Sorry, you need to enable JavaScript to visit this website.
Skip to main content
Report File
Date Issued
Submitting OIG
Department of Veterans Affairs OIG
Agencies Reviewed/Investigated
Department of Veterans Affairs
Components
Veterans Health Administration
Report Number
24-00568-38
Report Description

The VA Office of Inspector General (OIG) conducted an inspection to evaluate allegations concerning patients’ data security and related oversight practices within the national cancer prevention, treatment, and research program and Office of Research & Development (ORD). The OIG identified additional concerns related to a Veterans Health Administration (VHA) project not submitted to an Institutional Review Board (IRB) and the process for reviewing a protected health information (PHI) breach.

The OIG did not substantiate that the national cancer prevention, treatment, and research program Executive Director categorized projects as operational to bypass IRB review. However, the OIG found that a collaborative project between VHA and non-VHA investigators was not submitted to a VHA IRB for approval. 

The OIG substantiated that the Executive Director of Operations for a national cancer testing program and project staff did not deidentify a data file before sharing with non-VHA investigators. The OIG review of the data file found a significant amount of data containing PHI. The Executive Director of Operations also did not recognize the extent of PHI disclosed. 

The OIG did not substantiate that the Executive Director of Operations for a national cancer testing program and an ORD privacy officer did not take action to review privacy concerns of a potential breach of PHI (privacy event). However, the privacy officer did not enter the privacy event into the tracking system or report the event to a VHA privacy officer timely. The Data Breach Response Service director reviewed the privacy event and determined it was not a data breach.

The OIG made six recommendations for VHA to ensure IRB review of the project and corrective actions address issues for determination of research project designation, privacy reporting and data disclosure, and national cancer prevention, treatment and research program staff receive training on IRB submission and privacy requirements.

Report Type
Review
Agency Wide
Yes
Number of Recommendations
6
Questioned Costs
$0
Funds for Better Use
$0
Report updated under NDAA 5274
No

Open Recommendations

This report has 6 open recommendations.
Recommendation Number Significant Recommendation Recommended Questioned Costs Recommended Funds for Better Use Additional Details
01 No $0 $0

The Executive Director of Operations for a national cancer testing program ensures the project has met the requirements for Institutional Review Board review for research with human subjects and takes action as needed.

02 No $0 $0

The Executive Director of Operations for a national cancer testing program ensures national cancer prevention, treatment, and research program staff are trained on Institutional Review Board project submission and privacy requirements.

03 No $0 $0

The National Specialty Care Program Office Chief Officer ensures the national cancer prevention, treatment, and research program staff reviews and provides required approvals before the release of protected health information for research.

04 No $0 $0

The National Specialty Care Program Office Chief Officer, in conjunction with the Office of Research & Development ensures that VA privacy officers report privacy incidents involving data obtained from or for national cancer prevention, treatment, and research program activities timely and monitors for compliance.

05 No $0 $0

The Office of Research Oversight Executive Director in conjunction with the Chief Research and Development Officer, VHA Office of Research & Development, reviews the national cancer prevention, treatment, and research program final mitigation plan and ensures corrective actions address system-wide issues for determining whether a national cancer prevention, treatment, and research program project constitutes research, safeguarding privacy when data is shared for projects, and ensuring data security requirements are met.

06 No $0 $0

The National Specialty Care Program Office Chief Officer ensures the national cancer prevention, treatment, and research program has safeguards in place including biostatistician expertise to ensure that data containing sensitive patient information and protected health information is deidentified before sharing outside of VA as required.

Department of Veterans Affairs OIG

United States