A VA Office of Inspector General (OIG) information security audit of the VA Spokane Healthcare System (including the Mann-Grandstaff VA Medical Center) identified control weaknesses that could put sensitive data at risk, citing deficiencies in configuration management, vulnerability management, and access controls. The audit findings indicate gaps in how systems are securely configured, how vulnerabilities are identified/remediated, and how user access is governed.
The Spokane VA system initiated an action plan to address the OIG recommendations, and the report noted that some corrective actions had already been implemented. The audited environment is also operating within the VA’s broader electronic health record (EHR) modernization effort, with Spokane described as one of several VA healthcare systems using the newer federal EHR platform as the department plans additional rollouts in 2026—raising the operational importance of consistent hardening, patching, and access governance during modernization.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
Following the audit findings, the OIG issued seven recommendations to address the identified security gaps. The Spokane system initiated an action plan to implement the recommendations, with some corrective actions already completed.
A VA Office of Inspector General information security audit found deficiencies at the VA Spokane Healthcare System, including weak configuration management, vulnerability management, access controls, and physical security that could expose sensitive data. Auditors also found some users retained unnecessary access in the federal EHR to screens containing unredacted personally identifiable information.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.