{"database": "press", "table": "releases", "rows": [["https://web.archive.org/web/20140221084855/http://black.house.gov/press-release/case-you-missed-it-hiding-hacking-healthcaregov", "In Case You Missed It: Hiding the Hacking at Healthcare.gov", "2013-12-23", "2013", "2013-12", "Republican", "House", "TN", "Diane Black", "B001273", "web.archive.org", null, null, "legacy", "In Case You Missed It: Hiding the Hacking at Healthcare.gov  \n\tby John Fund\nChristmas shoppers were stunned to learn last Thursday that computer hackers had made off with the names and other personal info of some 40 million Target customers. Some of the pilfered information is reportedly being sold on the black market, prompting JP Morgan Chase to limit purchases and cash withdrawals on debit cards owned by recent Target shoppers.\nBut at least Target informed its customers of the security breach, as it is required by federal law to do. HealthCare.gov faces no such requirement; it need never notify customers that their personal information has been hacked or possibly compromised. The Department of Health and Human Services was specifically asked to include a notification requirement in the rules it designed for the health-care exchanges, but HHS declined.\nThe Federal Register\u00a0tells the tale\u00a0about what happened on March 27, 2012, at a meeting on the issue.\nAt that meeting, two commenters asked HHS to ensure the exchanges would promptly notify affected enrollees in the event of a data breach or unauthorized access to the exchange\u2019s databases. One commenter suggested that a full investigation be launched each time such a breach occurred, with the goal of holding hackers legally and financially accountable for breaking into the website.\nAccording to a\u00a0report by the group Watchdog.org, HHS responded: \u201cWe do not plan to include the specific notification procedures in the final rule. Consistent with this approach, we do not include specific policies for investigation of data breaches in this final rule.\u201d In other words, the government doesn\u2019t have to tell you about a security breach unless it decides it wants to \u2014 despite the fact that private companies are required to publicly disclose any incidents. State laws also require many of the 14 state-run insurance exchanges to disclose such information, but no such law exists for the federally run exchange, which 36 states rely upon.\nThe Watchdog report notes that it\u2019s through state laws that we\u2019ve learned the most about security problems in the exchanges. In September, the Minneapolis\u00a0Star Tribune\u00a0reported that \u201can official at MNsure, the state\u2019s new online health insurance exchange, acknowledged it had mishandled private data.\u201d A Minnesota insurance broker received an e-mail containing a trove of confidential information on more than 2,400 people, including their Social Security numbers and business addresses. A staffer at MNsure had accidentally sent the e-mail to him. \u201cThe more I thought about it, the more troubled I was,\u201d Jim Koester, the recipient of the data, told the\u00a0Star Tribune. \u201cWhat if this had fallen into the wrong hands? It\u2019s scary.\u201d\nLast July, Dave Jones, California\u2019s insurance commissioner and a Democrat, expressed his concerns about inadequate security processes on his state\u2019s exchange, one of the better-run ones. If unscrupulous people get hold of Social Security numbers, health records, or other private information of consumers \u201cwe can have a real disaster on our hands,\u201d Jones told the AP. He has declined further comment since then.\nIn Florida, GOP governor Rick Scott is troubled that privacy guidelines will be ignored in the rush to try to enroll his state\u2019s 3.5 million uninsured residents. He wrote to Congress this fall expressing worry that the thousands of \u201cnavigators\u201d hired by private groups posed a possible security threat, given that they undergo no federal background checks: \u201cAs the push for \u2018navigators\u2019 to sign up Floridians on the federal health insurance exchange becomes more frenzied, the need to safeguard the personal information Floridians submit to the \u2018navigators,\u2019 and its use in a \u2018federal data hub,\u2019 is taking on paramount importance.\u201d The workers the federal government hired to conduct the 2010 census were fingerprinted and underwent background checks. Not so the Obamacare \u201cnavigators.\u201d\nIt\u2019s not as if the Obama administration wasn\u2019t notified of security concerns about its website. MITRE Corporation, an HHS contractor, alerted the agency that 19 unaddressed security vulnerabilities plagued the website before its launch on October 1. Last week, Teresa Fryer, the chief information-security officer for the Centers for Medicare and Medicaid Services (CMS), told the House Oversight Committee that she recommended that HealthCare.gov not launch on October 1 because of serious security concerns. \u201cMy evaluation of this was a high risk,\u201d she\u00a0told\u00a0the committee in a private interview. Tony Trenkle, the project manager for the website, declined along with Fryer to sign the Authority to Operate (ATO) license needed to launch the site, which is why it had to be signed by Marilyn\u00a0Tavenner, the political appointee in charge of CMS. Trenkle retired on November 13 and has declined to talk with reporters. But Fryer said her own concerns about security remain unaddressed because there have been \u201ctwo high findings of risk\u201d \u2014 the most serious warning level \u2014 in tests conducted in just the past few weeks. A CMS spokesman says both problems have been resolved.\nFew cyber-security experts I spoke with for this article have much confidence that the government will quickly or competently reveal any security breaches on HealthCare.gov. On October 30, HHS Secretary Kathleen Sebelius testified under oath before Congress that \u201cno senior official reporting to me ever advised me that we should delay\u201d the launch of the website. But Fryer told the House committee that she had personally briefed Sebelius\u2019s top aides on her findings on September 20, ten days before the site launched. While it may be true that Fryer and Trinkle don\u2019t report directly to Sebelius, they both declined to sign off on the ATO needed to launch the site. At best, Sebelius has demonstrated a complete inability to follow or manage the security crisis, though it\u2019s her responsibility to do so.\nAccording to Bruce Webster, a consultant who has advised companies for 40 years on IT issues, the administration\u2019s policy appears to be \u201csecurity through obscurity,\u201d a largely discredited approach. He told me:\nThey do not want to talk about their security measures; they do not want to talk about their security breaches; they do not want to inform affected citizens of compromised personal information. Their attitude reminds me of Lily Tomlin\u2019s character Ernestine as an AT&amp;T operator back when AT&amp;T had a monopoly: \u201cWe don\u2019t care. We don\u2019t have to. We\u2019re the phone company.\u201d\nCongresswoman Diane Black, a Tennessee Republican, is fed up with the obfuscation and evasion surrounding HealthCare.gov. She has introduced the \u201cFederal Data Breach Notification Act,\u201d which would require that the Federal Trade Commission notify anyone whose personal information has been jeopardized. \u201cThe federal government imposes these same rules on the private sector, yet they have gone out of their way to avoid imposing this basic diligence on their own Obamacare exchange,\u201d she told me.\nIf the House and Senate have any basic concern for the privacy rights of Americans, they will catapult her bill onto President Obama\u2019s desk ASAP. It is horrible news that Target\u2019s security vulnerabilities allowed hackers to filch the names and personal information of customers. But it will be even worse if the federal government can continue to keep people in the dark about its own security breaches, leaving many Americans with big, fat targets on their backs for identity thieves.\n\u2014 John Fund is a national-affairs columnist for\u00a0National Review Online.\nBackground: \nRELEASE: Black Introduces the Federal Exchange Data Breach Notification Act of 2013\n###\nCongressman Diane Black represents Tennessee\u2019s 6th Congressional District. She has been a registered nurse for more than 40 years and serves on the House Ways and Means and Budget Committees.", 1, "2026-03-30T12:14:52Z", "2026-03-30T12:14:52Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://web.archive.org/web/20140221084855/http://black.house.gov/press-release/case-you-missed-it-hiding-hacking-healthcaregov"], "units": {}, "query_ms": 1.5498248394578695, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}