would you like to be added to our mailing lists?
Daily Headlines
Breaking News
Special Offers
 
Advanced Search
Web Search powered by YAHOO! SEARCH

Blogroll

Most Popular

Polls

» View Past Poll Results
» Suggest a Poll

Marketplace

Special Sections

More Special Sections