The Pentagon is still failing to safeguard the electronic health records of senior government officials, according to a troubling new watchdog report. The findings reveal that serious privacy and national security gaps remain years after auditors first sounded the alarm.

A 2021 Department of War Inspector General audit found that snoopers could access protected health information belonging to “well known Department of War personnel.” That should have triggered swift corrective action, but the latest audit shows the bureaucratic machinery did not finish the job.

The danger is hardly theoretical. The Department of Veterans Affairs previously found that employees, sometimes motivated by simple curiosity, improperly accessed the records of then vice presidential candidates J.D. Vance and Tim Walz.

The Defense Health Agency has tightened access controls for the records of prominent personnel since the earlier audit. However, auditors found that the agency still was not properly investigating people who accessed sensitive files despite not appearing on an approved user list.

Here's What They're Not Telling You About Your Retirement

The heavily redacted report said the agency “rarely investigated users who accessed the EHRs [electronic health records] of well known individuals to determine whether the access was improper.” In other words, the Pentagon built monitoring tools but too often failed to act on what those tools revealed.

The agency maintains a whitelist of medical providers authorized to view protected records. It also operates a watchlist containing users suspected of making unauthorized or otherwise questionable attempts to access those files.

People appearing on the watchlist are supposed to be referred to the agency’s Privacy and Civil Liberties Office, or to “the military medical treatment facility chain of command, for breach reporting, investigation, mitigation, containment, and sanctions if applicable,” according to the report. Those procedures sound serious on paper, but paperwork does not secure records unless officials actually enforce it.

The Defense Health Agency is also required to review weekly access logs and determine whether users had a legitimate reason to open a person’s medical file. Auditors found that the agency investigated neither unapproved users nor individuals already flagged on the watchlist.

This Could Be the Most Important Video Gun Owners Watch All Year

Following recent reports that Congress is considering a nationwide voter ID requirement for federal elections, do you support requiring voters to show identification before casting a ballot?

By completing the poll, you agree to receive emails from Common Defense, occasional offers from our partners and that you've read and agree to our privacy policy and legal statement.

Investigators examined access involving 25 Department of War personnel who were senior officials or whose names had appeared in news coverage after highly publicized events. The scale of unexplained access was substantial enough to raise concerns well beyond routine medical privacy.

“Of the 2,600 users who accessed the PHI of those 25 well known individuals, 1,482 of the users were on the DHA’s Whitelist, and 15 were on the DHA’s Watchlist,” investigators found. “Of the 1,103 users (42 percent) who were not on the DHA’s Whitelist or Watchlist, the DHA did not investigate any of the users.”

That means more than four out of every 10 users who accessed the records were not included on either tracking list. Despite that glaring gap, auditors found no investigations into any of those 1,103 users.

One case involving a senior Department of War official was especially alarming. A total of 334 users accessed that official’s health records, including 94 people who appeared on neither the whitelist nor the watchlist, yet the agency conducted no follow up investigations.

Auditors also determined that one redacted Defense Health Agency policy does not satisfy Department of War guidelines and may violate the Health Insurance Portability and Accountability Act. The report warned that the policy “may not support the Executive Order and National Counterintelligence Strategy that warned that access to sensitive information of well known individuals could threaten national security.”

Medical records can contain details about illnesses, medications, psychological treatment, family circumstances and physical vulnerabilities. In the hands of hostile intelligence services, political operatives or dishonest insiders, that information can become material for coercion, manipulation or blackmail.

“Without proper monitoring and inquiry, users who improperly access these EHRs would not be held accountable as required by DHA guidance.” That blunt finding captures the core failure: the Pentagon had rules, lists and logs, but accountability went missing when it mattered.

The Inspector General recommended that the agency seek assistance from appropriate Department of War or other federal components if it lacks the resources or legal authority to conduct the necessary inquiries. Secretary of War Pete Hegseth now has another bureaucratic mess demanding firm oversight, because curiosity is not authorization and sensitive records cannot be treated like office gossip.

Warning: Account balances and purchasing power no longer tell the same story. Know in 2 minutes if your retirement is working for you.