atotrade-pressNewsThe Broadside2 min read

VA OIG raises PATS-R risk after low-risk cloud review

A medical-records access path does not become low impact because most users say they do not need it.


TL;DR

FedScoop reports that the VA Office of Inspector General found the Patient Advocate Tracking System-Replacement was wrongly categorized as low risk after its November 2023 cloud transfer, despite access to veteran medical records. VA’s IT office raised PATS-R to moderate after March 2025 preliminary findings. Assessors and agency CISOs should notice the harder point: access controls and user reviews, not the label, are where the audit found the real exposure.

FedScoop, citing a VA Office of Inspector General report released Tuesday, says the Department of Veterans Affairs’ IT office treated the Patient Advocate Tracking System-Replacement as a low-risk system after a November 2023 transfer to the cloud and the Office of Strategic Initiatives. That label mattered because PATS-R, used by Veterans Health Administration staff to document communications with veterans, also provided access to patient medical records. The OIG said the low-risk categorization potentially jeopardized the confidentiality, integrity and availability of veterans’ data.

The operational problem is not subtle. Low impact assumes a limited adverse effect if confidentiality, integrity or availability is lost. The OIG found that assumption did not fit a system with medical-record access. VA’s Office of Information and Technology raised the system to moderate after preliminary findings in March 2025, and VA concurred with the recommendations. The OIG has already closed the recommendation tied to the higher risk categorization.

That does not make the access problem go away. The OIG said moderate risk may still be insufficient because access controls were not working as intended and the program office was not consistently reviewing whether users were authorized for PATS-R based on their roles. The user survey makes the risk posture look even stranger: 77% of sampled users said they did not know they could use PATS-R to view veteran medical records, while 89% said losing that access would not affect their job responsibilities.

For assessors, this is the part worth clipping. The audit is a cloud-migration control failure before it is a paperwork error. If a system inherits moderate-to-high controls as a minor application under Microsoft Azure Services, as VA said PATS-R now does, the inheritance still has to meet the actual business function and access pattern. A risk category can be corrected in a memo. Excess medical-record access, weak user reviews and delayed automated deactivation are implementation defects, and those are the defects that become report findings when the label stops protecting the system owner.


Published ·Deep Fathom