Wire flash
PoliticsPentagon audit: 42% of users accessing senior officials' health records not investigated
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
A new Department of Defense Inspector General audit published on August 31, 2026, reveals that the Pentagon's Defense Health Agency (DHA) continues to fail in safeguarding the electronic health records of top government officials. The audit found that DHA rarely investigates users who access the protected health information of well-known individuals, even when those users are not on an approved whitelist or are on a watchlist for suspected unauthorized access. Of 2,600 users who accessed records of 25 senior DoD personnel or media-visible individuals, 1,103 (42 percent) were neither on the whitelist nor watchlist, and none were investigated. In one case, 94 of 334 users accessing a senior official's records were uninvestigated. The IG warns that this lack of monitoring may violate HIPAA and could threaten national security, as sensitive health information of high-profile individuals could be exploited. The report recommends DHA contact all unapproved users who accessed such records and maintain complete audit trails.
Source report
The Department of Defense (DoD) continues to fail in safeguarding the electronic health records (EHRs) of top government officials, according to a new watchdog report.
In 2021, a DoD Inspector General audit found that unauthorized individuals were able to access the protected health information (PHI) of "well-known DOD personnel." Separately, the Department of Veterans Affairs discovered that VA staff—often out of simple curiosity—had improperly accessed the records of then-vice presidential candidates J.D. Vance and Tim Walz.
The Defense Health Agency (DHA) has since tightened access to health records of well-known personnel, according to a follow-up DoD IG audit published Monday. However, the DHA is not investigating access by individuals who are not on a designated list of approved users.
The DHA "rarely investigated users who accessed the EHRs of well‑known individuals to determine whether the access was improper," said the IG report, which was heavily redacted.
Current Safeguards and Gaps
The DHA maintains two key lists:
- Whitelist: Authorized medical providers who can access health records.
- Watchlist: Users suspected of unauthorized access. Individuals on this list are supposed to be referred to DHA's Privacy and Civil Liberties Office, or to "the military medical treatment facility chain of command, for breach reporting, investigation, mitigation, containment, and sanctions if applicable," the report noted.
The DHA is also required to review weekly logs to determine whether access was justified.
Yet, the DHA neither investigated users who were not on the approved list, nor those on the watchlist.
Key Findings
Auditors examined the cases of 25 DoD personnel who were either senior officials or whose names had appeared in the media after a highly publicized event.
- Of the 2,600 users who accessed the PHI of those 25 well‑known individuals:
- 1,482 were on the DHA's Whitelist.
- 15 were on the DHA's Watchlist.
- 1,103 users (42 percent) were on neither list—and the DHA did not investigate any of them.
In one case involving a senior DoD official, 334 users accessed that person's health records. Of those, 94 were neither on the whitelist nor the watchlist. No follow-up investigations were conducted.
Policy and Legal Concerns
One DHA policy—redacted in the report—is not meeting DoD guidelines and may also violate the Health Insurance Portability and Accountability Act (HIPAA), the audit said. In addition, it "may not support the Executive Order and National Counterintelligence Strategy that warned that access to sensitive information of well‑known individuals could threaten national security."
"Without proper monitoring and inquiry, users who improperly access these EHRs would not be held accountable as required by DHA guidance."
Recommendations
The IG recommended that the DHA:
- Contact any user not on the approved whitelist who accessed the health records of well-known individuals.
- Maintain a complete audit trail of all correspondence between the DHA and the user.
If the Defense Health Agency lacks the resources or authorities to complete these inquiries, it should coordinate with the appropriate DoD or other federal components for assistance, the report suggested.
About the Author
Michael Peck is a correspondent for Defense News and a columnist for the Center for European Policy Analysis. He holds an M.A. in political science from Rutgers University. Find him at theuncommondefense.com. His email is mikedefense1@gmail.com.
Source
Military TimesWestern
Part of this Story
Pentagon fails to secure health records of top officials, watchdog audit finds