‘A hacker broke into part of the HealthCare.gov insurance enrollment website in July and uploaded malicious software, according to federal officials.
Investigators found no evidence that consumers' personal data were taken or viewed during the breach, federal officials said. The hacker appears only to have gained access to a server used to test code for HealthCare.gov, the officials said.
The server was connected to more sensitive parts of the website that had better security protections, the officials said. That means it would have been possible, if difficult, for the intruder to move through the network and try to view more protected information, an official at the Department of Health and Human Services said. There is no indication that happened, and investigators suspect the hacker didn't intend to target a HealthCare.gov server.
The prospect nevertheless raised concerns among federal officials because of how easily the intruder gained access and how much damage could have occurred.’
‘Washington officials said they are concerned an intruder gained access to the HealthCare.gov network through a basic security flaw. The server had low security settings because it was never meant to be connected to the Internet, the HHS official said. When the hacker broke in, it was only guarded by a default password, which often is easy to crack.
"There was a door left open," the official said.
The department discovered the break-in weeks later on Aug. 25 during a daily security scan. Buried amid lines of computer log files were data showing the test server had been contacted by the outside Internet, which wasn't supposed to happen.
Lawmakers first raised security concerns about HealthCare.gov when it launched nearly a year ago. At the time, then-HHS Secretary Kathleen Sebelius said the department had a plan in the event of a security breach. Other hacking attempts reportedly have been made, but none appear to have been successful before this.
"It is full of data that criminals covet," said Rep. Joe Barton (R., Texas), who opposes the health-care law. "Handing private information over to the government is bad enough. People should at least know it won't fall into the hands of hackers."‘ - Hacker Breached HealthCare.gov Insurance Site, WSJ, 09/04/2014
The entire article appears in the link below:
http://online.wsj.com/articles/hacker-breached-healthcare-gov-insurance-site-1409861043?cb=logged0.7588583977035412
Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts
Sunday, September 7, 2014
Friday, August 22, 2014
ACA/Obamacare: The Ongoing Saga of Cyber Security and the ACA Web Site
Make special note of 3:04 to 3:39 of the video regarding the description of the pathways along which one's sensitive personal information travels.
Sunday, December 8, 2013
Wednesday, October 16, 2013
The Fortunate Few ACA Applicants -or- The Unfortunate Few?
Consider for a moment if one had a web site that supposedly has massive web page hits. Consider said web site is simultaneously massively malfunctioning. Would hackers be attracted? Rather likely.
Is one lucky or unlucky to have managed to navigate the broken ACA web site and have fed in the massive personal information which is demanded in the application process? Succeeding in applying for coverage on the ACA web site may be hazardous to your financial health.
Take a gander at the video above and note John McAfee's comments.
Updated 11/10/2013:
Exclusive: HealthCare.gov Users Warn of Security Risk, Breach of Privacy, Heritage.org, 11/02/2013
http://blog.heritage.org/2013/11/02/exclusive-healthcare-gov-users-warn-of-security-risk-breach-of-privacy/?utm_source=heritagefoundation&utm_medium=email&utm_campaign=&utm_content=&utm_source=heritagefoundation&utm_medium=email&utm_content=headline&utm_campaign=saturday1311096
Labels:
ACA broken web site,
hackers,
identity theft,
John McAfee,
personal data
Subscribe to:
Posts (Atom)
