Paying for Nothing: How the VA Spent $11.2 Million on Services Never Delivered
A Bureaucracy Times Analysis
The Department of Veterans Affairs paid roughly $11.2 million for a Veterans Crisis Line backup center that never meaningfully answered a call. For nearly a year, taxpayer money went to a ghost operation that was supposed to catch overflow and emergencies for the nation’s 24/7 lifeline for veterans in suicidal crisis—but it never legally came online, never handled real traffic, and never delivered the backup protection the contract promised.
The payments continued despite officials knowing—as early as November 2022—that the contractor couldn’t legally deliver the service. The backup call center sat understaffed, unable to meet security requirements, incapable of handling calls. Yet invoices kept coming. Checks kept clearing. Nobody stopped it until June 2023.
This is not a case of good intentions gone wrong, or an unavoidable technical failure. It’s a story of institutional dysfunction, blurred accountability, and a bureaucratic apparatus so fractured that nobody felt personally responsible for stopping money from flowing to a ghost operation.
The Setup: Why Backup Systems Matter
The Veterans Crisis Line has answered over 5 million contacts since its 2007 launch. With a suicide rate among veterans nearly double the general population—35 deaths per 100,000 veterans according to VA’s own data—the service exists because it works. Trained responders recognize the specific trauma signatures of military experience. They know how to talk someone down from immediate harm.
In 2022, the VCL added a new routing mechanism: the 988 hotline (national suicide prevention line) followed by the “press 1” option for veterans. This integration meant calls flowed through a contractor’s routing system before reaching VA responders. That contractor was also supposed to provide backup capacity—10 percent of call volume normally, but 100 percent in emergencies.
Ten percent of normal traffic meant handling calls when the VCL’s main system went down for maintenance, during a cyberattack, or in the event of disaster. For a line that fielded 600 responders on average per month, this meant the contractor needed to maintain roughly 60 dedicated backup staff.
On paper, the VA had it covered. A $32.5 million contract, awarded in April 2019, was supposed to last five years. The backup responder portion—$20.5 million of that total—went to a subcontractor brought in by the prime contractor. The service was supposed to be seamless, invisible unless needed, but absolutely reliable if crisis struck.
It was none of those things.
The Misaligned Checklist
Start with the fundamental error: a security compliance failure buried in bureaucratic procedure.
When the VA’s acquisition team put together the 2019 contract, they filled out a security checklist. This document, required by VA Handbook 6500.6, is supposed to identify what sensitive information the contractor will handle and what security protections are required. The 2019 checklist concluded: no Authority to Operate (ATO) needed. The contractor wouldn’t be storing sensitive veteran data, the team reasoned, so standard commercial security would suffice.
This was wrong.
The performance work statement—the contract’s actual requirements—mandated that the contractor transmit call documentation within 30 minutes of each call and provide call recordings to VA within 24 hours upon request. The contract explicitly stated: “call recordings will be kept according to VA policy; 100% recording and 100% retention.”
Call recordings of veterans in crisis contain deeply sensitive information: suicidal ideation, trauma histories, medical conditions, personal identifying information. This is exactly the kind of data requiring Authority to Operate certification.
The VA even had a reference point. When checking the previous 2017 contract—for nearly identical services—the 2019 acquisition team could have seen that ATO was required for the same work. But that discrepancy wasn’t caught. Nobody at VA compared the two. Nobody asked the information security officer why the exact same service changed from “requires ATO” to “doesn’t require ATO.”
The information security officer would later tell OIG investigators that the understanding was the contractor wouldn’t store VA data. But the contract explicitly required it. When asked about the disconnect, neither the security officer nor the contracting officer could adequately explain the discrepancy.
As the OIG report notes: “The information security officer and the COR who signed the 2019 checklist could not fully explain the discrepancy for the same service requiring an authority to operate for the 2017 contract but not requiring one for the 2019 contract.”
This is how $11.2 million starts getting wasted: through a failure in the most basic institutional check—comparing your contract to the last contract for the same work.
The Subcontractor Switch
For three years, the system limped forward under the original subcontractor. Then, in April 2022, that subcontractor announced it was getting out of the business. Termination was set for July 15, 2022—the day before the VA was implementing “988 press 1” hotline routing through this same contractor.
Within a week, VA leadership scrambled to create an internal backup system. But it would take months to get operational, and even longer to fully functional. So they needed the contractor—with his new subcontractor—to maintain backup capacity in the interim.
The new subcontractor came on July 15, 2022, with an aggressive staffing plan provided to VA’s Contracting Officer’s Representative (COR):
- 50 staff by October 2022 (2.5 months in)
- 92 fully staffed responders by November 2022 (3.5 months in)
The COR rated this plan “acceptable” and signed off on it.
By August 2022, just weeks into the new subcontract, the new subcontractor revealed its technology plan: it wanted to use a cloud-based system for document sharing.
This triggered an information security review. And that’s when VA’s sloppiness caught up with them.
By the end of August 2022, the information security officer told the COR and VCL officials: if the contractor was processing, storing, or transmitting VA data using cloud services, it would need FedRAMP certification and an Authority to Operate. The proposed system didn’t have it.
September 2022: The COR confirmed the contractor couldn’t use the proposed system because it lacked FedRAMP compliance.
October 2022: The VCL’s deputy director of technology circulated an issue brief. It would take 12 to 18 months for the contractor to achieve compliance.
Twelve to eighteen months. Let that sink in. VA officials had just learned they’d contracted for a year-and-a-half of security remediation—during which the contractor couldn’t legally handle veteran calls—and didn’t immediately stop the bleeding.
The Meeting Where Everyone Knew
November 2, 2022. This is the date that matters most.
VCL officials, the COR, the contracting officer, and the acquisition services division chief all sat down to discuss the unfolding disaster. The meeting notes are blunt:
“Contractor could not provide backup responder services without an Authority to Operate.”
“It would be at least one to two years before services would be provided.”
The acquisition services division chief—essentially the boss of the contracting operation—suggested options. The contract could be modified (which would require renegotiating price). A 60-day stop-work order could be issued to buy time to figure this out. Or the whole service could be terminated.
The contracting officer’s response: “The contractor must be given a chance to become compliant and had to be paid.”
This is the pivot point where negligence becomes something more deliberate. Everyone in that room understood:
- The service wasn’t being provided
- The contractor wasn’t compliant with federal security law
- The contractor couldn’t become compliant for at least a year
- Yet the contractor had to keep getting paid
The meeting notes even included a section explicitly labeled “paying for services not received”—the COR later told OIG investigators that VCL leaders had expressed concerns about this issue to the contracting officer.
Eight days later, on November 10, the parties met again. Same conclusion: the contractor would need 9 to 18 months for compliance. Still, the contracting officer didn’t issue a stop-work order. Didn’t renegotiate. Didn’t terminate.
Why? The contracting officer told OIG investigators he was waiting for VCL officials’ direction.
The VCL deputy executive director told OIG investigators VCL needed the backup system while building their internal option.
So who made the decision? Nobody. That’s the answer. It fell into a bureaucratic void.
The Invoice Trap
Meanwhile, invoices were flowing in. Every month, the contractor—or its subcontractor—submitted payment requests for call responder backup services. The COR, whose job was to verify that services were actually delivered before authorizing payment, kept approving them.
The data tells the real story.
Call routing logs show: zero calls transferred to the backup center from mid-July 2022 through June 2023. Two calls in August 2022 that probably weren’t even answered based on call duration. Then nothing. Complete silence. A year of radio silence, during which VA paid $11.2 million for staffing that didn’t exist and calls that were never handled.
Yet in March 2023—nine months into this black hole—the VCL management analyst emailed the VCL executive director asking to exercise the next contract option year for the backup center. Same day, the executive director approved it. The COR issued an evaluation saying the contractor’s performance was “satisfactory.” The contracting officer issued the modification to continue the contract.
This is the trap: federal contracting law doesn’t punish you for overpaying for nothing. A firm-fixed-price contract means the contractor bears financial risk—but it also means the contractor gets paid regardless, as long as they keep billing. And unless someone explicitly stops payment, the machine keeps grinding.
The COR later explained to OIG investigators that he approved invoices based on the contracting officer’s advice that payments were justified because the contractor was “making progress during the implementation phase and working toward an approval.” Translation: he approved payment for work not done because someone else told him it was okay.
But VA’s acquisition manual explicitly states: “the COR should not recommend invoice payment solely on the recommendation of another government employee.”
It happened anyway. Month after month, January through May 2023, invoices were approved based on one official deferring to another official’s judgment, with nobody actually verifying the work was done.
The irony is caustic: the COR’s job was to protect the government’s interests. Instead, he abdicated that responsibility to someone else.
Why Nobody Stopped It
Three factors created this mess:
First: Unclear authority and responsibility. The contracting officer believed VCL leadership needed to decide about the backup services. VCL leadership believed they needed contracting guidance. Nobody wanted to own the decision, so nobody made it. For seven months, the system defaulted to “keep paying.”
Second: Weak documentation and communication. When a VCL official apparently told the contractor not to take calls (without official authorization), the contracting officer found out later and was confused about who said it and when. At a critical moment, nobody had written proof of the problem, so the contracting officer could demand written direction before acting. But this created a catch-22: VCL couldn’t be expected to formalize a problem the contracting officer wasn’t formally acknowledging.
Third: The acquisition manual’s weak enforcement. The regulation says CORs shouldn’t rely on other officials’ advice. But there’s no secondary review, no checkpoint, no audit until months later. A COR can violate the manual by just deferring to the contracting officer, and nobody catches it until an OIG audit.
The acquisition services division chief told OIG investigators that “there was no evidence in the contract file that indicated the contractor did not provide call answering services” and that “VCL officials did not provide a formal written notification stating that services were not being provided.”
This is the heart of bureaucratic dysfunction. Nobody takes action without formal documentation. But the system that’s supposed to generate that documentation is the same system that’s failing. It’s circular: you can’t stop payment without formal notice, but nobody issues formal notice because nobody owns the decision.
The Termination and Settlement
Finally, in May 2023—a year after the disaster began—the VCL deputy executive director notified the COR: terminate the backup responder services. The COR relayed this to the contracting officer. The contracting officer issued the termination in June.
Total damage: $11.2 million in payments for undelivered services. Plus $677,575 in settlement costs to unwind the contract.
The OIG excluded the settlement costs from its “questioned costs” calculation—the official figure for waste. So the number that gets reported to Congress, the number that matters for oversight, is $11.2 million.
But the real number is $11.9 million.
Systemic Red Flags
The OIG’s recommendations are measured but pointed:
- Have the Office of General Counsel determine whether to recoup the $11.2 million under the Contract Disputes Act.
- Implement policies to ensure information security requirements are accurately determined before contract award.
VA’s response was equally measured. They concurred with #1 and said they’d check with General Counsel by year-end 2026. On #2, they concurred “in principle” and said they’d already addressed the issue with the acquisition team. No systemic breakdown, they implied. Just an isolated error.
But the OIG identified two structural failures:
Control environment failure: “VA officials did not take timely action to prevent paying for services not received.”
Monitoring failure: “VA officials did not take timely action to modify the contract or terminate the call responder backup services.”
These aren’t compliance errors. These are institutional willingness to let money flow to a failed program.
The Missing Annual Assessment
Buried in the report is another missed opportunity. VA Handbook 6500.6 requires contractors handling sensitive information to conduct annual security self-assessments. The 2019 contract included this requirement.
The OIG found no evidence this assessment was ever conducted. The information security officer hadn’t seen it and thought it was no longer required.
This should have been the circuit-breaker. The first annual assessment after the July 2022 subcontractor change would have immediately identified that an Authority to Operate was needed. The assessment would have forced the acquisition team to confront the noncompliance in real time, in formal documentation.
Instead, the assessment was skipped. Another checkpoint failed. Another opportunity to catch the problem before $11.2 million was committed.
The Veterans Crisis Line Context
What makes this particularly damaging is that this happened to the Veterans Crisis Line—the service literally designed to prevent veteran suicide. The OIG estimated veteran suicide rate at 35 deaths per 100,000 veterans, nearly double the general population rate.
The VCL answered over 5 million contacts since inception. It works. It saves lives. That’s why backup capacity matters. It’s not a theoretical nice-to-have; it’s insurance against the system that saves lives failing at a moment when someone’s in acute crisis.
And $11.2 million—the amount wasted on a non-functional backup—represents federal resources that should have been flowing to actual crisis services, training, prevention, follow-up care.
Waste at this scale, in a program this critical, isn’t just a budgeting problem. It’s a failure of stewardship toward the people the VA is supposed to serve.
The Reorganization Unknown
As of June 2026, the VA was still in the middle of a reorganization that consolidated contracting specialists under the Office of Acquisition, Logistics, and Construction. The OIG report notes: “The effects of these changes on the issues identified in this report are not yet known.”
This is the unsaid part of the story. If restructuring doesn’t actually fix these problems, if acquisition staff just get moved around without changing procedures or accountability, then the next $11.2 million waste is probably already in the pipeline.
The question isn’t whether the VA has policies that should work. They do. VA Handbook 6500.6, VA Directive 6500, the Federal Acquisition Regulation—these documents contain the requirements to prevent exactly this scenario.
The question is whether the VA has the institutional discipline to enforce them.
Open Questions for Further Investigation
- Will General Counsel actually pursue recoupment? The OIG’s recommendation was for Office of General Counsel to determine if VA should recover the funds. VA said they’d report by December 31, 2026. Has that happened? What did they conclude?
- Is this common? How many other VA contracts have similar compliance gaps? The OIG report treats this as an isolated incident, but the conditions that created it—weak security checklist review, missing annual assessments, unclear authority—are systemic.
Conclusion: The Cost of Deferred Decisions
This wasn’t a case of fraud or deliberate theft. Nobody was running a scam. The contractor presumably believed it could eventually become compliant. VA officials presumably believed paying during the compliance period was reasonable, especially if they thought the money might ultimately be clawed back under the Contract Disputes Act.
But that reasoning collapses once you have a conference room full of people explicitly discussing “paying for services not received” and still choosing to let invoices through. The VA had tools to stop it. The contracting officer could have issued a stop-work order. The COR could have refused to approve invoices. VCL leadership could have formally declared the contractor noncompliant. Any of these actions would have prevented most of the $11.2 million in waste.
None happened. Instead, each official deferred the decision to someone else. The contracting officer waited for VCL guidance. The COR approved invoices based on the contracting officer’s advice. VCL waited for the contracting officer to act. This is how $11.2 million disappears in a federal bureaucracy: not through malice, but through diffused responsibility. When everyone’s supposed to be in charge, nobody is.
The open question now is whether that responsibility will ever be reassembled. VA has told the OIG it will decide by December 31, 2026 whether to seek recoupment of the $11.2 million. That decision point is more than an accounting exercise. It is a live test of whether the department is willing to say, in writing and with consequences, that paying for nothing is unacceptable even when the system has already moved on.
Meanwhile, the underlying tradeoff doesn’t change. Veterans’ resources remain finite. Every million dollars wasted on a defunct contractor backup is a million dollars not available for crisis responder training, community outreach, or the mental health services that support long-term veteran wellbeing. The Veterans Crisis Line will keep taking calls, and the VA’s internal backup will keep running, but the opportunity cost of this failure is already baked into future budgets.
The VA’s response to the OIG—concurring in principle while framing this as an isolated error—leans heavily on the hope that this is a one-off. The facts of the case suggest something else: a system that chose inaction when action was required, and that only fully acknowledged the problem once the money was gone and the audit was underway.
That leaves a larger, unresolved question hanging over the Veterans Crisis Line case: is this common? If the same weak controls, missing assessments, and blurred lines of authority exist elsewhere in VA contracting, then this episode is not an anomaly but a preview. Whether General Counsel pursues recoupment will tell us something. Whether the institution prevents the next version of this from happening at all will tell us everything.
Sources and Documentation
- VA Office of Inspector General, “Review of Contracted Backup Services for the Veterans Crisis Line,” Report No. 23-03464-146, September 1, 2026
- VA Office of Suicide Prevention, “2025 National Veteran Suicide Prevention Annual Report, Part 2: Report Findings,” March 2026
- VA Handbook 6500.6, “Contract Security”
- VA Directive 6500, “VA Cybersecurity Program”
- Federal Acquisition Regulation (FAR) 1.602-1, 1.602-2, 32.905, 52.212-4
- Contract Disputes Act, 41 U.S.C. §§ 7101–7109
- Interview materials and meeting notes reviewed by OIG investigators
