US United States Department of Veterans Affairs May 2011 Misuse (Q14575)

From Open Risk Manual
A data breach risk event
Language Label Description Also known as
English
US United States Department of Veterans Affairs May 2011 Misuse
A data breach risk event

    Statements

    0 references
    May 2011
    0 references
    A Veteran/employee requested from the Privacy Officer (PO), a Sensitive Access Report (SAR) to determine accesses to her record. Upon review of the SAR the Veteran/Employee noticed another employee within the same Service had accessed her CPRS records, twice on the same day back in 2010. The PO began an investigation and the employee could not justify access to this CPRS record to perform VA assigned duties. (English)