Breadcrumb

Improper Sharing of Sensitive Information on Cloud-Based Collaborative Applications

Report Information

Issue Date
Report Number
24-01330-29
VA Office
Information and Technology (OIT)
Report Author
Office of Audits and Evaluations
Report Type
Review
Report Topic
Information Technology and Security
Major Management Challenges
Information Systems and Innovation
Recommendations
6
Questioned Costs
$0
Better Use of Funds
$0
Congressionally Mandated
No

Summary

Summary

The OIG received a hotline allegation from a VA medical center employee regarding the improper sharing of sensitive information on VA’s internal network. The complainant reported that an employee could search for fellow employees on the internal network and find documents and emails that contained sensitive personal information. Among these documents were human resources paperwork, such as interview questions and reference checks, performance awards, and personally identifiable information for veterans getting surgery.

The OIG confirmed sensitive personal information was accessible by VA users who had no business need to access it. Furthermore, the OIG noted that the type of sensitive personal information accessible should not have been hosted on the systems it was found on, as the information exceeded the systems’ security authorizations. The OIG determined this was a national issue because the hosting systems are cloud based and the information was observable by any authorized VA employee, regardless of location.

To address the reasons for the improper sharing, the OIG recommended that the assistant secretary for information and technology 
   •    ensure facilities and programs remove unauthorized sensitive personal information from collaborative application sites such as SharePoint; 
   •    direct facilities and programs to standardize SharePoint administration, inventory and consolidate their SharePoint sites; 
   •    implement enforcement mechanisms such as recommended architecture to allow greater control of permissions and content; 
   •    expand roles and responsibilities for privacy officers and information system security officers; 
   •    implement automated tools to detect and correct improper sharing agencywide; and 
   •    mandate standardized training for SharePoint administrators and owners. 

The assistant secretary concurred with all recommendations, and the OIG agreed to close two recommendations after VA provided sufficient evidence of implementation. The four other recommendations remain open.

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Open Recommendation Image, Square
to Information and Technology (OIT)

Take corrective actions to ensure that facilities and programs remove unauthorized sensitive information from collaborative application sites.

No. 2
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 4/22/2025

Direct facilities and programs to standardize SharePoint administration, inventory and consolidate their SharePoint sites, and enforce the recommended architecture to better control access and content at the facility or program level.

No. 3
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 4/22/2025

Implement enforcement mechanisms to ensure that facilities and programs are following standardized processes to secure SharePoint and Teams sites.

No. 4
Open Recommendation Image, Square
to Information and Technology (OIT)

Expand roles and responsibilities of facility and program information system security officers and privacy officers to include the routine review of SharePoint and Teams site permissions and content.

No. 5
Open Recommendation Image, Square
to Information and Technology (OIT)

Implement automated tools and policies, supported with training, to enable the timely and routine detection and correction of improper sharing and unauthorized content throughout VA.

No. 6
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 8/13/2025

Mandate standardized training for SharePoint administrators and owners to clarify and reinforce data security requirements.