The Department of Veterans Affairs' internal watchdog has found that the software system patient advocates use to track veterans' complaints and access their medical records was wrongly labeled "low risk" for more than a year, an error that let weak account controls go unfixed while the system held veterans' sensitive health data, according to VA Office of Inspector General Report No. 25-01781-71, published July 7, 2026.
Background
The Patient Advocate Tracking System-Replacement, known as PATS-R, is the case-management platform used by Veterans Health Administration patient advocates to log and resolve complaints, compliments, and inquiries from veterans and their families. Because advocates often need to review a veteran's treatment history to address a complaint, PATS-R stores personally identifiable information alongside protected health information, putting it in a sensitivity category that demands strict access governance under federal risk-management rules.
That governance broke down after a bureaucratic handoff. In November 2023, oversight of PATS-R moved from VA's Office of Information and Technology to the VA Office of Enterprise Integration, which was renamed the Office of Strategic Initiatives in September 2025, at the same time the system was migrated from a stand-alone, physical environment to a cloud-based one. The OIG's audit, which examined the period from March 2025 through January 2026, found that OIT did not carry through the steps required by the federal Risk Management Framework during that transition, including reevaluating the system's privacy impact assessment. As a result, PATS-R carried an "impact level low" designation — the categorization VA reserves for systems whose data would cause limited harm if compromised — even though it houses veterans' medical records.
Under federal risk-management practice, a system's impact category drives nearly everything downstream: how often accounts get reviewed, what encryption and monitoring controls apply, and how much scrutiny an authorizing official gives before granting an authorization to operate. A "low" label on a system touching protected health information effectively told VA's security apparatus that PATS-R needed less attention than its actual data holdings warranted. The OIG's audit set out to determine whether the access controls guarding PATS-R matched the sensitivity of what it stored, and found the categorization itself was the first point of failure.
Key Details
The inappropriate risk categorization was not a paperwork technicality. The OIG tied it directly to a pattern of loose access controls that had gone unchecked. Investigators surveyed a statistical sample of 261 VHA staff identified as active PATS-R users and found that 77% never used PATS-R to view medical records and were not aware the system had that functionality, and 89% said losing medical-record access in PATS-R would not affect their job responsibilities at all — a strong signal that far more accounts carried medical-record access than the advocate mission required.
The audit also found that OIT did not consistently verify that PATS-R users were authorized to hold the accounts and permissions assigned to them. Periodic reviews of user accounts and role assignments, which are supposed to catch employees who have changed jobs, left VA, or simply accumulated access they no longer need, were performed inconsistently across the audit period, according to the OIG report, as first noted by FedScoop.
The OIG issued five recommendations addressing the risk categorization and the access-control gaps. VA concurred with all five. The department did not wait for the final report to begin fixing what auditors flagged during fieldwork: after the OIG team raised the low-risk categorization with OIT officials in March 2025, OIT completed a new privacy impact assessment and updated PATS-R's risk categorization to moderate, and it automated the deactivation of accounts left inactive for 90 days or more. By December 2025, according to VA's own follow-up reporting cited by the OIG, PATS-R was running as a minor application hosted on Microsoft Azure and inheriting the cloud platform's moderate-to-high level security controls — a materially different posture than the one the system carried when the audit period began.
The report does not allege that veterans' data was actually stolen or misused. Its finding is narrower and, for a system touching medical records, still serious: the combination of an incorrect risk label and unvalidated access rights meant VA could not demonstrate that only the right people could see sensitive health information, for more than a year.
The interim fixes also illustrate how quickly a categorization change can ripple into technical controls once it is corrected. Moving PATS-R from "low" to "moderate" raises the baseline set of controls the system must maintain under federal guidance, and automating account deactivation after 90 days of inactivity closes one of the most common vectors auditors flag in access-control reviews: dormant credentials that nobody remembered to revoke.
What It Means for Contractors
PATS-R is a VA-run system now hosted on Microsoft Azure's commercial cloud rather than a stand-alone in-house platform, but the audit lands squarely on issues that recur across every VA system built or maintained under contract: cloud migrations that outrun the risk-management paperwork required to authorize them, and portfolio reassignments that leave nobody clearly accountable for a system's security categorization. Firms holding VA IT support, cloud-hosting, or systems-integration task orders should expect the corrective actions here — moderate-or-higher categorization defaults for anything touching PHI, automated inactive-account deactivation, and tighter role-based access reviews — to surface as new contract requirements or modifications on adjacent VHA systems, not just on PATS-R itself.
The audit also offers a template VA OIG is likely to reuse. Investigators used a user survey, rather than a technical penetration test, to expose over-provisioned access, asking users directly whether they needed the permissions they held. Contractors managing identity and access for any VA clinical or case-management system should anticipate that OIG or VA's own compliance staff may run similar surveys, and should get ahead of them by validating role assignments against actual job duties before an auditor does it for them. Contract vehicles that include continuous ATO (authorization to operate) monitoring or ongoing RMF support are the most likely near-term beneficiaries, since VA now has a documented case where a mid-migration portfolio handoff caused a categorization to lapse unnoticed for more than a year.
For teams bidding on VA health-IT modernization work, the report is also a reminder of where VA's Office of Inspector General is currently focused: not major system failures, but access governance on the systems clinicians and patient-facing staff use every day. Five-for-five recommendation concurrence signals VA leadership accepts the findings without dispute, which typically accelerates funding and staffing for the fixes — and the task orders that come with them.