VA avoids standards to deploy mobile Apple products

Mobile Phones - 28.44 Kb
In response to a confidential hotline allegation, the U.S. Department of Veterans Affairs' Office of Inspector General (VA OIG) has issued its report evaluating whether the VA’s approach for information system certification and storing sensitive data on Apple mobile devices circumvents information security requirements.

Sen. Jon Kyl (R-Ariz.) also requested that the VA OIG evaluate whether VA’s approach for only storing sensitive data on encrypted mobile device applications meets Federal Information Security Management Act of 2002 (FISMA) requirements.

“We determined VA was not circumventing FISMA certification and accreditation requirements by suspending security control testing and granting operational waivers for existing information systems,” according to information posted on the organization’s website. “We also determined that VA’s approach for allowing only certified applications to access sensitive data or storing encrypted data on the mobile device met FISMA information security requirements for data protection.”

The VA OIG noted, however, that VA could improve management controls by ensuring an accurate inventory and consistent configuration of mobile devices deployed enterprisewide.

The VA OIG made the following two recommendations:
  1. The assistant secretary for information and technology implement minimally acceptable baseline security configuration requirements for VA mobile devices in accordance with FISMA.
  2. The assistant secretary centrally manage the distribution of VA mobile devices to ensure they are accurately inventoried and configured in accordance with minimum security standards.

The assistant secretary for information and technology concurred with the findings and recommendations, according to the agency. The entire review is available on the VA OIG website.

Beth Walsh,

Editor

Editor Beth earned a bachelor’s degree in journalism and master’s in health communication. She has worked in hospital, academic and publishing settings over the past 20 years. Beth joined TriMed in 2005, as editor of CMIO and Clinical Innovation + Technology. When not covering all things related to health IT, she spends time with her husband and three children.

Around the web

GE HealthCare designed the new-look Revolution Vibe CT scanner to help hospitals and health systems embrace CCTA and improve overall efficiency.

Clinicians have been using HeartSee to diagnose and treat coronary artery disease since the technology first debuted back in 2018. These latest updates, set to roll out to existing users, are designed to improve diagnostic performance and user access.

The cardiac technologies clinicians use for CVD evaluations have changed significantly in recent years, according to a new analysis of CMS data. While some modalities are on the rise, others are being utilized much less than ever before.