{"id":765,"date":"2022-08-23T12:44:00","date_gmt":"2022-08-23T16:44:00","guid":{"rendered":"https:\/\/digital.va.gov\/ehr-modernization\/?p=765"},"modified":"2026-08-12T09:51:44","modified_gmt":"2026-08-12T13:51:44","slug":"va-has-the-veterans-back-when-it-comes-to-cybersecurity-and-data-privacy","status":"publish","type":"post","link":"https:\/\/digital.va.gov\/ehr-modernization\/news-stories\/va-has-the-veterans-back-when-it-comes-to-cybersecurity-and-data-privacy\/","title":{"rendered":"VA has the Veteran\u2019s back when it comes to cybersecurity and data privacy"},"content":{"rendered":"\n<p>With few exceptions, most of us are online. That means our personal information, including personal health information (PHI), is online, too. As VA transitions to a new Electronic Health Record (EHR) system \u2015 the software that stores health information and tracks patient care \u2014\u00a0<a href=\"https:\/\/digital.va.gov\/ehr-modernization\/frequently-asked-question\/\" target=\"_blank\" rel=\"noreferrer noopener\">security of PHI<\/a>\u00a0is a critical element.<\/p>\n\n\n\n<p>Protecting PHI is part of Duc Nguyen\u2019s (DOOK N-win) job as director of the Electronic Health Record Modernization Integration Office (EHRM IO) Joint Cyber Operations Integration Center (JCOIC). Nguyen and his team are responsible for ensuring all interfaces and components of the EHR system comply with VA policies for cybersecurity and data privacy.<\/p>\n\n\n\n<p>\u201cIn this day and age, cybersecurity and privacy go hand in hand,\u201d Nguyen said, \u201cand we have an obligation to safeguard Veteran health care information. Those who have served can feel confident that we are taking these issues seriously.\u201d<\/p>\n\n\n\n<p>Certain segments of VA\u2019s records are already online, of course, but&nbsp;<a href=\"https:\/\/www.ehrm.va.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">EHR modernization<\/a>, which began in 2018 and, as of July 29, 2022, has been implemented at five VA medical centers, represents a multiyear process that will provide seamless care to those who served. That connectivity touches millions of people \u2015 from clinicians and administrators to Veterans themselves.<\/p>\n\n\n\n<p>The EHR\u2019s advanced cybersecurity protocols are deeply rooted in the principals of the&nbsp;<a href=\"https:\/\/www.cdc.gov\/phlp\/publications\/topic\/hipaa.html#:~:text=The%20Health%20Insurance%20Portability%20and,the%20patient&#039;s%20consent%20or%20knowledge.\" target=\"_blank\" rel=\"noreferrer noopener\">Health Insurance Portability and Accountability Act (HIPAA)<\/a>, the 1996 legislation that established national standards for the protection of PHI, as well as in the&nbsp;<a href=\"https:\/\/www.nist.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">National Institute Standards and Technology (NIST)<\/a>&nbsp;cybersecurity standards and best practices.<\/p>\n\n\n\n<p>Regarding such standards, Marvin Marin, who is part of JCOIC\u2019s leadership team noted, \u201cHIPAA surrounds us, and we incorporate it in every process, every step, both from an operations perspective and from a cyber perspective.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">An eye on every record<\/h2>\n\n\n\n<p>In a first step toward full integration of health records between the Department of Defense (DoD) and VA, in 2019, VA transferred the health records of some 23.5 million Veterans into the new EHR system. Now, by design, VA\u2019s EHR connects with similar health data systems at DoD and the Department of Homeland Security\u2019s U.S. Coast Guard, as well as with hundreds of community hospitals and clinics nationwide. That\u2019s a lot of points of access.<\/p>\n\n\n\n<p>But every one of those points of access is being vigilantly guarded by VA. Suzanne Leach is also on the JCOIC team, and part of her role is to make sure that each one has what is called an \u201cauthority to connect.\u201d Simply put, that means when a person or another system tries to communicate with the EHR, VA knows who or what is behind the attempt.<\/p>\n\n\n\n<p>Nguyen, Marin, Leach and the cybersecurity teams at VA and DoD \u2014 as well as the software itself \u2014 are always watching for what are commonly called \u201cbad actors,\u201d people or entities who pose threats that can take the form of&nbsp;<a href=\"https:\/\/www.oit.va.gov\/news\/article\/?read=doing-your-part-protecting-health-care-data\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware<\/a>,&nbsp;<a href=\"https:\/\/digital.va.gov\/security-excellence\/hook-line-and-sinker\/\">phishing emails<\/a>&nbsp;and other incursions.<\/p>\n\n\n\n<p>The new EHR system includes built-in technologies that watch for that kind of unauthorized activity. \u201cThe auditing and monitoring systems will flag if there\u2019s any sort of erroneous update to a patient record,\u201d Marin added. \u201cThen those records are reviewed manually to make sure that nothing impacts patient care.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Protecting with passion<\/h2>\n\n\n\n<p>With technology and cyberthreats always changing, the JCOIC team is committed to staying in front of issues before they arise.<\/p>\n\n\n\n<p>\u201cCybersecurity needs to be ever evolving,\u201d Leach said, returning to the value of the continuous monitoring built into the new EHR system. At VA, it is. And using these and other safeguards, the cybersecurity team is actively scanning and protecting the data environment, watching for new and persistent threats and working to deny bad actors any access to Veterans\u2019 data.<\/p>\n\n\n\n<p>\u201cWe don\u2019t see this as work,\u201d Marin said. \u201cWe see this as, I guess, passionate work. Cybersecurity professionals really embrace this mission.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>With few exceptions, most of us are online. That means our personal information, including personal health information (PHI), is online, too. As VA transitions to a new Electronic Health Record (EHR) system \u2015 the software that stores health information and tracks patient care \u2014 security of PHI is a critical element. <\/p>\n","protected":false},"author":1,"featured_media":786,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[27],"class_list":["post-765","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-stories","tag-cybersecurity"],"meta_box":{"external_links":"0","endorsement":"0","subheading":"","byline":"","author_title":"","external_source":"","external_source_url":""},"_links":{"self":[{"href":"https:\/\/digital.va.gov\/ehr-modernization\/wp-json\/wp\/v2\/posts\/765","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digital.va.gov\/ehr-modernization\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digital.va.gov\/ehr-modernization\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digital.va.gov\/ehr-modernization\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digital.va.gov\/ehr-modernization\/wp-json\/wp\/v2\/comments?post=765"}],"version-history":[{"count":7,"href":"https:\/\/digital.va.gov\/ehr-modernization\/wp-json\/wp\/v2\/posts\/765\/revisions"}],"predecessor-version":[{"id":3949,"href":"https:\/\/digital.va.gov\/ehr-modernization\/wp-json\/wp\/v2\/posts\/765\/revisions\/3949"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digital.va.gov\/ehr-modernization\/wp-json\/wp\/v2\/media\/786"}],"wp:attachment":[{"href":"https:\/\/digital.va.gov\/ehr-modernization\/wp-json\/wp\/v2\/media?parent=765"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digital.va.gov\/ehr-modernization\/wp-json\/wp\/v2\/categories?post=765"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digital.va.gov\/ehr-modernization\/wp-json\/wp\/v2\/tags?post=765"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}