VA User Restricted Access to DoD-only Patient Data
JLV audits user access to restricted patient records when VHA or VBA users view DoD-only patients. (i.e., there are no VA identifiers for this patient). At login, the VA user’s site selection determines the site against which the VA user is authenticating. A VHA user is authenticating against VistA; a VBA user is authenticated against CAPRI.
- In JLV, VHA users are allowed to view the records of DoD-only patients (i.e., there are no VA identifiers, or the patient is not registered in MVI), but the VA requires that these actions are audited. After performing a patient search and selecting a patient from the list presented, the VHA user is asked to specify the purpose of accessing the record. Options presented to the user are: Emergent Care, Clinical Care, or Authorized Administrative Use. See Restricted Access for VHA Users.
- VBA users are allowed to view the records of a patient who is registered in MVI but the VA requires that these actions are audited in JLV. When a patient is not registered in MVI, the VBA user will be blocked access to the patient's health record. See Restricted Access for VBA Users.
Note: JLV also audits users each time a DoD sensitive record in the Outpatient Encounters, Documents, Progress Notes, or Lab Results widget is viewed. See Audited Access to DoD Sensitive Data for more information.
Related topics: