Cybersecurity rules in this supplement
The VA Acquisition Regulation (VAAR) focuses on protecting veteran health and personal data:
VAAR Subpart 804.19 — Basic Safeguarding of Covered Contractor Information Systems. Applies basic safeguarding requirements to contractor systems that process VA information.
VAAR clause 852.204-71 — Information and Information Systems Security. The central VA cyber clause: requires contractors to protect VA information and systems, follow VA security and privacy policies, and meet VA Handbook 6500 requirements.
VAAR clauses 852.239-70 through -74 — Security for IT resources; security plan and accreditation; system design/development; hosting, operation, maintenance or use; and security-controls compliance testing. Govern IT resources and hosted systems, including the right to test security controls.
VAAR clause 852.211-76 — Liquidated Damages, Reimbursement for Data Breach Costs. Makes contractors liable for the cost of credit protection if they cause a data breach of sensitive personal information.
In plain terms
The VA's rules center on one idea: if you handle veterans' information or run a system for the VA, you must protect it to VA standards (including Handbook 6500), let the VA test your controls, and pay the cost of credit monitoring if you cause a breach.
Who it applies to
Contractors and subcontractors that access, store, generate, transmit, or host VA information or operate information systems for the VA.
What it requires
Follow the FAR baseline, then: meet VA information-security and privacy requirements, maintain a security plan and accreditation for VA systems, submit to security-controls compliance testing, and accept liability (liquidated damages) for breach-related credit-protection costs.
Why it matters
The VA handles large volumes of health and personally identifiable information, and its breach-cost liability clause puts real financial exposure on contractors who fall short.
Citation
VA Acquisition Regulation (VAAR), codified at 48 C.F.R. Chapter 8.