St. Petersburg Times
Special report
Video report
  • For their own good
    Fifty years ago, they were screwed-up kids sent to the Florida School for Boys to be straightened out. But now they are screwed-up men, scarred by the whippings they endured. Read the story and see a video and portrait gallery.
  • More video reports
Multimedia report
Print Email this storyEmail story Comment Email editor
Fill out this form to email this article to a friend
Your name Your email
Friend's name Friend's email
Your message
 

VA data security falls short

By WILLIAM R. LEVESQUE
Published March 19, 2007


ADVERTISEMENT

The theft last year of a laptop containing personal data on more than 26-million veterans left the Department of Veterans Affairs embarrassed and promising reform.

In January, it happened again.

With the medical care of wounded soldiers dominating headlines in recent weeks, a lesser storm involving the VA's failure to protect veterans' personal information is quietly gaining strength.

Veterans advocates are clamoring for action, bipartisan congressional critics are zeroing in, and the VA's top official has acknowledged frustration with his agency's ineptness with computers.

On top of it all, the VA told Congress last week that it needs at least $15.1-million to cover costs associated with the latest data breach.

The case involves a computer hard drive with billing information for 1.3-million doctors and more than 500,000 veterans that was either stolen or misplaced from a VA research facility in Birmingham, Ala.

"It is now clear to me that there are still too many VA employees ... who still do not comprehend the seriousness of this issue," VA Secretary R. James Nicholson wrote in a recent memo.

Bradenton Army veteran Dewell Crews, 51, whose name was likely among the 26-million, was more blunt:

"Can't the VA get anything right?" he asked.

In the theft last May and in the January case, the missing data included Social Security numbers, raising the prospect of identity theft.

The laptop stolen last May eventually was recovered with no apparent criminal use of its data. A worker had taken home the laptop, which included information on every veteran discharged since 1975.

The hard drive in Alabama is still missing, though early reports indicated the data hadn't been used criminally. A national VA spokesman did not respond to repeated calls for comment.

A bigger question is why the data on that drive was unprotected, particularly after the VA spent nearly $4-million to encrypt its computer data after last year's burglary.

The VA has said it will notify affected veterans. Meanwhile, it has suggested that veterans closely monitor their credit, even offering free credit report monitoring if their personal information has been compromised.

The VA is operating a call center where veterans can get information about the Birmingham incident. Veterans can call toll-free 1-877-894-2600.

Carolyn Clark, a spokeswoman for the James A. Haley VA Medical Center in Tampa, the nation's busiest VA medical facility, said in a statement that new safeguards have been implemented since Birmingham, including restrictions on data being allowed outside facilities.

That does little to assuage the anxiety among veterans.

"Nicholson's made a mess of everything," said Bill Geden, 65, a Citrus County resident who is district director of the Blinded Veterans Association's chapter for west-central Florida. "The data's not protected at all. The message they're sending is: Don't join the military. It's real simple."

The VA's office of inspector general said five key recommendations it made after last May's incident are still unaddressed, including a clear and consistent policy for investigating and tracking incidents of data loss.

"It seems to me there is a lack of willpower to enforce data security at the VA by top administrators and a Paleolithic civil service hiring and firing system that lets employees who violate the data security guidelines keep their jobs," Rep. Ginny Brown-Waite, R-Brooksville, said in a statement after a Feb. 28 congressional hearing on the issue.

How often information is lost or misused by the VA remains unclear. The VA's Security Operations Center has referred 250 incidents since July 2006 to its inspector general, which has led to 46 separate investigations.

In one of the few incidents to make the news late last year, a computer disk containing personal information on 1,400 Oklahoma veterans was lost in the mail. But the magnitude of most cases has not been made public.

The VA faces a pending class-action lawsuit in Washington from veterans and advocacy groups trying to force court oversight of the VA's data protection, a suit filed after the May incident. A plaintiff's lawyer said the suit may be enlarged to include the Alabama loss.

"The VA's taken a pretty haughty tone" about why oversight isn't necessary, said attorney Doug Rosinski. "But there's no longer a barn door. There is no door. There is no barn. There are just random pieces of wood lying around the farm."

William R. Levesque can be reached at levesque@sptimes.com or (813) 226-3436.

[Last modified March 19, 2007, 01:22:17]


Share your thoughts on this story

Comments on this article
by YetAnotherVictim 04/02/07 09:56 AM
There *is* no VA Security Operations Center anymore - VACO abused the contract on what could have been a world class security operation and wasted 91 million dollars on hardware; the contract managers constantly playing golf with the vendors.
by Gary 03/22/07 04:28 PM
I have not see a democrat yet that has had a good idea about anything . you can't blame Bush if you stub your toe. He is not doing a good job, but Al Gore and the other demo. dummy's are worse.(much worse)!!
by Concerned 03/20/07 09:02 AM
I am sick of people blaming Bush for everything! GROW UP. I suppose Bush is responsible for the CA wildfires and bad weather too. Yes problems need to be addressed, but whining won't fix anything.
by Vet for peace 03/20/07 07:13 AM
This sorry chapter in American history offers yet another look at Bush's inept management style. We have all been betrayed again by his inaction. Maybe he styled his entire life around his "deserter" status he achieved as a young man, never to return
by Ken 03/19/07 08:07 AM
My comment is the VA cannot get anything right. Their employee's have terrible attitude problems and they think they are doing veterans "a favor" by just showing up to work in the morning.
by Tom 03/19/07 04:49 AM
Demand that the corrupt Bushie chrony Secretary Jim Nicholson be fired. Then demand the impeachment of Bush and Cheney
by Veteran 03/19/07 03:34 AM
Who ever is behind this is also using medical records to spam veteran's emails with "alternative" medical treatments (non-western). Examples include rubbing semi-precious stones on and and coercing them to sign power of attorneys as a "cure."
by Jay 03/19/07 02:23 AM
Once again we see the total incompetence of the VA and it's leader Jim Nicholson. My feeling are that this will not change until we have a Democratic President in 2008. Republicans do not support the troops, they consider Veterans an an expense.
Subscribe to the Times
Click here for daily delivery
of the St. Petersburg Times.

Email Newsletters

ADVERTISEMENT