Skip to main content
Research Paper Undergraduate 3,504 words

Cybercrime and Internet Security Risks at the VA Healthcare System

~18 min read 5 sections Technology · Internet Security
Abstract

This paper examines Internet-related security risks and cybercrime affecting the U.S. Department of Veterans Affairs (VA) and its Veterans Health Administration (VHA), the nation's largest integrated healthcare system. The paper reviews the VHA's organizational scope, documents major data breaches from 2002 through 2014, and analyzes the cybercrime landscape targeting sensitive veteran patient records. It explores the consequences of these breaches—including identity theft, financial fraud, and foreign intrusion—and evaluates the VA's responses, including encryption improvements, breach notification reforms, and the creation of a Data Breach Core Team. The paper concludes that, despite incremental progress, the VA remains systemically noncompliant with its own security protocols, making comprehensive reform essential to fulfilling its mission.

Key Takeaways
  • Introduction: VA mission, VHA scope, and paper overview
  • Overview of the Department of Veterans Affairs: VHA facilities, regional networks, and budget scale
  • Internet Risk at the Department of Veterans Affairs: Major breaches, attack statistics, and policy responses
  • Cybercrime at the Department of Veterans Affairs: Cybercrime definitions, motives, VA response mechanisms, and audit failures
  • Conclusion: Synthesis of findings and call for system-wide reform
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • Grounds abstract cybersecurity concepts in specific, well-documented real-world incidents, including exact breach dates, affected record counts, and estimated costs, which adds credibility and specificity to the argument.
  • Balances external scholarly sources with primary government documents (VA monthly congressional reports, OIG audits, OMB directives), demonstrating engagement with authoritative institutional evidence.
  • Uses a structured narrative arc—organizational overview, threat landscape, cybercrime analysis, institutional response, and critique—that builds logically toward the conclusion that systemic reform is necessary.

Key academic technique demonstrated

The paper demonstrates effective use of institutional documentation as evidence. By citing internal VA reports, congressional testimony, and federal audit findings alongside peer-reviewed scholarship, the author shows how primary government sources can be used to substantiate and reinforce an argument that an agency is failing its own stated standards—a technique well suited to policy-focused academic writing.

Structure breakdown

The paper opens with a dual introduction that situates the VA's mission and the security problem. A factual overview of the VHA's scale follows, grounding subsequent analysis in organizational context. The third section catalogues Internet-related breaches in chronological table format and traces their policy consequences. The fourth section defines cybercrime, surveys the broader threat environment, and evaluates the VA's internal response mechanisms. A focused conclusion synthesizes the findings and argues for system-wide reform. Total length is moderate, appropriate for an undergraduate policy analysis paper.

Essay 3,504 words

Introduction

The mission of the U.S. Department of Veterans Affairs (VA), drawn from President Lincoln's second inaugural address, is "To care for him who shall have borne the battle, and for his widow, and his orphan." To this end, this cabinet-level organization provides healthcare services through the Veterans Health Administration (VHA) to approximately nine million veteran patients each year. In an effort to improve the quality of these services, the VHA has implemented a number of technological solutions, including electronic healthcare records and a nationwide communication network. These solutions, however, have also introduced significant security risks, and several high-profile security breaches have drawn increased scrutiny to the VHA in recent years.

Through its Veterans Health Administration, the Department of Veterans Affairs is the largest healthcare provider in the United States, and millions of veteran patients receive care from its nationwide network of medical centers, outpatient clinics, and Vet Centers. In recent years, the VA has committed itself to improving the quality of patient care by implementing a wide range of technological solutions, including electronic healthcare records and a sophisticated communications system (Boyer, 2011). These same innovations, however, have introduced a number of security problems, including most especially the compromise of sensitive patient data. Although the VA is not unique in experiencing these problems, the fact that the organization is so large and its mission so critical makes these breaches an important issue for all stakeholders. This paper provides an overview of the VA and a critical analysis of the strategic approaches used to identify, analyze, and address cyber threats within the organization, taking into account the impact of managing risk throughout its operations.

Overview of the Department of Veterans Affairs

The VHA is the nation's largest integrated healthcare system, consisting of more than 1,700 healthcare facilities that provide care for nearly 9 million veteran patients annually (Veterans Health Administration, 2016). These facilities comprise the VHA's integrated services network of 23 divisions:

VISN 1: VA New England Healthcare System; VISN 2: VA Health Care Upstate New York; VISN 4: VA Healthcare – VISN 4; VISN 5: VA Capitol Health Care Network; VISN 6: VA Mid-Atlantic Health Care Network; VISN 7: VA Southeast Network; VISN 8: VA Sunshine Healthcare Network; VISN 9: VA MidSouth Healthcare Network; VISN 10: VA Healthcare System; VISN 12: VA Great Lakes Health Care System; VISN 15: VA Heartland Network; VISN 16: South Central VA Health Care Network; VISN 17: VA Heart of Texas Health Care Network; VISN 18: VA Southwest Health Care Network; VISN 19: Rocky Mountain Network; VISN 20: Northwest Network; VISN 21: Sierra Pacific Network; VISN 22: Desert Pacific Healthcare Network; VISN 23: VA Midwest Health Care Network (Veterans Health Administration, 2016).

Across these regions, the VHA operates 150 medical centers, almost 1,400 community-based outpatient clinics, community living centers, Vet Centers, and domiciliaries staffed by more than 53,000 healthcare practitioners (Veterans Health Administration, 2016). With an annual budget exceeding $182 billion (Annual budget submission, 2016), an enormous amount of resources has been allocated to the VA to fulfill its mission. The organization, however, has failed in this mission in a number of ways in recent years, including most especially the compromise of millions of patient data records.

Internet Risk at the Department of Veterans Affairs

Given its far-flung operations and thousands of employees, it is little wonder that the VA has experienced a number of Internet-related security breaches in recent years. Many of the risks associated with the Internet relate directly to the advantages the medium provides. As Eastmond (2004) cautions, "The Internet is indeed a technology of freedom—but it can free the powerful to oppress the uninformed, it may lead to the exclusion of the devalued by the conquerors of value" (p. 70). Notwithstanding these constraints, the Internet has introduced fundamental changes in the manner in which people work, live, recreate, and communicate. Ball, Haggerty, and Lyon (2012) report that "Digital technologies and the Internet have made the sharing and dissemination of information instantaneous and without restriction across geographical borders" (p. 58). These same technologies, however, introduce risks of data compromise and security breaches that can have devastating effects on individuals, organizations, and governmental agencies. As Barlow observed early on, "Cyberspace has a lot in common with the 19th Century West. It is vast, unmapped, culturally and legally ambiguous. . . . It is, of course, a perfect breeding ground for both outlaws and new ideas about liberty" (para. 4).

This assertion is certainly applicable to the VA. The organization reports that in December 2015 alone it blocked 181,188,372 intrusion attempts, blocked or contained 546,969,366 malware attacks, and filtered 100,778,911 suspicious or malicious emails (Monthly report to Congress of data incidents, 2015). Of these incidents, 394 veterans were affected in some fashion, including 47 cases involving lost or stolen electronic communication devices and 240 cases related to protected health information incidents reported to Health and Human Services in accordance with the Health Information Technology for Economic and Clinical Health (HITECH) Act (Monthly report to Congress of data incidents, 2015).

Some of the most severe Internet-related security breaches at the VHA include the following notable incidents:

Stolen Veterans Affairs laptop and hard drive (June 29, 2002): A laptop computer and hard drive containing sensitive data for more than 26 million veterans, their spouses, and active-duty military personnel was stolen but subsequently recovered by the FBI. Documents show that the VA had given permission in 2002 for an analyst—from whom the equipment was stolen—to work from home with data that included millions of Social Security numbers, disability ratings, and other personal information. The analyst was reportedly fired for violating agency procedure by taking the data home (Electronic Privacy Information Center, 2016, para. 2). According to Konkel (2013), then-VA Secretary was not notified about the incident until three weeks after it took place (para. 4).

Computers donated with patient data intact: A report concerning discarded hard drives and disk sanitization practices revealed that in August 2002, the United States Veterans Administration Medical Center in Indianapolis sold or donated 139 of its computers without removing confidential information from their hard drives, including the names of veterans with AIDS and mental illnesses (Matwyshyn, 2009, p. 107).

Personal information compromised (June 7, 2006): The personal information of approximately 1.1 million active-duty military personnel, 430,000 members of the National Guard, and 645,000 members of the Reserves was stolen in a theft of computer data from the VA. The agency had previously stated that all 26.5 million people affected were veterans and their spouses. The stolen data included Social Security numbers and disability ratings. The VA estimated it would cost between $100 million and $500 million to prevent and cover possible losses from the theft. Although the theft occurred on May 3, 2006, the VA waited until May 22 to inform those affected—a delay that represented just one of many failures by the agency in handling this incident (Electronic Privacy Information Center, 2016, para. 4).

Mismanaged software update (January 15, 2014): This breach occurred when a bungled software update to the VA's eBenefits system exposed at least 5,300 veterans' medical and financial information to the public (Konkel, 2014).

Contractor data breach (December 24, 2014): This breach placed more than 7,000 veterans at risk of identity theft. A potential flaw in a patient database managed by a vendor providing home telehealth services may have exposed the personal information of veterans. The contractor alerted the VA on November 4, 2014, of the potential security flaw. An investigation was immediately initiated and security scans were conducted, which confirmed the concern. The VA notified and offered credit protection to all 7,054 veterans in the database. The type of security flaw identified could have exposed veterans' data—including names, addresses, dates of birth, phone numbers, and VA patient identification numbers—via the Internet (Contractor security flaw puts data of 7,000 veterans at risk, 2014, para. 2).

The stolen laptop and hard drive incident resulted in fundamental changes in the manner in which the VA administers electronic patient data records and other digital communications, including:

A greater focus on data encryption. Since this high-profile breach occurred, more attention has been paid to encrypting data on laptops and other mobile devices.

Stronger breach notification guidelines. When breaches occurred prior to this incident, there were few formal internal processes for notifying incident response teams and administrators. The Office of Management and Budget's (OMB) guidelines now require, in most cases, that agencies notify management of data breaches immediately when they happen.

More attention to data retention, classification, and minimization. An OMB directive issued in the wake of the VA breach requires agencies to log all data extracts from databases holding sensitive information. Under the directive, they are also required to verify that extracted data is erased within 90 days or is still being used for valid purposes.

Stronger remote access policies. The OMB instructed the VA to implement two-factor authentication for controlling remote access to agency networks and data from remote locations. It also required remote users to re-authenticate themselves after 30 minutes of inactivity. In addition, the VA breach resulted in more focus on securing remote systems through the use of endpoint network admission control tools to ensure that any system logging into a network has adequate antivirus and firewall protections, all mandated configuration settings, and is properly patched (Vijayan, 2007, para. 2–4).

In addition, other security breaches involving the VHA have included hacking, the inadvertent disclosure of confidential data, and the deliberate misuse of information by unauthorized individuals (Matwyshyn, 2009). Like other large organizations, the VHA is also at risk for security breaches that are particularly difficult to identify and counter. As Matwyshyn (2009) points out, "The threats to information security are varied: for example, search engines increasingly index Web pages that may not be meant for public consumption, and employee use of file-sharing software exposes many different kinds of files to communication networks" (p. 33).

Although the VA has taken steps to address these security threats, major lapses in human judgment and employee theft are exceedingly difficult to address until something drastic occurs to draw attention to them. As Matwyshyn emphasizes:

Data security is never perfect, and government agencies cannot perfectly predict security lapses. But the growing number of news stories about compromised personal records reveal a wide range of organizational mismanagement and internal security breaches: lost hard drives and backup tapes, employee theft, and other kinds of administrative errors. (2009, p. 33)

The implications of these security breaches are far-ranging and severe. The compromise of sensitive patient data can be carried out by physicians, nurses, healthcare employees, and even organized crime syndicates (Matwyshyn, 2009). In some cases, the theft of patient data can result in credit card fraud and other types of identity theft that can cost veterans and their families billions of dollars each year (Matwyshyn, 2009).

More troubling still, a confidential report from the VA's Office of Information and Technology Risk Management obtained by CNBC predicted that "A data breach to financial, medical and personal information is practically unavoidable [and] is likely to happen within 12 to 18 months" (cited in Gusovsky, 2014, para. 3). The report also cautioned that "The VA cannot ensure the safety and privacy of Veteran and employee healthcare, benefits, and financial information. The VA is non-compliant with its own privacy and security policies and with Federal laws and regulations" (cited in Gusovsky, 2014, para. 3).

Besides this damning report, additional information technology security issues were identified during congressional testimony in June 2014 by Jerry Davis, former deputy assistant secretary for information security at the VA. According to Davis's testimony, "In nearly 20 years of building and managing security programs across government and private industry, I had never seen an organization with as many unattended IT security vulnerabilities" (cited in Gusovsky, 2014, para. 6). The June 2014 congressional hearing also revealed that the VA had been hacked numerous times by foreign actors since March 2010 (Gusovsky, 2014). One congressman reported that "the VA's database has repeatedly been compromised since 2010 by foreign actors, including in China and possibly in Russia" (cited in Gusovsky, 2014, para. 7). In fact, between March 2010 and February 2014, there were at least eight major security breaches of the VA's network, including the "Master Password" file (Gusovsky, 2014).

Given these serious concerns, it is reasonable to suggest that there is a "perfect storm" brewing at the VHA that will have serious consequences for the organization and its stakeholders. Further exacerbating the risks inherent in using the Internet and digital devices for patient data records are the growing numbers of cybercriminals who exploit this environment for a wide range of illegal and illicit purposes.

1 Section Hidden · 730 words
Cybercrime at the Department of Veterans Affairs730 words
According to Glennon (2012), "The term cybercrime has been used broadly to describe a wide range of activities, from illegal interference and illegal access to the misuse of devices and content-related offenses" (p. 86). As noted above, the VHA experiences millions of cyber-attacks each…

Conclusion

The research was consistent in showing that the Internet provides healthcare organizations such as the Veterans Health Administration with a wide range of advantages and tools that can be used to facilitate and improve patient care. These same advantages and tools, however, can be used to compromise patient data records in ways that can wreak havoc on the lives of affected veterans. The research also showed that the threat of cybercrime is real and all signs indicate that it is growing, making compliance with the VA's own data security policies and protocols an essential first step in addressing these system-wide problems. Based on the testimony of industry experts and the findings of congressional oversight committees, it is reasonable to conclude that the data security environment at the VA will continue to erode unless and until the organization takes the steps needed to ensure that patient data is fully protected.

Annual budget submission. (2016). Department of Veterans Affairs. Retrieved from http://www.va.gov/budget/products.asp.

Ball, K., Haggerty, K., & Lyon, D. (Eds.) (2012). The Routledge handbook of surveillance studies. London: Routledge.

Barlow, J. P. (1990). Crime and puzzlement. Retrieved from

Bell, D. (2001). An introduction to cybercultures. London: Routledge.

Boyer, K. (2011, October–November). The technology promise: Widespread use of electronic medical records promises to transform health care: but can we afford it? State Legislatures, 37(9), 20–22.

Brenner, S. (2001). Is there such a thing as "virtual crime"? California Criminal Law Review, 4(1), 105–111.

Contractor security flaw puts data of 7,000 veterans at risk. (2014, December). Federal News Radio. Retrieved from http://federalnewsradio.com/defense/2014/12/contractor-security-flaw-puts-data-of-7000-veterans-at-risk/.

Electronic Privacy Information Center. (2016). EPIC. Retrieved from https://epic.org/privacy/vatheft/.

Glennon, M. J. (2012, February–March). State-level cybersecurity. Policy Review, 171, 85–87.

Gusovsky, D. (2014, February 20). VA data breach 'practically unavoidable,' memo says. CNBC. Retrieved from

Halliday, L. A. (2015, May 19). Department of Veterans Affairs Federal Information Security Management Act audit for fiscal year 2014. Department of Veterans Affairs. Retrieved from

Inan, F. A. & Namin, A. S. (2016, January). Internet use and cybersecurity concerns of individuals with visual impairments. Educational Technology & Society, 19(1), 28–31.

Konkel, F. (2013, August 21). How the VA deals with data breaches. FCW. Retrieved from

Konkel, F. (2014, January 27). Latest breach at VA has Congress asking more questions. FCW. Retrieved from

Matwyshyn, A. M. (2009). Harboring data: Information security, law, and the corporation. Stanford, CA: Stanford University Press.

Monthly report to Congress of data incidents. (2015, December). Department of Veterans Affairs. Retrieved from http://www.va.gov/ABOUT_VA/docs/monthly_rfc_Dec2015.pdf.

Snell, E. (2016, March 15). Top 5 healthcare data breaches in 2016 not from hacking. Health IT Security. Retrieved from http://healthitsecurity.com/news/top-5-healthcare-data-breaches-in-2016-not-from-hacking.

Tuluc, A. M. (2012). Economic processes associated with the cybercrime industry. Economics, Management and Financial Markets, 7(2), 180.

Veterans Health Administration. (2016). Department of Veterans Affairs. Retrieved from http://www.va.gov/health/.

Vijayan, J. (2007, June 1). One year later: Five lessons learned from the VA data breach. ComputerWorld. Retrieved from http://www.computerworld.com/article/2541516/security0/one-year-later--five-lessons-learned-from-the-va-data-breach.html?page=3.

Key Concepts in This Paper
Data Breach Veterans Health Administration Cybercrime Patient Privacy Identity theft Federal Cybersecurity Electronic Health Records Information Security Breach Notification Foreign Intrusion
Cite This Paper
PaperDue. (2026). Cybercrime and Internet Security Risks at the VA Healthcare System. PaperDue. https://www.paperdue.com/study-guide/cybercrime-internet-security-va-healthcare-2158301

Always verify citation format against your institution’s current style guide requirements.