Security holes found in HealthCare.gov

WASHINGTON — Significant security vulnerabilities are still being uncovered in the Obama administration’s health-insurance website, nearly three months after the launch of HealthCare.gov.

Officials discovered two such vulnerabilities, known as “high findings,” within the past month, including one this week, Teresa Fryer, chief information security officer for the Center for Medicare and Medicaid Services, told the House Oversight Committee this week in an interview. Fryer said that both issues were being addressed.

The debate over the security of HealthCare.gov has raised questions about whether similar vulnerabilities exist in systems across the federal government. Because the Internal Revenue Service, the Social Security Administration and other agencies communicate with HealthCare.gov, security gaps in those agencies could, if discovered, allow hackers to penetrate their systems and indirectly compromise the functioning of the new health-care law, outside security experts say.

“It’s a standard technique,” said James Lewis, a cybersecurity scholar at the Center for Strategic and International Studies. “If the target is hard but it’s linked to an easy target, breaking into the easy target will get you into the hard target.”

While software vulnerabilities in Healthcare.gov have been documented, the potential risk stemming from the site’s interconnection with other federal systems has not. Officials from the White House, the Health and Human Services Department and others did not answer questions posed by The Washington Post about whether serious vulnerabilities exist in other federal IT systems linked to HealthCare.gov.

The strength of HealthCare.gov’s security has been the subject of ongoing rancor between Republicans and Democrats.

In recent weeks, House Oversight Committee Chairman Darrell Issa, R-Calif., has highlighted the site’s early vulnerabilities while accusing the White House of launching a premature product. Democrats, meanwhile, maintain that the bugs have been fixed and that the site is safe to use.

Of the two vulnerabilities identified by Fryer in her interview with Congress, one of them turned out to be false, said Patti Unruh, a spokeswoman for HHS. The contractor flagged the problem while performing an assessment in a test version of HealthCare.gov. But the real version contained safeguards that prevented the vulnerability from posing a security risk.

The other high finding involved a faulty piece of code that was successfully repaired, and there are no other significant security issues on the site, Unruh said.

Separately, Mitre, an independent contractor hired to test the security of HealthCare.gov, identified 28 security vulnerabilities in one of several tests it conducted in mid-October, according to the company.

Those tests also showed that hackers could have obtained people’s personal information, according to a letter written to HHS this week by Issa, who quoted information given to him by the company.

Administration officials said the issues identified by Mitre either did not pose a security risk or have since been fixed.

“There have been no successful security attacks on HealthCare.gov,” said HHS spokeswoman Joanne Peters, “and no person or group has maliciously accessed personally identifiable information from the site.”

Last month, Mitre agreed to send redacted copies of its test results to Issa in response to a subpoena. On Dec. 9, Issa requested the documents in an unredacted format.

In four letters to Issa, executives from Mitre warned that the unredacted documents could pose a risk to national security.

“In the wrong hands, this information could cause irreparable harm to the basic security architecture of HealthCare.gov,” Mitre chief executive Alfred Grasso wrote in a letter that accompanied the unredacted documents, “and potentially to the security of other CMS data networks that share attributes of this architecture.”

The Obama administration chimed in, with the White House counsel’s office urging Issa not to leak the documents for fear of endangering “other, similarly constructed federal IT system controls.”

HHS wrote in a letter to Issa: “Disclosure of these security documents could ⅛allow€ hackers to penetrate not only HealthCare.gov and the Federal Data Services Hub, but other Federal IT systems, some of which contain taxpayer information.”

A Republican aide for Issa would not rule out a release, but said that the lawmaker is working with outside analysts to determine the danger for himself.

House Democrats have demanded a classified meeting with Issa so that members of the IRS and the Department of Homeland Security could brief him on the danger of releasing the documents.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Traffic idles while waiting for the lights to change along 33rd Avenue West on Tuesday, April 2, 2024 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Lynnwood seeks solutions to Costco traffic boondoggle

Let’s take a look at the troublesome intersection of 33rd Avenue W and 30th Place W, as Lynnwood weighs options for better traffic flow.

A memorial with small gifts surrounded a utility pole with a photograph of Ariel Garcia at the corner of Alpine Drive and Vesper Drive ion Wednesday, April 10, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Death of Everett boy, 4, spurs questions over lack of Amber Alert

Local police and court authorities were reluctant to address some key questions, when asked by a Daily Herald reporter this week.

The new Amazon fulfillment center under construction along 172nd Street NE in Arlington, just south of Arlington Municipal Airport. (Chuck Taylor / The Herald) 20210708
Frito-Lay leases massive building at Marysville business park

The company will move next door to Tesla and occupy a 300,0000-square-foot building at the Marysville business park.

Edmonds City Council members answer questions during an Edmonds City Council Town Hall on Thursday, April 18, 2024 in Edmonds, Washington. (Olivia Vanni / The Herald)
Edmonds fire service faces expiration date, quandary about what’s next

South County Fire will end a contract with the city in late 2025, citing insufficient funds. Edmonds sees four options for its next step.

House Transportation Subcommittee Chairman Rep. Rick Larsen, D-Wash., speaks during a hearing on Capitol Hill in Washington, Wednesday, May 15, 2019, on the status of the Boeing 737 MAX aircraft.(AP Photo/Susan Walsh)
How Snohomish County lawmakers voted on TikTok ban, aid to Israel, Ukraine

The package includes a bill to ban TikTok if it stays in the hands of a Chinese company, which made one Everett lawmaker object.

A grizzly bear is seen on July 6, 2011 while roaming near Beaver Lake in Yellowstone National Park, Wyoming. The National Park and U.S. Fish and Wildlife services have released a draft plan for reintroducing grizzlies into the North Cascades.
Grizzlies to return to North Cascades, feds confirm

Under the final plan announced Thursday, officials will release three to seven bears every year. They anticipate 200 in a century.

ZeroAvia founder and CEO Val Mifthakof, left, shows Gov. Jay Inslee a hydrogen-powered motor during an event at ZeroAvia’s new Everett facility on Wednesday, April 24, 2024, near Paine Field in Everett, Washington. (Ryan Berry / The Herald)
ZeroAvia’s new Everett center ‘a huge step in decarbonizing’ aviation

The British-American company, which is developing hydrogen-electric powered aircraft, expects one day to employ hundreds at the site.

"Unsellable Houses" hosts Lyndsay Lamb (far right) and Leslie Davis (second from right) show homes in Snohomish County to Randy and Gina (at left) on an episode of "House Hunters: All Stars" that airs Thursday. (Photo provided by HGTV photo)
Snohomish twin stars of HGTV’s ‘Unsellable Houses’ are on ‘House Hunters’

Lyndsay Lamb and Leslie Davis show homes in Mountlake Terrace, Everett and Lynnwood in Thursday’s episode.

Logo for news use featuring Snohomish County, Washington. 220118
Oso man gets 1 year of probation for killing abusive father

Prosecutors and defense agreed on zero days in jail, citing documented abuse Garner Melum suffered at his father’s hands.

Everett Mayor Cassie Franklin steps back and takes in a standing ovation after delivering the State of the City Address on Thursday, March 21, 2024, at the Everett Mall in Everett, Washington. (Ryan Berry / The Herald)
In meeting, Everett mayor confirms Topgolf, Chicken N Pickle rumors

This month, the mayor confirmed she was hopeful Topgolf “would be a fantastic new entertainment partner located right next to the cinemas.”

Alan Edward Dean, convicted of the 1993 murder of Melissa Lee, professes his innocence in the courtroom during his sentencing Wednesday, April 24, 2024, at Snohomish County Superior Court in Everett, Washington. (Ryan Berry / The Herald)
Bothell man gets 26 years in cold case murder of Melissa Lee, 15

“I’m innocent, not guilty. … They planted that DNA. I’ve been framed,” said Alan Edward Dean, as he was sentenced for the 1993 murder.

Gus Mansour works through timing with Jeff Olson and Steven Preszler, far right, during a rehearsal for the upcoming annual Elvis Challenge Wednesday afternoon in Everett, Washington on April 13, 2022. (Kevin Clark / The Herald)
Hunka hunka: Elvis Challenge returns to Historic Everett Theatre May 4

The “King of Rock and Roll” died in 1977, but his music and sideburns live on with Elvis tribute artists.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.