Why It Matters

The findings expose systemic security vulnerabilities at institutions that serve 9 million enrolled veterans across more than 1,300 facilities, a sprawling healthcare system where basic safeguards like weapon detection and alcohol enforcement are failing at scale.

The stakes are stark: a Government Accountability Office (GAO) investigation found that covert testers successfully smuggled prohibited weapons into all 30 VA facilities they visited without detection. Staff failed to confront an investigator openly drinking from a vodka bottle in 25 of 26 separate tests. These breaches occurred even as violent incidents, threats, and security-related emergencies have become routine at VA hospitals.

For policymakers, the report reveals an agency struggling to implement federal security standards despite years of warnings. For the VA itself, the findings suggest that compliance gaps and communication failures between headquarters and regional offices have left millions of veterans and staff in facilities where basic security protocols are not being followed.

The Security Breakdown

The raw crime data tells part of the story. Approximately 74,700 crimes were recorded at VA medical facilities in fiscal years 2024 and 2025, with the overwhelming majority classified as nonviolent offenses. These included disorderly conduct, theft, and drug offenses.

Urban VA facilities averaged approximately 214 crimes per location over the two years, roughly double the rate of 123 crimes per facility at rural sites. While this disparity mirrors broader Department of Justice findings on crime trends, the GAO's covert testing revealed that VA's defenses remain inadequate regardless of setting.

The weapon detection failures were comprehensive. In covert tests, VA staff did not detect a prohibited weapon that GAO investigators carried into any of the 30 tested VA medical facilities. Only two of those 30 facilities even had metal detectors. The alcohol tests were similarly revealing: in 25 of 26 instances, staff did not confront an investigator appearing to drink alcohol in plain view, despite drinking alcohol being generally prohibited at VA facilities.

They point to systemic failures in enforcement across the system.

Federal Standards

The Interagency Security Committee (ISC) established risk management standards that all federal agencies, including the VA, are required to follow. Yet the GAO found that VA has not fully implemented all ISC requirements. Specifically, the agency has failed to document decisions on which security strategies it will adopt, and it has not established mechanisms to measure the performance of the security strategies it does employ.

This compliance gap has persisted despite the VA's stated commitment to addressing security vulnerabilities through infrastructure planning. VA has a performance goal to address security gaps for capital projects. While VA met its overall security gap planning goal in fiscal years 2023 through 2025, two of its 18 regions fell short. More troubling, VA headquarters did not communicate to those underperforming regions that they were failing to meet the goal.

The communication breakdown suggests an agency where regional accountability mechanisms have atrophied. Two of VA's 18 regions did not take actions to improve performance on the security gap planning goal during the review period, a failure that went unaddressed by central management.

GAO Recommendations

The GAO issued three core recommendations. First, the Secretary of Veterans Affairs should develop a plan with specific milestones for fully implementing the ISC's risk management standard. Second, the agency should assess the resources needed to fully implement the ISC's risk management standard. Third, VA headquarters should create a mechanism to communicate with regional officials about their progress on security gap closure.

The agency agreed with all recommendations. On the first, VA moved quickly: in June 2026, it submitted documentation of an implementation plan that included milestone dates. The plan sets a goal of measuring the performance of its security strategies by the end of June 2027. The GAO marked this first recommendation as closed and implemented.

The second recommendation, assessing resource needs, remains open. The third, requiring a communication mechanism between headquarters and regional offices, also remains unresolved, though VA stated in May 2026 that it will develop the mechanism by September 2026.

GAO's second recommendation regarding assessment of resources needed to fully implement the ISC's risk management standard remains open.

The Investigation

The GAO's examination was comprehensive in some respects and limited in others. Investigators reviewed VA security and infrastructure planning policies, analyzed crime data from fiscal years 2024 and 2025, and examined risk assessment and infrastructure performance data spanning fiscal years 2023 through 2025. They interviewed VA personnel and veterans in Arkansas and California.

The covert testing at 30 facilities was deliberately constructed to ensure variation in size and geographic location, though the GAO acknowledged the sample was not generalizable to the entire system. This methodological constraint means the weapon and alcohol detection failures observed at those 30 sites cannot be statistically projected across all 1,300-plus VA facilities.

VA did not provide formal written comments on the draft GAO report.

What Comes Next

The May 2026 release of the GAO report has set specific accountability markers. VA has already moved on the first recommendation, providing its implementation plan.

Two of VA's 18 regions did not meet the security gap planning goal in fiscal years 2023 through 2025, and VA headquarters did not communicate to the regions that they were not meeting this goal.

The covert testing documented security failures at VA medical facilities.

Spot something wrong? Report an issue with this article