Pentagon fails to secure health records of top officials, watchdog audit finds
A Department of Defense Inspector General audit published August 31, 2026, reveals the Pentagon’s Defense Health Agency failed to safeguard electronic health records of 25 senior officials and media figures. Of 2,600 users who accessed their records, 1,103 (42%) were not on an approved whitelist or watchlist, and none were investigated. The IG warns this may violate HIPAA and threaten national security.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection
Cross-source coverage
Wire timeline
Pentagon fails to secure health records of top officials, watchdog audit finds
A new Department of Defense Inspector General audit published on August 31, 2026, reveals that the Pentagon is still failing to safeguard the electronic health records (EHRs) of top government officials. The Defense Health Agency (DHA) has tightened access to records of well-known personnel but rarely investigates users who access these records without authorization. Auditors examined 25 DoD personnel who were senior officials or media figures. Of 2,600 users who accessed their protected health information, 1,103 (42 percent) were not on DHA's whitelist or watchlist, and none were investigated. In one case, 94 of 334 users accessing a senior official's records were uninvestigated. The IG report warns that this failure may violate HIPAA and threaten national security, recommending DHA contact all unauthorized users and maintain audit trails.
Pentagon fails to secure health records of top officials, watchdog audit finds
A new Department of Defense Inspector General audit published on August 31, 2026, reveals that the Pentagon continues to fail in safeguarding the electronic health records (EHRs) of top government officials. The Defense Health Agency (DHA) has tightened access controls since a 2021 audit found snoopers accessed protected health information of well-known personnel, but the follow-up audit found DHA rarely investigates users who access these records without authorization. Auditors examined 25 senior DoD officials and media figures, finding that of 2,600 users who accessed their records, 1,103 (42 percent) were not on DHA's whitelist or watchlist, and none were investigated. In one case, 94 of 334 users accessing a senior official's records were unauthorized. The IG report warns this may violate HIPAA and could threaten national security, as unauthorized access to sensitive information of well-known individuals poses counterintelligence risks. The IG recommended DHA contact all unauthorized users and maintain complete audit trails, or coordinate with other federal agencies if lacking resources.
Pentagon still failing to secure health records of top officials, audit finds
A new Department of Defense Inspector General audit published on August 31, 2026, reveals that the Pentagon continues to fail in safeguarding the electronic health records of top government officials. The Defense Health Agency has tightened access to records of well-known personnel but has not investigated access by users not on a designated whitelist. Auditors examined 25 DoD personnel who were senior officials or had media exposure after publicized events. Of 2,600 users who accessed their protected health information, 1,103 (42 percent) were neither on the DHA's whitelist nor watchlist, and none were investigated. In one case, 94 of 334 users accessing a senior official's records were uninvestigated. The IG report notes this may violate HIPAA and could threaten national security per Executive Order and National Counterintelligence Strategy. The IG recommended DHA contact all unapproved users who accessed records and maintain complete audit trails, or coordinate with other federal components if lacking resources.
Show 2 older updatesHide older updates
Pentagon still failing to secure health records of top officials, audit finds
A new Department of Defense Inspector General audit published on August 31, 2026, reveals that the Pentagon's Defense Health Agency (DHA) continues to fail in safeguarding the electronic health records of top government officials. The audit found that DHA rarely investigates users who access the protected health information of well-known individuals, even when those users are not on an approved whitelist or are on a watchlist for suspected unauthorized access. Of 2,600 users who accessed records of 25 senior DoD personnel or media-visible individuals, 1,103 (42 percent) were neither on the whitelist nor watchlist, and none were investigated. In one case, 94 of 334 users accessing a senior official's records were uninvestigated. The IG warns that this lack of monitoring may violate HIPAA and could threaten national security, as sensitive health information of high-profile individuals could be exploited. The report recommends DHA contact all unapproved users who accessed such records and maintain complete audit trails.
Pentagon still failing to secure health records of top officials, audit finds
A new Department of Defense Inspector General audit, published on August 31, 2026, reveals that the Defense Health Agency (DHA) continues to fail in safeguarding the electronic health records of well-known government officials. The audit, a follow-up to a 2021 report that found snoopers accessed protected health information of senior DoD personnel, examined 25 high-profile individuals. Of 2,600 users who accessed their records, 1,103 (42 percent) were not on DHA's approved whitelist or watchlist, yet DHA conducted no investigations into these accesses. In one case, 94 of 334 users accessing a senior official's records were unlisted and uninvestigated. The IG found that DHA rarely investigated users on its own watchlist and that its policies may violate HIPAA and fail to meet national security guidelines. The report recommends DHA contact all unapproved users and maintain complete audit trails, or seek assistance from other federal components if resources are insufficient.