Why It Matters
Millions of service members and veterans rely on a single federal electronic health record system to receive care, but a recent Government Accountability Office report found that the federal agencies managing this critical infrastructure are not fully following leading practices for interagency collaboration to protect the system as cyberattacks increase across the health care sector.
The federal electronic health record system supports health care for millions of service members and veterans across four federal agencies, the Department of Defense, the Department of Veterans Affairs, the U.S. Coast Guard, and the National Oceanic and Atmospheric Administration. The system is housed in a data center referred to as the federal enclave. DOD holds primary responsibility for ensuring the cybersecurity of the federal electronic health record.
The Big Picture
The Federal Electronic Health Record Modernization office, a joint DOD and VA office, facilitates collaboration among the federal agencies. A GAO investigation mandated by Congress through the Further Consolidated Appropriations Act, 2024, identified gaps in how the agencies work together to defend the system and protect its data.
GAO reviewed interagency agreements, agency cybersecurity and privacy policies, and interviewed officials from the participating agencies. GAO also compared the Federal Electronic Health Record Modernization office’s collaboration efforts with leading practices for interagency collaboration. GAO found that the office has not fully followed those practices and has not fully articulated specific or common goals or outcomes related to the cybersecurity of the electronic health record or the privacy of data within it.
The Federal Electronic Health Record Modernization office also reported that it did not have related performance measures for monitoring progress toward cybersecurity and privacy outcomes.
The Federal Electronic Health Record Modernization office is a joint DOD-VA decision-making authority with requirements set by Congress and is responsible for providing direction and oversight on joint functions. The office initiates joint activities to enhance the security of the system and works to improve interagency cybersecurity and privacy collaboration by providing opportunities for partner agencies to coordinate.
What They’re Saying
GAO made two recommendations to address the gaps, one to DOD and one to VA. Both recommendations call for the Federal Electronic Health Record Modernization office to define common goals, outcomes, and associated performance measures and to monitor, assess, and communicate progress on collaboration efforts to ensure the cybersecurity and privacy of the federal enclave.
DOD disagreed with the GAO report and its recommendation. VA neither agreed nor disagreed with its recommendation. GAO maintains that both recommendations are valid.
The Bottom Line
The Government Accountability Office made two recommendations to address the gaps, one to the Department of Defense and one to the Department of Veterans Affairs. Both recommendations direct the Federal Electronic Health Record Modernization office to define common goals, outcomes, and associated performance measures, and monitor, assess, and communicate progress on collaboration efforts toward ensuring the cybersecurity and privacy of the federal enclave.
The Department of Defense disagreed with the GAO report and its recommendation. The Department of Veterans Affairs neither agreed nor disagreed with the recommendation. Both recommendations remain open, meaning actions to satisfy the intent of the recommendations have not been taken or are being planned.
In the meantime, cyberattacks on health care systems are increasing, placing the federal electronic health record system and the patient information it stores at risk.
Spot something wrong? Report an issue with this article