{"database": "press", "table": "releases", "rows": [["https://web.archive.org/web/20140108114616/http://black.house.gov:80/press-release/black-meehan-seek-answers-irs-security-testing", "Black, Meehan Seek Answers on IRS Security Testing", "2013-12-09", "2013", "2013-12", "Republican", "House", "TN", "Diane Black", "B001273", "web.archive.org", null, null, "legacy", "Washington, D.C. \u2013 Congressmen Diane Black (R-TN-06) and Patrick Meehan (R-PA-07) sent a letter to Danny Werfel, the Acting Commissioner for the Internal Revenue Service (IRS), in response to a report from the Treasury Inspector General for Tax Administration (TIGTA). The IRS is responsible for administering tax credits under Obamacare and TIGTA has reported that \u201ccritical\u201d elements of the security controls failed during testing, potentially risking the exposure of sensitive taxpayer information. Below is the text of their letter, or a digital copy can be found here.\n\u00a0\nThe Honorable Daniel I. Werfel\nActing Commissioner, the Internal Revenue Service\nU.S. Department of the Treasury\n1111 Constitution Avenue, NW, Room 3241\nWashington, DC 20224\n\u00a0\nDear Commissioner Werfel:\nAmericans face a great threat to their personal security online, as it is widely understood that information systems can be hacked.\u00a0 Bad actors are constantly in search of opportunities to exploit vulnerabilities in our infrastructure, many of which are related to misconfigured system components and software flaws.\u00a0 Given this reality, we are concerned for the integrity and security of the sensitive personal data transmitted through the new health insurance exchanges. \u00a0As you know, the Internal Revenue Service (IRS) is responsible for administering the premium tax credits (PTCs) established under the Affordable Care Act (ACA).\u00a0 Now that the health care exchanges are open for business, it is imperative that the IRS has processes in place to keep taxpayer information secure.\nRecently, the Treasury Inspector General for Tax Administration (TIGTA) released a report that was completed on September 27, 2013 \u2013 days before the launch of the Healthcare.gov website.\u00a0 TIGTA determined that IRS has completed development and testing for the Premium Tax Credit Computation Engine (PTC-CE), which will calculate the PTC for eligible Americans.\u00a0 However, \u201ccritical\u201d elements of the security controls failed during testing.\u00a0 Specifically, the report found that twelve controls were only partially implemented during the testing process.\u00a0 The ACA infrastructure components included in those twelve security controls also failed during the Security Controls Assessment, as they did not include the baseline configurations and mandatory configuration settings required by the National Institute of Standards (NIST) and Internal Revenue Manual (IRM) guidelines.\nThe report also found that Change Management Guidelines were not always adhered to when approved baseline security requirements were removed from the PTC Project.\u00a0 Just one of seven baseline requirements was removed from the PTC Project in accordance with the process outlined in the ACA Program Configuration Management Plan, which requires a change request (CR) and change impact assessment.\u00a0\u00a0 The IRS\u2019s IT Cybersecurity organization management stated that the organization does not have access to the CR Tracking System tool.\u00a0 Thus, it cannot ensure that CRs are approved, processed, and is \u201cunaware of when final changes to the baseline security requirements were implemented.\u201d\u00a0 This raises concerns as to whether the IRS can accurately determine how changed requirements will affect the security controls and operation of the PTC-CE.\nTIGTA recommended that the IRS IT Cybersecurity organization resolve or develop a plan with specific corrective actions and time periods for the failed security tests that were reviewed as part of the ACA Security Assessment and Authorization.\u00a0 TIGTA states this resolution or action plan \u201cis needed to ensure the IRS is addressing vulnerabilities in information systems that can be traced to software flaws and misconfigurations of system components for the PTC Project and across other information technology projects being developed\u201d under the ACA.\nWe are also concerned that the TIGTA report indicates that during audit fieldwork, IT Cybersecurity organization officials \u201ccould not provide documentation to verify the corrective measures for the failed test controls.\u201d\u00a0 According to the report, the IRS disagrees with the recommendation to develop an action plan and did not reference the audit findings that triggered the recommendation.\nWe find IRS\u2019 refusal to adopt a corrective action plan of serious concern as the sensitive personal information of American taxpayers may be at risk.\u00a0 This audit raises important questions as to whether the IRS can successfully protect taxpayer data against fraud and abuse.\u00a0 Therefore, to better understand how the IRS plans to securely and successfully transmit taxpayer data, we respectfully request you provide a written explanation of the IRS\u2019s process plan, along with copies of the documented policies for resolving the failed security tests.\u00a0 We also request an explanation on how the IRS coordinates with the ACA Program to ensure that change management guidelines are followed and that the PTC-CE operation is not impaired.\nThank you in advance for your attention to this letter.\u00a0 We look forward to your prompt reply.\u00a0\n\u00a0\nSincerely,\n\u00a0\nPatrick Meehan\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Diane Black\nMember of Congress\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Member of Congress\n####", 1, "2026-03-30T12:14:52Z", "2026-03-30T12:14:52Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://web.archive.org/web/20140108114616/http://black.house.gov:80/press-release/black-meehan-seek-answers-irs-security-testing"], "units": {}, "query_ms": 0.8990268688648939, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}