Oregon Audit warns Aging Corrections IT Systems Pose Public Safety Risks

Published: August 11, 2026

Economic Development/RegulationGeneral Government ServicesInformation TechnologyInformation TechnologyOREGON

An Oregon state audit found that decades-old technology used by the Department of Corrections is creating growing operational and public safety risks.

The Oregon Department of Corrections (DOC) is facing concerns over aging, mission-critical IT systems that support inmate records, sentencing, parole and probation, security operations and other core functions. A July 2026 audit from the Oregon Secretary of State found that many DOC applications are custom-built on outdated platforms and programming languages, making them increasingly difficult to maintain or modify.

These systems operate around the clock across Oregon’s 12 correctional institutions and all 36 county community corrections offices, supporting roughly 12,000 adults in custody as well as thousands of state and county employees. Auditors warned that a major system failure could disrupt prison operations, staff safety and information sharing with parole officers, state police and victim-notification systems.

Modernization has been complicated by limited funding and the need to maintain high levels of security, reliability and interoperability with other public-safety applications. Oregon funded a new electronic health records system in 2024, but legacy applications remain in need of replacement. The DOC plans to transition many of its aging applications toward more modern, vendor-supported commercial and cloud-based solutions.

The audit recommends that the DOC address the operational and security risks associated with its aging systems and conduct an exercise simulating a major failure of its Corrections Information System. The results could help the agency calculate the consequences of continued delays and strengthen future modernization funding requests to lawmakers. The findings demonstrate how legacy IT can become a broader public-safety and operational risk, rather than simply an internal technology issue.

Source: StateScoop

Source: Oregon Secretary of State Audit Report: 2026-19