{"database": "press", "table": "releases", "rows": [["https://www.hatch.senate.gov/public/index.cfm/releases?ContentRecord_id=f5e42641-9f64-48db-b913-e98cd549aae4", "Senators Ask Secretary Sebelius Whether Privacy, Security Standards Met For Obamacare Website", "2013-10-29", "2013", "2013-10", "Republican", "House", "UT", "Orrin Hatch", "H000338", "www.hatch.senate.gov", null, null, "legacy", "Today the eleven Republican members of the Senate Finance Committee, led by Ranking Member Orrin Hatch (R-Utah), wrote to Department of Health and Human Services (HHS) Secretary Kathleen Sebelius asking whether all federal privacy and security standards were met prior to the launch of HealthCare.gov, the website to sign up for ObamaCare.\u00a0\r\nIn a letter to Secretary Sebelius, the Senators wrote, \u201c[W]e are troubled that day after day more issues arise which illustrate that the website was simply not ready to launch on October 1.\u00a0 While we recognize that the website\u2019s operational issues are being worked on and will likely be resolved eventually, serious questions remain as to the privacy and security of the very detailed personal information being transmitted through the Federally-Facilitated Marketplace (FFM) and what testing, if any, occurred or is occurring to ensure that information is secure.\u201d\r\nThe Senators asked Sebelius to provide answers and information to a series of questions detailing what level of security and privacy measures were undertaken prior to the launch of the website to safeguard the privacy of those Americans signing up for coverage through healthCare.gov.\u00a0 \u00a0\r\nSenators Chuck Grassley (R-Iowa), Mike Crapo (R-Idaho), Pat Roberts (R-Kan.), Mike Enzi (R-Wyo.), John Cornyn (R-Texas), John Thune (R-S.D.), Richard Burr (R-N.C.), Johnny Isakson (R-Ga.), Rob Portman (R-Ohio), and Pat Toomey (R-Penn.) joined Hatch in sending the letter today.\r\nThe letter to the Secretary is below and can be found HERE: \u00a0\u00a0\r\nThe Honorable Kathleen Sebelius  U.S. Department of Health and Human Services  200 Independence Avenue, S.W.  Washington, D.C. 20201\r\nDear Secretary Sebelius:\r\nAs Members of the Committee on Finance (Committee), which has jurisdiction over implementation of the Patient Protection and Affordable Care Act (PPACA), we are seeking information about the various types of testing which were utilized to ensure that the healthcare.gov website and underlying system (hereinafter collectively referred to as \u201cwebsite\u201d) met all Federal privacy and security standards before going live on October 1, 2013. Additionally, we are requesting detailed information about security threats received since the website launch, as well as measures taken by your agency and contractors to ensure website security. \r\nThe Administration\u2019s Chief Technology Officer, Todd Park, publicly stated on September 11, 2013, that \u201cafter over two years of work, it [healthcare.gov] is built and ready for operation, and we have completed security testing and certification to operate.\u201d[1] Despite these and other assurances, we are troubled that day after day more issues arise which illustrate that the website was simply not ready to launch on October 1.\u00a0 While we recognize that the website\u2019s operational issues are being worked on and will likely be resolved eventually, serious questions remain as to the privacy and security of the very detailed personal information being transmitted through the Federally-Facilitated Marketplace (FFM) and what testing, if any, occurred or is occurring to ensure that information is secure.\r\nIt is our understanding that each Centers for Medicare &amp; Medicaid Services (CMS) system is required by law to obtain an Authority to Operate (ATO) certification that attests the system has met all testing requirements before it is placed into operation.\u00a0 CMS\u2019 own internal procedures require that \u201c. . . security controls be operational, effective, managed, and continuously monitored.\u00a0 Controls must meet mandatory requirements, as defined in the current CMS Information Security Acceptable Risk Safeguards (ARS) CMS Minimum Security Requirements (CMSR).\u201d[2]\u00a0 Additionally, as the head of the Department of Health and Human Services (HHS), you are responsible for ensuring that your agency\u2019s information systems, including the website, fully comply with security requirements imposed by the Federal Information Security Management Act of 2002 (FISMA).[3]\u00a0 The website must also comply with the Office of Management and Budget\u2019s (OMB) implementing policies including Appendix III of OMB circular A-130, and guidance and standards from the Department of Commerce\u2019s National Institute of Standards and Technology.\r\nTo help us better understand how CMS ensured that these and other standards were met, please provide us with the following information:\r\n \r\nDescribe in detail the security testing that was completed on all aspects of the healthcare.gov website before October 1, 2013.\u00a0 Please include copies of all testing certification or other documents that indicate the results of all testing that occurred.\r\nPlease provide all timelines, dashboards or other tracking mechanisms developed to track the testing requirements.\r\nWas CMS/HHS granted a Privacy Act exemption by the Office of Management and Budget (OMB) for the website or any related applications?\u00a0 If so, please provide documentation for the exemption.\r\nWere any other security testing exemptions granted for the website or any related applications by OMB?\u00a0 If so, please provide all supporting documentation.\r\nWas all testing completed to meet the standards set forth by the FISMA?\u00a0 Please provide copies of all testing results and certifications that show all FISMA standards were met.\r\nWas a Privacy Impact Assessment (PIA) completed by CMS prior to the website going live?\u00a0 If so, please provide a copy of the PIA.\r\nAre reports generated on a regular basis regarding the security of the website and its related applications?\u00a0 How often are reports generated and what office (and whom) within CMS received those reports?\r\nWhat alerts are generated if an outside entity attempts to inappropriately gain access to sensitive information submitted to the website?\u00a0 \r\n\r\nSince October 1, 2013, how many times has an outside entity attempted to inappropriately or unlawfully gain access to sensitive information?\r\nHave any of these attempts been successful? \r\nProvide a log of all alerts, or whatever method of tracking is used to track alerts, as well as the outcome of each alert (i.e., attempt was successful, not successful, etc.).\r\nWhich contractors have access to user data submitted to the website?\r\n\r\nHow many employees at each contractor have access to this data?\r\nProvide names of the contractors that are responsible for staffing and operating all call centers associated with the website.\r\nWith respect to each contractor retained by CMS to work on the website or the call center:\r\n\r\nWhat measures are in place to ensure that these contractors appropriately secure data?\r\nWhat training have these employees completed regarding how to handle sensitive data?\r\nTo date, have there been any instances when contractors have inappropriately disclosed or used data?\r\nIf so, what steps has CMS taken against the contractor and/or the employee?\r\nWhat security clearance is required for contractor employees who handle personally identifiable information (PII)?\r\n\r\nHave all contractor employees been cleared to handle PII?\u00a0 If not, when does CMS anticipate that all employees will be cleared?\r\nIf any contractor employees are working with only a temporary clearance, what additional steps has CMS taken to ensure that these employees do not improperly disclose sensitive data?\r\nTo your knowledge, have there been any improper disclosures of PII submitted by users of the website or the call center?\u00a0 If so, explain the circumstances and CMS\u2019 reaction.\r\nIn the event that the website becomes no longer functional or suffers a loss of PII, does CMS have a disaster recovery plan?\u00a0 If so, please provide a copy of the plan.\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n\r\n \r\nWherever possible, please provide the information requested in electronic format.\u00a0 Thank you for your prompt attention to this request and we respectfully request receiving all information by no later than December 3, 2013.\u00a0\r\nSincerely,\r\n\n  \r\n\r\n[1] http://www.businessweek.com/news/2013-09-11/obamacare-computer-network-completes-security-tests-u-dot-s-dot-says.\r\n\r\n\r\n[2] CMS Risk Management Handbook, Volume II, Procedure 7.8, August 17, 2012 (Document Number: CMS-CISO-2012-vII-pr7.8).", 1, "2026-03-30T12:14:52Z", "2026-03-30T12:14:52Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.hatch.senate.gov/public/index.cfm/releases?ContentRecord_id=f5e42641-9f64-48db-b913-e98cd549aae4"], "units": {}, "query_ms": 2.484317868947983, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}