Cyber Security Experts: HealthCare.gov Isn't Secure, Government's Doing Nothing About It
January 16, 2014 1:38 PM
comment(s) - last by
Over 20 vulnerabilities were reported shortly after HealthCare.gov launched, but the government has neglected to address them
HealthCare.gov was a mess the first couple of months after its October launch, and while many of
appear to be clearing up; experts say there are gaping holes in the website's security.
According to a report from
, cyber security experts have called the U.S. government out on its lack of effort to fix security problems with HealthCare.gov, which were pointed out shortly after the site's launch last year.
David Kennedy, head of computer security consulting firm TrustedSec LLC, is leading the crusade against the government in an effort to get these security holes patched. He said that he reported over 20 vulnerabilities shortly after HealthCare.gov launched on October 1, but the government has neglected to address them.
One of the first vulnerabilities Kennedy found was that hackers could easily obtain the full names and email addresses of Americans who signed up with HealthCare.gov. He said it took him five minutes to write a computer program that imported about 70,000 records in only four minutes.
Further, Kennedy discovered from a fellow security researcher that hackers could upload malicious code to HealthCare.gov, allowing them to take control of other HealthCare.gov users' computers to steal and/or modify data as well as attack other computers.
"These issues are alarming," said Kennedy.
[SOURCE: NBC News]
Kennedy and three other security experts first presented these security flaws at a November Science Committee hearing, where they suggested that the site be shut down immediately.
The Centers for Medicare & Medicaid Services, which oversees HealthCare.gov's operations, responded by saying no threats have been detected regarding the health insurance site.
"To date there have been no successful security attacks on HealthCare.gov and no person or group has maliciously accessed personally identifiable information from the site," said the federal agency. "Security testing is conducted on an ongoing basis using industry best practices to appropriately safeguard consumers' personal information."
For weeks after HealthCare.gov's initial launch, the site experienced slow speeds and loading messages preventing users from shopping the health insurance marketplace.
Back in November, Republican investigators with the House of Representatives Energy and Commerce Committee launched an investigation of the HealthCare.gov's troubles, and found emails from the project manager back in July 2013 that warned of potential issues that could arise. HealthCare.gov project manager Henry Chao sent an email out about the site's main contractor, CGI Federal, on July 16 saying that he "needs to feel more confident they are not going to crash the plane at take-off."
Staff shortages, problems with contractors and software issues were among the issues discussed prior to HealthCare.gov's launch.
More recently, HealthCare.gov's first contractor, CGI Federal -- which launched the site back in October -- was
booted in favor of Accenture
. CGI Federal's government contract for HealthCare.gov will expire February 28, 2014, and the contractor said it would not be renewed (more than likely because of all the website's problems).
Accenture's new one-year contract is worth $45 million USD for the project's initial phase, with a total value of $90 million by the time it expires.
This article is over a month old, voting and posting comments is disabled
RE: Corrupt Administration
1/16/2014 6:27:39 PM
Fact check some of your claims before posting, please:
As far as the rest, can you name a president in the last 50 years that has a completely clean bill when it comes to promises, cover ups, and spending? By these standards, every president of the last 50 years is a turd. Further, there is a strong degree of likelihood that any candidate that will likely win in 2016 will fail the same tests.
I'm still waiting for people who complain about "a turd of a president" to come up for a real solution that hasn't already been tried to remedy the issues that exist for every president in the oval office.
By the measure of democracy, the president isn't the turd. It's the turd of a citizenry (including yourself) that has failed to do anything about it (except, complain, of course).
RE: Corrupt Administration
1/17/2014 10:56:02 AM
The raindrop never feels responsible for the flood. You can go back to sleep now.
“We do believe we have a moral responsibility to keep porn off the iPhone.” -- Steve Jobs
Government Hires Contractor Accenture for HealthCare.gov, Kicks CGI Federal Out
January 13, 2014, 10:15 AM
HealthCare.gov Project Manager Sent Concerns About the Site Back in July
November 15, 2013, 11:40 AM
Google Knocked by Analysts, But Shows Strokes of Brilliance in Q1 2014
April 18, 2014, 2:33 PM
Google Street View and reCAPTCHA Get Smarter with New Algorithm
April 17, 2014, 9:02 AM
Mt. Gox CEO Refuses to Come to the U.S. in Financial Crimes Probe
April 16, 2014, 3:50 PM
Mark Zuckerberg: Facebook Home Reception Slower than Expected, Social Graph Will Pick Up
April 16, 2014, 2:00 PM
FBI's Facial Recognition Database to Have 52 Million Criminal, Non-Criminal Photos by 2015
April 15, 2014, 2:56 PM
Microsoft's Anti-Google "Scroogled" Campaign May Have Ended
April 15, 2014, 2:44 PM
Most Popular Articles
Cities to Carpoolers: Sharing Your Car is Illegal, We Will Seize Your Cars
April 4, 2014, 9:17 PM
iPad Exploiter is Freed by Federal Appeals Court
April 11, 2014, 7:40 PM
A-10 Warthog May Live to Fight Another Day with Support from Lawmakers
April 14, 2014, 9:41 AM
Taiwan's AOU Claims to Have World's Highest-Res. OLED Smartphone Display
April 11, 2014, 1:44 PM
EFF: NSA May Have Used IRC Botnets to Exploit Heartbleed for Last Two Years
April 14, 2014, 4:43 PM
Latest Blog Posts
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
Global Cyber Espionage Concerns Reveal Growing Cyber Armies
Nov 29, 2013, 11:04 AM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information