{"database": "press", "table": "releases", "rows": [["https://mrvan.house.gov/media/press-releases/mrvan-opening-statement-technology-modernization-subcommittee-hearing", "Mrvan Opening Statement for Technology Modernization Subcommittee Hearing on Cybersecurity", "2021-05-20", "2021", "2021-05", "Democrat", "House", "IN", "Frank J. Mrvan", "M001214", "mrvan.house.gov", "mrvan", "https://mrvan.house.gov/media/press-releases", "scraper", "Washington, DC - Congressman Frank J. Mrvan convened a hearing today with the House Committee on Veterans\u2019 Affairs Subcommittee on Technology Modernization entitled Cybersecurity and Risk Management at the VA: Addressing Ongoing Challenges and Moving Forward.\n\nA video of the hearing is available here and the text of the opening statement as prepared for delivery is below.\n\nThis afternoon, the Subcommittee will be reviewing the Department of Veterans Affairs\u2019 cybersecurity posture. We will also be reviewing the findings in the annual Federal Information Security Modernization Act or FISMA audit. Our goal here today is to assess how VA manages its cybersecurity program\u2014including its cyber supply chain, how it controls access to confidential data, and how well it safeguards its information technology assets.\n\nAt today\u2019s hearing we will hear from VA leadership about the broader cybersecurity landscape, the challenges, management\u2019s approach to tackling these challenges, and what resources may be needed.\n\nLast Congress, the Subcommittee on Technology Modernization held the Committee\u2019s first ever hearing to examine VA\u2019s cybersecurity. I am pleased that we can continue this important work and explore the ongoing cybersecurity management challenges at VA.\n\nCybersecurity is not a new challenge in the federal government. The threats to our information systems have only increased since the Federal Information Security Management Act (FISMA) was first passed in 2002.\n\nMajor cybersecurity breaches earlier this year\u2014especially of SolarWinds\u2019 Orion software, the zero-day Exchange server hack, and other incidents\u2014highlight the risks to our information systems. As our reliance on electronic personal data increases, and the sharing of that data increases, so do the risks. Our dependence on electronic systems to support healthcare, e-commerce, and public service delivery is growing\u2014all the more so during the pandemic as government and industry shifted life online.\n\nWe need to only look back a few weeks to see how dangerous a cyber incident can be. The recent ransomware attack on Colonial Pipeline crippled fuel supplies up and down the east coast, adding unnecessary uncertainty and increased costs for countless individuals.\n\nUnfortunately, the health sector is not immune to these attacks. In 2017, WannaCry ransomware, created by hackers working for the North Korean government, spread across the world and infected the U.K.'s National Health System. In May 2020, Blackbaud, a cloud software provider used by many healthcare companies, was the victim of a ransomware attack. So far, more than 6 million individuals have been impacted.\n\nMany experts estimate that the value of medical records on the darknet is higher than that of passwords and credit cards. According to security company Comparitech\u2014in 2020 at least 92 individual ransomware attacks affected more than 600 separate clinics, hospitals, and organizations, and over 18 million individual patient records. Ransomware attacks may have contributed to 40,056 hours (1,669 days) of downtime to healthcare organizations in 2020. The average time lost to downtime is increasing\u2014up to 21 days during Q4 of 2020. On average, healthcare cyberattacks cost $1.4 million in recovery.\n\nVA prides itself as being the nation\u2019s largest integrated healthcare provider. In that role, VA should be at the forefront of addressing many of these risks and should be a leader in healthcare cybersecurity. As VA continues the process of modernizing its IT systems to deliver healthcare, adjudicate disability claims, and provide educational benefits, information security management should be a key component from the outset.\n\nThe Subcommittee is still concerned that VA has not done enough to assess risk and develop long-term information security strategies. Numerous Inspector General and Government Accountability Office reports continue to cite management failures and lack of internal oversight.\n\nThey also repeat recommendations year-after-year\u2014seemingly without adequate progress in resolving them.\n\nI look forward to hearing from leadership within VA\u2019s Office of Information Technology about the Department\u2019s overall cyber program and cyber strategy. We will also hear from the Office of Inspector General about its recent FISMA audit, outstanding issues, and how VA\u2019s cybersecurity posture has evolved over the last several years. Finally, we will hear from the Congressional Research Service, whose expertise can help us contextualize some of these issues and understand cybersecurity within the federal government.\n\nAs the Technology Modernization Subcommittee, we must ask\u2014is VA ready? Is VA\u2019s information security management system up to the task? Is VA ready to prioritize cybersecurity? America's veterans should be able to access VA healthcare with the peace of mind that their data and privacy will be protected. I hope VA can get this right.\n\nI thank the witnesses for being here, and I look forward to their testimony.", 1, "2026-03-30T01:40:41Z", "2026-04-06T19:49:40Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://mrvan.house.gov/media/press-releases/mrvan-opening-statement-technology-modernization-subcommittee-hearing"], "units": {}, "query_ms": 0.9049607906490564, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}