healthcarereimagined

Envisioning healthcare for the 21st century

  • About
  • Economics

VA plans facial recognition pilot for health care employees to reduce log-in burden – Federal News Network

Posted by timmreardon on 01/13/2024
Posted in: Uncategorized.

By Jory Heckman

December 21, 2023 6:26 pm

The Department of Veterans Affairs is looking at facial recognition technology for its frontline medical workers to log into their workstations more quickly, and spend more time treating veterans.

VA Chief Information Security Officer Lynette Sherrill said the department plans on piloting facial recognition tools next year at VA hospitals, particularly for frontline clinicians working in intensive care units.

The pilot, if successful, would give VA health care employees an alternative to using their Personal Identity Verification (PIV) cards to securely log onto the department’s network.

“I’ve got nurses and clinicians trying to care for veterans. And they’ve got to reach for a PIV card … and plug it into a workstation to log in, while they’re trying to give a veteran a shot or give a patient an exam. So if I can make that a more frictionless authentication experience for them, I feel like that’s my job to help them,” Sherrill said Nov. 7 at the Rise8’s Prodacity summit in Washington, D.C.

Sherrill told Federal News Network on the sidelines of the event that the VA plans to run facial recognition pilots throughout 2024 with clinical staff.

“Much like we use facial recognition to log into an iPhone today, that’s that type of experience we want to give VA clinical staff,” she said in an interview.

Sherrill said there’s already a high rate of PIV card utilization among the VA workforce. About 95% of employees, she added, are using their PIV cards to log onto the VA network.

But even with those metrics, that means roughly 30,000 VA employees are logging on only with a username and password.

Sherrill said the facial recognition pilot is focused on providing a “more frictionless authentication process” for VA clinical staff.

“The technology is finally there, where we can utilize the technology to provide a better experience for our end users,” she said.

Carrie Lee, VA’s deputy chief information officer for product engineering service, told Federal News Network that she’s heading up the department’s new identity, credential and access management (ICAM) modernization efforts.

“We’re looking at our single sign-on experiences for both internal and external users, making sure that we are using multifactor [authentication], and making it compliant, making it an easy experience for the users,” Lee said.

For external users,  Lee said VA is using Login.gov and transitioning off of legacy credentials that only require a username and password, and may not be as secure.

The VA is also setting a new standard for cybersecurity across its networks.

VA is shifting some of its systems to a continuous Authority to Operate (ATO). It’s a trend that’s already happening across the Defense Department.

The idea is VA will keep checking in to make sure its systems uphold cybersecurity requirements, rather than just checking off that those standards are met once before their launch.

“We have quarterly reviews that review the security posture of every application within that continuous ATO, where I can click down and see how many risks were mitigated, how many vulnerabilities did we keep from being released into production,” Lee said.  “I can go in at any point, and understand what’s happening in that environment for multiple applications.”

Sherrill said the continuous ATO marks a step toward the VA having an “automated enterprise risk view” across its network.

“With the ever-changing threat landscape that we’re dealing with in cybersecurity today, one of the things that is very hard to keep up with is how is the risk posture of all of our systems changing,” she said.

Sherrill added that the VA, with its new automated cybersecurity tools, will be able to respond more quickly to zero-day vulnerabilities and other emerging threats.

“What this integration and automation is going to [is] … we’d know immediately, ‘These are our six most critical systems impacted by this zero-day vulnerability.’ And we’d be able to focus our resources on those systems, to make sure that we could maintain a risk posture that’s acceptable to the organization,” she said.

Lee said the continuous ATO will also allow VA’s IT workforce to develop code and software more quickly, and spend less time on manual cybersecurity compliance work.

“It also frees up a lot of people from manually entering into our [governance, risk and compliance] systems the compliance information, which can take a lot of resources, to be able to focus on higher value valuable tasks, such as actually developing systems,” Lee said.

Lee said the VA has more than 1,000 systems with an ATO. Of those, she said she’s the authorizing official for about 400 of them. She said she spends about an hour each week authorizing systems.

“VA is an extremely complex organization. We’re probably the largest IT infrastructure of any civilian federal agency,” Lee said. “I really need to understand the security of the system I’m looking at the time I look at it. So, the assurance of having those automated controls in place, and understanding that technical risk posture, instead of just the compliance is very important to me, from an authorizing official perspective.”

Lee said the VA has reduced the ATO process from 400 days to about 60 days for new products coming into the environment.

VA’s Office of Information and Technology (VA OIT) is also taking steps to make sure its employees are incorporating cybersecurity into the foundation of everything in development.

Sherrill said no VA OIT development team is allowed to publish “any critical or high vulnerabilities in code.”

“We understand very uniformly that you can no longer produce a quality system if it’s not secure. And that’s our mantra at VA now — if it’s not secure, it’s not quality code, it’s not a quality product, so you’ve got to go back to the drawing board,” she said.

The VA is also focused on bringing in the next generation of cyber workers.

“We’ve got to use nontraditional hiring methods and nontraditional people and get them interested in cybersecurity,” Sherrill said. “We’ve got cybersecurity people leaving the cybersecurity industry because of burnout. We have to stop doing that. We’ve got to figure out how do we fill that pipeline back.”

Sherrill told Federal News Network that the VA is looking at ways to partner with the Defense Department’s SkillBridge program, which places transitioning service members into civilian careers.

“If I can bring in transitioning service members who already have cyber skills, and they’re transitioning out of the service, and I can give them a soft place to transition to and the VA and then give them two [or] three years of training, and they launch into industry — that’s a win,” she said. “But if they choose to stay in VA, and they get passionate about the mission, like most of us are in serving veterans, that’s a win as well.”

Sherrill said the VA also sees potential in reaching out to military spouses to consider careers in cybersecurity.

“They have an aptitude that they uniquely bring into the field, and I think that’s an untapped resource for us. We’ve got to look at these non-traditional places to really bring resources into the cyber pool,” she said.

The VA this summer rolled out a Special Salary Rate for its IT and cybersecurity employees, resulting in an average 17% pay raise. The SSR is meant to narrow the gap between what the government and private sector can afford to pay in-demand tech experts.

“We’re bringing in people and being able to pay them, not at the exact level they would be making in the industry, but close to that level. And between that, the benefits we offer and our amazing mission, I think we’ve been able to get the best talent,” Lee said.

Article link: https://federalnewsnetwork.com/it-modernization/2023/12/va-plans-facial-recognition-pilot-for-health-care-employees-to-reduce-log-in-burden/

Share this:

  • Click to share on X (Opens in new window) X
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on LinkedIn (Opens in new window) LinkedIn
Like Loading...

Related

Posts navigation

← NSA Publishes 2023 Cybersecurity Year in Review
Pentagon’s first industrial strategy calls for ‘generational’ change – Defense News →
  • Search site

  • Follow healthcarereimagined on WordPress.com
  • Recent Posts

    • Hype Correction – MIT Technology Review 12/15/2025
    • Semantic Collapse – NeurIPS 2025 12/12/2025
    • The arrhythmia of our current age – MIT Technology Review 12/11/2025
    • AI: The Metabolic Mirage 12/09/2025
    • When it all comes crashing down: The aftermath of the AI boom – Bulletin of the Atomic Scientists 12/05/2025
    • Why Digital Transformation—And AI—Demands Systems Thinking – Forbes 12/02/2025
    • How artificial intelligence impacts the US labor market – MIT Sloan 12/01/2025
    • Will quantum computing be chemistry’s next AI? 12/01/2025
    • Ontology is having its moment. 11/28/2025
    • Disconnected Systems Lead to Disconnected Care 11/26/2025
  • Categories

    • Accountable Care Organizations
    • ACOs
    • AHRQ
    • American Board of Internal Medicine
    • Big Data
    • Blue Button
    • Board Certification
    • Cancer Treatment
    • Data Science
    • Digital Services Playbook
    • DoD
    • EHR Interoperability
    • EHR Usability
    • Emergency Medicine
    • FDA
    • FDASIA
    • GAO Reports
    • Genetic Data
    • Genetic Research
    • Genomic Data
    • Global Standards
    • Health Care Costs
    • Health Care Economics
    • Health IT adoption
    • Health Outcomes
    • Healthcare Delivery
    • Healthcare Informatics
    • Healthcare Outcomes
    • Healthcare Security
    • Helathcare Delivery
    • HHS
    • HIPAA
    • ICD-10
    • Innovation
    • Integrated Electronic Health Records
    • IT Acquisition
    • JASONS
    • Lab Report Access
    • Military Health System Reform
    • Mobile Health
    • Mobile Healthcare
    • National Health IT System
    • NSF
    • ONC Reports to Congress
    • Oncology
    • Open Data
    • Patient Centered Medical Home
    • Patient Portals
    • PCMH
    • Precision Medicine
    • Primary Care
    • Public Health
    • Quadruple Aim
    • Quality Measures
    • Rehab Medicine
    • TechFAR Handbook
    • Triple Aim
    • U.S. Air Force Medicine
    • U.S. Army
    • U.S. Army Medicine
    • U.S. Navy Medicine
    • U.S. Surgeon General
    • Uncategorized
    • Value-based Care
    • Veterans Affairs
    • Warrior Transistion Units
    • XPRIZE
  • Archives

    • December 2025 (8)
    • November 2025 (9)
    • October 2025 (10)
    • September 2025 (4)
    • August 2025 (7)
    • July 2025 (2)
    • June 2025 (9)
    • May 2025 (4)
    • April 2025 (11)
    • March 2025 (11)
    • February 2025 (10)
    • January 2025 (12)
    • December 2024 (12)
    • November 2024 (7)
    • October 2024 (5)
    • September 2024 (9)
    • August 2024 (10)
    • July 2024 (13)
    • June 2024 (18)
    • May 2024 (10)
    • April 2024 (19)
    • March 2024 (35)
    • February 2024 (23)
    • January 2024 (16)
    • December 2023 (22)
    • November 2023 (38)
    • October 2023 (24)
    • September 2023 (24)
    • August 2023 (34)
    • July 2023 (33)
    • June 2023 (30)
    • May 2023 (35)
    • April 2023 (30)
    • March 2023 (30)
    • February 2023 (15)
    • January 2023 (17)
    • December 2022 (10)
    • November 2022 (7)
    • October 2022 (22)
    • September 2022 (16)
    • August 2022 (33)
    • July 2022 (28)
    • June 2022 (42)
    • May 2022 (53)
    • April 2022 (35)
    • March 2022 (37)
    • February 2022 (21)
    • January 2022 (28)
    • December 2021 (23)
    • November 2021 (12)
    • October 2021 (10)
    • September 2021 (4)
    • August 2021 (4)
    • July 2021 (4)
    • May 2021 (3)
    • April 2021 (1)
    • March 2021 (2)
    • February 2021 (1)
    • January 2021 (4)
    • December 2020 (7)
    • November 2020 (2)
    • October 2020 (4)
    • September 2020 (7)
    • August 2020 (11)
    • July 2020 (3)
    • June 2020 (5)
    • April 2020 (3)
    • March 2020 (1)
    • February 2020 (1)
    • January 2020 (2)
    • December 2019 (2)
    • November 2019 (1)
    • September 2019 (4)
    • August 2019 (3)
    • July 2019 (5)
    • June 2019 (10)
    • May 2019 (8)
    • April 2019 (6)
    • March 2019 (7)
    • February 2019 (17)
    • January 2019 (14)
    • December 2018 (10)
    • November 2018 (20)
    • October 2018 (14)
    • September 2018 (27)
    • August 2018 (19)
    • July 2018 (16)
    • June 2018 (18)
    • May 2018 (28)
    • April 2018 (3)
    • March 2018 (11)
    • February 2018 (5)
    • January 2018 (10)
    • December 2017 (20)
    • November 2017 (30)
    • October 2017 (33)
    • September 2017 (11)
    • August 2017 (13)
    • July 2017 (9)
    • June 2017 (8)
    • May 2017 (9)
    • April 2017 (4)
    • March 2017 (12)
    • December 2016 (3)
    • September 2016 (4)
    • August 2016 (1)
    • July 2016 (7)
    • June 2016 (7)
    • April 2016 (4)
    • March 2016 (7)
    • February 2016 (1)
    • January 2016 (3)
    • November 2015 (3)
    • October 2015 (2)
    • September 2015 (9)
    • August 2015 (6)
    • June 2015 (5)
    • May 2015 (6)
    • April 2015 (3)
    • March 2015 (16)
    • February 2015 (10)
    • January 2015 (16)
    • December 2014 (9)
    • November 2014 (7)
    • October 2014 (21)
    • September 2014 (8)
    • August 2014 (9)
    • July 2014 (7)
    • June 2014 (5)
    • May 2014 (8)
    • April 2014 (19)
    • March 2014 (8)
    • February 2014 (9)
    • January 2014 (31)
    • December 2013 (23)
    • November 2013 (48)
    • October 2013 (25)
  • Tags

    Business Defense Department Department of Veterans Affairs EHealth EHR Electronic health record Food and Drug Administration Health Health informatics Health Information Exchange Health information technology Health system HIE Hospital IBM Mayo Clinic Medicare Medicine Military Health System Patient Patient portal Patient Protection and Affordable Care Act United States United States Department of Defense United States Department of Veterans Affairs
  • Upcoming Events

Blog at WordPress.com.
  • Reblog
  • Subscribe Subscribed
    • healthcarereimagined
    • Join 154 other subscribers
    • Already have a WordPress.com account? Log in now.
    • healthcarereimagined
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • View post in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...
 

    %d