Advertisement

Aging IT systems present significant public safety risks across Oregon correctional facilities, audit finds

A recent audit found that decades-old systems threaten the corrections department's ability to manage its prisons safely.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
prison watchtower
(Getty Images)

Oregon auditors are urging lawmakers to treat aging prison technology as a public safety priority, warning that obsolete information systems supporting the state’s correctional facilities pose growing operational risks if they are not modernized.

The audit, released by the Oregon Secretary of State last week, found that the Department of Corrections relies on decades-old mission-critical systems that support inmate records, sentencing, parole and probation, security operations and other core functions. Auditors argued that the decades-old systems threaten the department’s ability to manage prisons safely, collect meaningful operational data and implement reforms.

To mitigate risks posed by its outdated Corrections Information System and Offender Management System, the audit recommends the department conduct a tabletop exercise simulating catastrophic system failure and use those findings to strengthen future funding requests to the legislature.

Department officials said the audit’s findings, which paint a stark picture of the department’s technology environment, came as no surprise.

Advertisement

“We’ve worked with the Secretary of State’s office for the last two years or so as they’ve compiled this audit,” Harvey Matthews, Oregon DOC’s spokesperson, said in an interview. “We went line by line with their recommendations and agreed with each one.”

The department’s IT system doesn’t just keep track of people in prison — it shares critical information with parole officers, state police and victim notification systems so agencies are working from the same records. However, the audit found many of DOC’s applications are custom-built, rely on outdated programming languages and have become increasingly difficult to maintain. Those limitations make it harder to respond to policy changes, replace paper-based workflows and collect reliable performance data, while increasing the consequences of a major system outage.

Since the systems operate continuously across Oregon’s 12 correctional institutions and support all 36 county community corrections offices, auditors warned that prolonged failures could affect prison operations, staff safety and public safety. Matthews said future upgrades would also make it easier to coordinate housing, education and treatment services for people leaving prison while tracking whether those programs help reduce repeat offenses.

“We all need to be operating with the same information,” Matthews said, adding that future systems should help agencies become “less siloed” and more data-driven. “This COBOL-based system built in 1989 is not great.”

Though Oregon lawmakers funded the department’s electronic health records project in 2024, which moved paper copies of medical and behavioral files to a new digital records system across its 12 facilities, Matthews said replacing other legacy applications presents others challenges. Any replacement system must balance security, interoperability and reliability while integrating with victim notification systems and other public safety applications. And funding is scarce —meaning the department is often forced to compete against other statewide IT priorities, including K-12 school projects and cybersecurity initiatives.

Advertisement

“Security features are paramount, there is a very high level expectation for both security and infallibility,” Matthews explained. “We have approached both the executive branch and the legislative branch about our aging systems, both IT and structural, for many years.”

Among the audit’s standout recommendations is that DOC conduct a tabletop exercise modeling the complete failure of its Corrections Information System to better understand operational consequences and inform future funding initiatives and policy changes. Matthews noted the agency regularly conducts emergency management tabletop exercises but was unsure whether any had specifically focused on a major IT outage: “If we knew that, we’d be a lot smarter and be better with our resources.”

Matthews said the audit should force lawmakers to view corrections technology as an essential public safety investment rather than solely a “back-office” IT upgrade: “This should be a call to action for elected leaders. Nobody should be okay with crumbling facilities and staffing shortages and obsolete IT systems. That just should not exist in Oregon.”

Sophia Fox-Sowell

Written by Sophia Fox-Sowell

Sophia Fox-Sowell reports on artificial intelligence, cybersecurity and government regulation for StateScoop. She was previously a multimedia producer for CNET, where her coverage focused on private sector innovation in food production, climate change and space through podcasts and video content. She earned her bachelor’s in anthropology at Wagner College and master’s in media innovation from Northeastern University.

Latest Podcasts