---
kind: "range"
citation: "38 C.F.R. §§ 1.600–1.603"
title: "38"
from: "1.600"
to: "1.603"
count: 4
url: "https://uscodex.org/cfr/38/1.600..1.603"
---

# §1.600. Purpose.

- (a) [Sections 1.600 through 1.603](/cfr/38/1.600..1.603.md) establish policy, assign responsibilities and prescribe procedures with respect to:
  - (1) When, and under what circumstances, VA will grant attorneys, agents, representatives of a VA-recognized service organization, affiliated support-staff personnel, and individuals authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter the ability to access records and basic claims status information through specific VA electronic information technology (IT) systems that contain information regarding the claimants whom they represent or assist in representing before VA;
  - (2) The exercise of authorized access by attorneys, agents, representatives of a VA-recognized service organization, affiliated support-staff personnel, and individuals authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter; and
  - (3) The bases and procedures for denial or revocation of access privileges to VA IT systems of an attorney, agent, representative of a VA-recognized service organization, affiliated support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter for violating any of the requirements for access.
- (b) VA will provide access to specific VA IT systems, the Veterans Benefit Management System (VBMS) and the Caseflow products Queue and eFolder Express, under the following conditions:
  - (1) Only to an attorney, agent, representative of a VA-recognized service organization, affiliated support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter who is approved to access VA IT systems under [§§ 1.600 through 1.603](/cfr/38/1.600..1.603.md);
  - (2)
    - (i) For a representative or affiliated support-staff person of a VA-recognized service organization, only to the records of VA claimants who appointed the service organization as the organization of record to provide representation on their claims,
    - (ii) For an attorney or agent, only to the records of VA claimants who either appointed the attorney or agent as the attorney or agent of record on their claims or appointed an attorney or agent employed by the same legal services office as the attorney or agent of record and consented to affiliated access on VA Form 21-22a, “Appointment of Individual as Claimant's Representative,”
    - (iii) For an individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter, only to the records of VA claimants who appointed the individual to provide representation on their claims, or
    - (iv) For a support-staff person working under the direct supervision of an accredited attorney or agent only to the records of VA claimants who appointed the attorney or agent as the attorney or agent of record on their claims and consented to affiliated access on VA Form 21-22a, “Appointment of Individual as Claimant's Representative”;
  - (3) Solely for the purpose of representing or assisting in the representation of the individual claimant whose records are accessed in a claim for benefits administered by VA; and
  - (4) On a read-only basis, an attorney, agent, representative of a VA-recognized service organization, affiliated support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter authorized to access VA IT systems under [§§ 1.600 through 1.603](/cfr/38/1.600..1.603.md) will not be permitted to modify the data, to include modifying any existing records. However, such an attorney, agent, representative of a VA-recognized service organization, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter may upload documents as permitted by VA IT policy regarding submittal of new documents.
- (c) Privileges to access VA IT systems may be granted by VA only for the purpose of accessing a represented claimant's electronically stored records pursuant to applicable privacy laws and regulations, and as authorized by a claimant's power of attorney under [§ 14.631](/cfr/38/14.631.md) of this chapter.
- (d) [Sections 1.600 through 1.603](/cfr/38/1.600..1.603.md) are not intended to, and do not:
  - (1) Waive the sovereign immunity of the United States;
  - (2) Create, and may not be relied upon to create, any right or benefit, substantive or procedural, enforceable at law against the United States or VA; or
  - (3) **Create or establish a right to electronic access.**

# §1.601. Qualifications for access.

- (a)
  - (1) An applicant for access to VA IT systems for the purpose of providing representation or assisting in representation must be:
    - (i) A representative of a VA-recognized service organization who is accredited by VA under [§ 14.629(a)](/cfr/38/14.629.md?p=a) of this chapter through a service organization and whose service organization holds power of attorney for one or more claimants under [§ 14.631](/cfr/38/14.631.md) of this chapter;
    - (ii) An attorney or agent who is accredited by VA under [§ 14.629(b)](/cfr/38/14.629.md?p=b) of this chapter and who:
      - (A) holds power of attorney for one or more claimants under [§ 14.631](/cfr/38/14.631.md) of this chapter or
      - (B) is authorized to assist in the representation of one or more claimants as an associate attorney or agent employed by the same legal services office as the attorney or agent of record;
    - (iii) An unaccredited support-staff person, including a legal intern, law student, or paralegal, working under the direct supervision of an accredited attorney or agent who has been designated to provide representation to one or more claimants under [§ 14.631(a)](/cfr/38/14.631.md?p=a) of this chapter or an accredited representative of a VA-recognized service organization designated to provide representation to one or more claimants under [§ 14.631(a)](/cfr/38/14.631.md?p=a); or
    - (iv) An individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter to represent, without VA accreditation, more than one claimant and holding power of attorney for one or more claimants under [§ 14.631](/cfr/38/14.631.md) of this chapter.
  - (2) To qualify for access to VA IT systems, the applicant must comply with all security requirements deemed necessary by VA to ensure the integrity and confidentiality of the data and VA IT systems, which may include passing a background suitability investigation for issuance of a personal identity verification badge.
  - (3) VA may deny access to VA IT systems if the requirements of paragraphs [(a)(1)](#a-1) or [(2)](#a-2) of this section are not met.
- (b) The method of access, including security software and work-site location of the attorney, agent, representative of a VA-recognized service organization, affiliated support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter, must be approved in advance by VA.
- (c) Each attorney, agent, representative of a VA-recognized service organization, affiliated support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter approved for access must complete, sign, and return a notice provided by VA. The notice will specify any applicable operational and security requirements for access, in addition to the applicable VA Rules of Behavior, and an acknowledgment that the breach of any of these requirements is grounds for revocation of access.

# §1.602. Utilization of access.

- (a) Once VA issues to an attorney, agent, representative of a VA-recognized service organization, affiliated support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter the necessary logon credentials to obtain basic claims status information and read-only access to the VA records regarding the claimants represented, access will be exercised in accordance with the following requirements. The attorney, agent, representative of a VA-recognized service organization, support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter:
  - (1) Will electronically access VA records through VA IT systems only by the method of access approved in advance by VA;
  - (2) Will use only his or her assigned logon credentials to obtain access;
  - (3) Will not reveal his or her logon credentials to anyone else, or allow anyone else to use his or her logon credentials;
  - (4) Will access via VA IT systems only the records of claimants whom he or she represents or is authorized to assist in representing;
  - (5) Will access via VA IT systems a claimant's records solely for the purpose of representing or assisting in the representation of that claimant in a claim for benefits administered by VA;
  - (6) Is responsible for the security of the logon credentials and, upon receipt of the logon credentials, will destroy the hard copy so that no written or printed record is retained;
  - (7) Will comply with all security requirements VA deems necessary to ensure the integrity and confidentiality of the data and VA IT systems; and
  - (8) Will, if accredited or authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter, comply with each of the standards of conduct for accredited individuals prescribed in [§ 14.632](/cfr/38/14.632.md) of this chapter.
- (b)
  - (1) A VA-recognized service organization shall ensure that all its representatives and support-staff personnel provided access in accordance with these regulations receive annual training approved by VA on proper security or annually complete VA's Privacy and Security Training.
  - (2) An attorney, agent, affiliated support-staff person of an attorney or agent, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter who is provided access in accordance with these regulations will annually acknowledge review of the security requirements for the system as set forth in these regulations, VA's Rules of Behavior, and any additional materials provided by VA.
- (c) **VA may, at any time without notice—**
  - (1) Inspect the computer hardware and software utilized to obtain access and their location;
  - (2) Review the security practices and training of any attorney, agent, representative of a VA-recognized service organization, support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter provided access in accordance with these regulations; and
  - (3) Monitor the access activities of an attorney, agent, representative of a VA-recognized service organization, support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter. By applying for and exercising the access privileges under [§§ 1.600 through 1.603](/cfr/38/1.600..1.603.md), the individual expressly consents to VA monitoring access activities at any time for the purpose of auditing system security.

# §1.603. Revocation and reconsideration.

- (a)
  - (1) VA may revoke access of an attorney, agent, representative of a VA-recognized service organization, affiliated support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter to a particular claimant's records because the principal individual or organization no longer represents the claimant, and, therefore, the claimant's consent is no longer in effect.
  - (2) VA may revoke access of a previously affiliated attorney or agent to a particular claimant's records because the attorney or agent is no longer affiliated with the principal individual, and, therefore, the claimant's consent is no longer in effect.
  - (3) VA may revoke access privileges of a previously affiliated support-staff person to all claimants' records because the support-staff person is no longer affiliated with the principal individual or VA-recognized service organization, and, therefore, the claimants' consent is no longer in effect.
- (b) VA may revoke the access privileges of an attorney, agent, representative of a VA-recognized service organization, affiliated support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter, either to an individual claimant's records or to all claimants' records via the VA IT systems, if the individual, or, additionally in the case of the affiliated support-staff personnel of an attorney or agent, the principal individual:
  - (1) Violates any of the provisions of [§§ 1.600 through 1.603](/cfr/38/1.600..1.603.md);
  - (2) Accesses or attempts to access data for a purpose other than representation or assistance in the representation of an individual claimant;
  - (3) Accesses or attempts to access data of a claimant whom he, she, or the VA-recognized service organization neither represents nor is authorized to assist in representing;
  - (4) Accesses or attempts to access a VA IT system by a method that has not been approved by VA; or
  - (5) **Modifies or attempts to modify data in a VA IT system without authorization.**
- (c)
  - (1) To initiate the process for denial of access under [§ 1.601(a)(3)](/cfr/38/1.601.md?p=a-3) or revocation of access under [paragraph (b)](#b) of this section, VA will notify the attorney, agent, representative of a VA-recognized service organization, support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter of the proposed denial or revocation. If VA is initiating the process to deny or revoke access privileges for a representative of a VA-recognized service organization or any support-staff person, VA will notify the service organization(s) through which the representative is accredited, or the employer of the support-staff person, of the proposal. If VA is initiating the process to revoke access privileges for an attorney or agent based on conduct related to the attorney's or agent's authorized assistance in the representation of one or more claimants, VA will notify the claimants' attorney or agent of record of the revocation proposal. VA's notice will include the procedures applicable to the proposed denial or revocation, including instructions for submitting an optional response and identification of the official making the final decision. VA will allow 30 days for an optional response to the proposal.
  - (2) After considering any timely-received response, VA will issue a final decision based on a preponderance of the evidence. The decision will describe in detail the facts found and state the reasons for VA's final decision. If VA denies or revokes access privileges for a representative of a VA-recognized service organization or any support-staff person, VA will notify the service organization(s) through which the representative is accredited, or the employer of the support-staff person, of the denial or revocation of access. If VA revokes access privileges for an attorney or agent based on conduct related to the attorney's or agent's authorized assistance in the representation of one or more claimants, VA will notify the claimants' attorney or agent of record of the revocation of access.
  - (3) The attorney, agent, representative of a VA-recognized service organization, support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter may request reconsideration of a denial or revocation of access by submitting a written request to VA. VA will consider the request if it is received by VA not later than 30 days after the date that VA notified the attorney, agent, representative of a VA-recognized service organization, support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter of its decision.
  - (4) The attorney, agent, representative of a VA-recognized service organization, support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter may submit additional information not previously considered by VA, provided that the additional information is submitted with the written request and is pertinent to the prohibition of access.
  - (5) VA will close the record regarding reconsideration at the end of the 30-day period described in [paragraph (c)(3)](#c-3) of this section and furnish the request, including any new information submitted by the attorney, agent, representative of a VA-recognized service organization, support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter to the Director of the VA regional office or center with jurisdiction over the final decision.
  - (6) VA will reconsider access based upon a review of the information of record as of the date of its prior denial or revocation, with any new information submitted with the request. The decision will:
    - (i) Identify the attorney, agent, representative of a VA-recognized service organization, support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter,
    - (ii) Identify the date of VA's prior decision,
    - (iii) Describe in detail the facts found as a result of VA's review of its decision with any new information submitted with the reconsideration request, and
    - (iv) State the reasons for VA's final decision, which may affirm, modify, or overturn its prior decision.
  - (7) VA will provide notice of its final decision on access to:
    - (i) The attorney, agent, representative of a VA-recognized service organization, support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter requesting reconsideration, and
    - (ii) if the conduct that resulted in denial or revocation of the authority of an attorney, agent, representative of a VA-recognized service organization, support-staff person, or individual authorized by the General Counsel under [§ 14.630](/cfr/38/14.630.md) of this chapter to access VA IT systems merits potential inquiry into the individual's conduct or competence, or in the case of an affiliated support-staff person of an attorney or agent, the principal individual's conduct or competence, pursuant to [§ 14.633](/cfr/38/14.633.md) of this chapter, the VA regional office or center of jurisdiction will immediately inform VA's Office of General Counsel in writing of the fact that it has denied or revoked the individual's access privileges and provide the reasons why.
- (d) VA may immediately suspend access privileges prior to any determination on the merits of a proposed revocation where VA determines that such immediate suspension is necessary to protect, from a reasonably foreseeable compromise, the integrity of the system or confidentiality of the data in VA IT systems. However, in such case, VA shall offer the individual an opportunity to respond to the charges that led to the immediate suspension and the proposed revocation after the temporary suspension.

