Security holes found in HealthCare.gov

WASHINGTON — Significant security vulnerabilities are still being uncovered in the Obama administration’s health-insurance website, nearly three months after the launch of HealthCare.gov.

Officials discovered two such vulnerabilities, known as “high findings,” within the past month, including one this week, Teresa Fryer, chief information security officer for the Center for Medicare and Medicaid Services, told the House Oversight Committee this week in an interview. Fryer said that both issues were being addressed.

The debate over the security of HealthCare.gov has raised questions about whether similar vulnerabilities exist in systems across the federal government. Because the Internal Revenue Service, the Social Security Administration and other agencies communicate with HealthCare.gov, security gaps in those agencies could, if discovered, allow hackers to penetrate their systems and indirectly compromise the functioning of the new health-care law, outside security experts say.

“It’s a standard technique,” said James Lewis, a cybersecurity scholar at the Center for Strategic and International Studies. “If the target is hard but it’s linked to an easy target, breaking into the easy target will get you into the hard target.”

While software vulnerabilities in Healthcare.gov have been documented, the potential risk stemming from the site’s interconnection with other federal systems has not. Officials from the White House, the Health and Human Services Department and others did not answer questions posed by The Washington Post about whether serious vulnerabilities exist in other federal IT systems linked to HealthCare.gov.

The strength of HealthCare.gov’s security has been the subject of ongoing rancor between Republicans and Democrats.

In recent weeks, House Oversight Committee Chairman Darrell Issa, R-Calif., has highlighted the site’s early vulnerabilities while accusing the White House of launching a premature product. Democrats, meanwhile, maintain that the bugs have been fixed and that the site is safe to use.

Of the two vulnerabilities identified by Fryer in her interview with Congress, one of them turned out to be false, said Patti Unruh, a spokeswoman for HHS. The contractor flagged the problem while performing an assessment in a test version of HealthCare.gov. But the real version contained safeguards that prevented the vulnerability from posing a security risk.

The other high finding involved a faulty piece of code that was successfully repaired, and there are no other significant security issues on the site, Unruh said.

Separately, Mitre, an independent contractor hired to test the security of HealthCare.gov, identified 28 security vulnerabilities in one of several tests it conducted in mid-October, according to the company.

Those tests also showed that hackers could have obtained people’s personal information, according to a letter written to HHS this week by Issa, who quoted information given to him by the company.

Administration officials said the issues identified by Mitre either did not pose a security risk or have since been fixed.

“There have been no successful security attacks on HealthCare.gov,” said HHS spokeswoman Joanne Peters, “and no person or group has maliciously accessed personally identifiable information from the site.”

Last month, Mitre agreed to send redacted copies of its test results to Issa in response to a subpoena. On Dec. 9, Issa requested the documents in an unredacted format.

In four letters to Issa, executives from Mitre warned that the unredacted documents could pose a risk to national security.

“In the wrong hands, this information could cause irreparable harm to the basic security architecture of HealthCare.gov,” Mitre chief executive Alfred Grasso wrote in a letter that accompanied the unredacted documents, “and potentially to the security of other CMS data networks that share attributes of this architecture.”

The Obama administration chimed in, with the White House counsel’s office urging Issa not to leak the documents for fear of endangering “other, similarly constructed federal IT system controls.”

HHS wrote in a letter to Issa: “Disclosure of these security documents could ⅛allow€ hackers to penetrate not only HealthCare.gov and the Federal Data Services Hub, but other Federal IT systems, some of which contain taxpayer information.”

A Republican aide for Issa would not rule out a release, but said that the lawmaker is working with outside analysts to determine the danger for himself.

House Democrats have demanded a classified meeting with Issa so that members of the IRS and the Department of Homeland Security could brief him on the danger of releasing the documents.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

City of Everett Engineer Tom Hood, left, and City of Everett Engineer and Project Manager Dan Enrico, right, talks about the current Edgewater Bridge demolition on Friday, May 9, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
How do you get rid of a bridge? Everett engineers can explain.

Workers began dismantling the old Edgewater Bridge on May 2. The process could take one to two months, city engineers said.

Smoke from the Bolt Creek fire silhouettes a mountain ridge and trees just outside of Index on Sept. 12, 2022. (Olivia Vanni / The Herald)
County will host two wildfire-preparedness meetings in May

Meetings will allow community members to learn wildfire mitigation strategies and connect with a variety of local and state agencies.

Helion's 6th fusion prototype, Trenta, on display on Tuesday, July 9, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Helion celebrates smoother path to fusion energy site approval

Helion CEO applauds legislation signed by Gov. Bob Ferguson expected to streamline site selection process.

Vehicles travel along Mukilteo Speedway on Sunday, April 21, 2024, in Mukilteo, Washington. (Ryan Berry / The Herald)
Mukilteo cameras go live to curb speeding on Speedway

Starting Friday, an automated traffic camera system will cover four blocks of Mukilteo Speedway. A 30-day warning period is in place.

Carli Brockman lets her daughter Carli, 2, help push her ballot into the ballot drop box on the Snohomish County Campus on Tuesday, Nov. 5, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Here’s who filed for the primary election in Snohomish County

Positions with three or more candidates will go to voters Aug. 5 to determine final contenders for the Nov. 4 general election.

Students from Explorer Middle School gather Wednesday around a makeshift memorial for Emiliano “Emi” Munoz, who died Monday, May 5, after an electric bicycle accident in south Everett. (Aspen Anderson / The Herald)
Community and classmates mourn death of 13-year-old in bicycle accident

Emiliano “Emi” Munoz died from his injuries three days after colliding with a braided cable.

Danny Burgess, left, and Sandy Weakland, right, carefully pull out benthic organisms from sediment samples on Thursday, May 1, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
‘Got Mud?’ Researchers monitor the health of the Puget Sound

For the next few weeks, the state’s marine monitoring team will collect sediment and organism samples across Puget Sound

Cal Brennan, 1, sits inside of a helicopter during the Paine Field Community Day on Saturday, May 17, 2025 in Everett, Washington. (Will Geschke / The Herald)
Children explore world of aviation at Everett airport

The second annual Paine Field Community Day gave children the chance to see helicopters, airplanes and fire engines up close.

A person walks past Laura Haddad’s “Cloud” sculpture before boarding a Link car on Monday, Oct. 14, 2024 in SeaTac, Washington. (Olivia Vanni / The Herald)
Sound Transit seeks input on Everett bike, pedestrian improvements

The transit agency is looking for feedback about infrastructure improvements around new light rail stations.

A standard jet fuel, left, burns with extensive smoke output while a 50 percent SAF drop-in jet fuel, right, puts off less smoke during a demonstration of the difference in fuel emissions on Tuesday, March 28, 2023 in Everett, Washington. (Olivia Vanni / The Herald)
Sustainable aviation fuel center gets funding boost

A planned research and development center focused on sustainable aviation… Continue reading

Dani Mundell, the athletic director at Everett Public Schools, at Everett Memorial Stadium on Wednesday, May 14, 2025 in Everett, Washington. (Will Geschke / The Herald)
Everett Public Schools to launch girls flag football as varsity sport

The first season will take place in the 2025-26 school year during the winter.

A “SAVE WETLANDS” poster is visible under an seat during a public hearing about Critical Area Regulations Update on ordinance 24-097 on Wednesday, May 14, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Snohomish County Council passes controversial critical habitat ordinance

People testified for nearly two hours, with most speaking in opposition to the new Critical Areas Regulation.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.