Audit finds slipshod cybersecurity at HealthCare.gov

WASHINGTON — The government stored sensitive personal information on millions of health insurance customers in a computer system with basic security flaws, according to an official audit that uncovered slipshod practices.

The Obama administration said it acted quickly to fix all the problems identified by the Health and Human Services inspector general’s office. But the episode raises questions about the government’s ability to protect a vast new database at a time when cyberattacks are becoming bolder.

Known as MIDAS, the $110-million system is the central electronic storehouse for information collected under President Barack Obama’s health care law.

It doesn’t handle medical records. But according to a government privacy impact statement, it does include names, Social Security numbers, birthdates, addresses, phone numbers, passport numbers, employment status and financial account information of customers on HealthCare.gov and state insurance marketplaces.

“It sounds like a gold mine for ID thieves,” said Jeremy Gillula, staff technologist for the Electronic Frontier Foundation, a civil liberties group focused on technology. “I’m kind of surprised that this information was never compromised.”

The flaws uncovered by auditors included issues of security policy — where mistakes can have bigger consequences — as well as 135 database vulnerabilities, of which nearly two dozen were classified as potentially severe or catastrophic.

Among the policy mistakes: User sessions were not encrypted, contrary to standard practice on financial websites. “Not doing so is inexcusable for such sensitive data,” said Michelle De Mooy, deputy director for consumer privacy at the Center for Democracy & Technology, an Internet rights group.

MIDAS is an internal system operated by the federal Centers for Medicare and Medicaid Services, the agency that administers the health care law. The acronym stands for Multidimensional Insurance Data Analytics System. Officials say it’s an electronic backbone, essential to the smooth operation of the health care law’s insurance markets.

Currently about 10 million people are covered through HealthCare.gov and state marketplaces offering taxpayer-subsidized private policies. But MIDAS also keeps information on many others, including former customers. Their data is retained for years.

Before HealthCare.gov went live in 2013, Obama administration officials assured Congress and the public that individuals’ information would be used mainly to determine eligibility for coverage, and that the government intended to store the minimum amount of personal data possible. Things don’t seem to have turned out that way.

Among the technical problems uncovered by the audit:

—Using a shared read-only account for access to the database that contained individuals’ personal information. Gillula said such a shared account creates a serious vulnerability because if data is stolen, it’s much more difficult to tell who was looking at what information, and when.

—Failure to disable “generic accounts” used for maintenance or other special access during testing, an oversight that can foster complacency about security practices when a system becomes operational.

—Failure to conduct certain automated vulnerability scans that mimic known cyberattacks and could reveal weaknesses in MIDAS and the systems supporting it.

—Database weaknesses. A total of 135 such vulnerabilities — oftentimes software bugs— were discovered by the inspector general’s vulnerability scans. Of these, 22 were classified as high risk, meaning they could have potentially severe or catastrophic fallout, and 62 as medium risk.

“MIDAS collects, generates and stores a high volume of sensitive consumer information, and it is critical that it be properly secured,” the inspector general’s report reads. A summary omitting specific details of the vulnerabilities was posted on the IG’s website this week.

In a written response to the audit, Medicare administrator Andy Slavitt said that “the privacy and security of consumers’ personally identifiable information are a top priority” for his agency. Slavitt said all of the high vulnerabilities were addressed within a week of being identified, and that all of the IG’s recommendations have been fully implemented.

The Medicare agency is conducting weekly vulnerability assessments of MIDAS, and an annual security review, Slavitt said.

However, the episode indicates how some technical and security issues from the program’s chaotic rollout in 2013 may still linger. Back then, the consumer-facing side of HealthCare.gov went live without a completed security certification.

Gillula, the technology expert, said he doesn’t question the administration’s intentions. “I’m sure they wanted to do the right thing,” he said. “But regardless of what they wanted, did they accomplish it? There certainly were some gaps.”

___

Online:

HHS Inspector General’s report — http://tinyurl.com/pycaesf

MIDAS privacy impact statement — http://tinyurl.com/nl79328

More in News

(Juneau Empire file photo)
Aurora forecast through the week of Nov. 10

These forecasts are courtesy of the University of Alaska Fairbanks’ Geophysical Institute… Continue reading

Tlingit “I Voted” stickers are displayed on a table at the voting station at the Mendenhall Mall during early voting in the Nov. 5 general election. (Laurie Craig / Juneau Empire file photo)
Ranked choice voting repeal coming down to wire, Begich claims U.S. House win in latest ballot counts

Repeal has 0.28% lead as of Saturday, down from 0.84% Thursday — an 895-vote gap with 9,000 left to count.

(Mark Sabbatini / Juneau Empire file photo)
Juneau man arrested on suspicion of murdering 1-month-old infant after seven-month investigation

James White, 44, accused of killing child with blunt blow to head in a motel room in April.

A map shows properties within a proposed Local Improvement District whose owners could be charged nearly $8,000 each for the installation of a semi-permanent levee to protect the area from floods. (City and Borough of Juneau map)
Hundreds of property owners in flood zone may have to pay $7,972 apiece for Hesco barrier levee

City, property owners to split $7.83M project cost under plan Juneau Assembly will consider Monday.

Dan Allard (right), a flood fighting expert for the U.S. Army Corps of Engineers, explains how Hesco barriers function at a table where miniature replicas of the three-foot square and four-foot high barriers are displayed during an open house Thursday evening at Thunder Mountain Middle School to discuss flood prevention options in Juneau. (Mark Sabbatini / Juneau Empire)
Residents express deluge of concerns about flood barriers as experts host meetings to offer advice

City, U.S. Army Corps of Engineers say range of protection options are still being evaluated

U.S. Geological Survey geologist Geoffrey Ellis stands on Oct. 29 by a poster diplayed at the University of Alaska Fairbanks that explains how pure hydrogen can be pooled in underground formations. Ellis is the leading USGS expert on geologic hydrogen. He was a featured presenter at a three-day workshop on geologic hydrogen that was held at UAF. (Yereth Rosen/Alaska Beacon)
Alaska scientists and policymakers look to hydrogen as power source of the future

The key to decarbonization may be all around us. Hydrogen, the most… Continue reading

(Michael Penn / Juneau Empire file photo)
Police calls for Wednesday, Nov. 13, 2024

This report contains public information from law enforcement and public safety agencies.

Gov. Doug Burgum of North Dakota speaks to reporters at the National Constitution Center in Philadelphia in advance of the presidential debate between former President Donald Trump and Vice President Kamala Harris, Sept. 10, 2024. President-elect Trump has tapped Burgum to lead the Interior Department, leading the new administration’s plans to open federal lands and waters to oil and gas drilling. (Kenny Holston/The New York Times)
Trump nominates governor of North Dakota — not Alaska — to be Interior Secretary

Doug Burgum gets nod from president-elect, leaving speculation about Dunleavy’s future hanging

Most Read