Government Accountability Office

GAO Urges HHS to Increase Oversight of Ransomware Practices

February 16, 2024 - The US Government Accountability Office (GAO) issued recommendations to HHS surrounding its oversight of ransomware practices across the sector in a recent report. The report assessed four federal agencies, including HHS, to evaluate each agency’s efforts to oversee sector adoption of leading cybersecurity practices. GAO chose to focus on...


More Articles

GAO Urges FDA, CISA to Revamp Medical Device Cybersecurity Agreement

by Jill McKeon

The US Government Accountability Office (GAO) released a report on medical device cybersecurity to address limitations in federal agencies’ authority, explore challenges in accessing federal...

GAO Calls on OCR to Educate Patients on Telehealth Security, Privacy Risks

by Jill McKeon

The US Government Accountability Office (GAO) conducted a review of Medicare telehealth services delivered during the pandemic, recommending that the Office for Civil Rights (OCR) provide additional...

GAO Calls on HHS to Improve Healthcare Data Breach Reporting Process

by Jill McKeon

In its latest report, the US Government Accountability Office (GAO) called on HHS to improve the healthcare data breach reporting process. Specifically, GAO urged HHS to create a mechanism for entities...

OIG: Evaluation of FISMA Shows HHS Security Program “Not Effective”

by Jill McKeon

The Office of Inspector General (OIG) called HHS’ security program “not effective” in an audit of Federal Information Security Modernization Act (FISMA) requirements for fiscal year...

GAO Seeks Feedback on Healthcare Data Breach Reporting

by Jill McKeon

UPDATE 2/7/22 - GAO extended the survey deadline to February 11. The Government Accountability Office (GAO) is asking HIPAA-covered entities for feedback on the healthcare data breach reporting...

GAO: Some Progress, But Changes Still Needed For The Department of Veterans Affairs HIT System

by Lisa Gentes-Hunt

The Department of Veterans Affairs has made some progress over the past 20 years but more changes need to be implemented to update its antiquated health...

GAO: HHS Must Collaborate to Ensure Healthcare Cybersecurity

by Jill McKeon

HHS clearly defined roles and responsibilities within its security departments, but a lack of collaboration between these entities is preventing adequate healthcare cybersecurity, according to a study...

GAO Audit Finds HHS Information Security Program “Not Effective”

by Jessica Davis

An evaluation of the Department of Health and Human Services against Federal Information Security Modernization Act of 2014 (FISMA) principles found the agency’s information security program...