Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Wednesday, September 17, 2014

ACA/Obamacare: GAO Reports that CMS Hasn’t Paid Proper Attention to Healthcare.gov Security Risks

‘HealthCare.gov has continuing security frailties that put users' sensitive personal information at risk, a government watchdog is set to tell Congress this week.

Despite the federal government's efforts to protect the website from breaches, "weaknesses remained in the security and privacy protections applied to HealthCare.gov and its supporting systems," said the Government Accountability Office.

The agency released a report Tuesday on the security of the site, through which millions of Americans bought coverage under the health law last year and which millions more will be urged to use.

"Until these weaknesses are fully addressed, increased and unnecessary risks remain of unauthorized access, disclosure, or modification of the information collected and maintained by Healthcare.gov and related systems, and the disruption of service provided by the systems," according to the GAO report, published ahead of testimony to be given at a Thursday hearing of the Republican-led House Oversight and Government Reform Committee.

The warnings come two weeks after the Department of Health and Human Services disclosed that a hacker had broken into part of the site and uploaded malicious software during the summer.’

‘GAO said the CMS failed to ensure system-security plans were complete and was relying on a draft data-use agreement with a contractor tasked with verifying users' identities.

Moreover, the agency skipped some assessments of privacy risks and didn't perform comprehensive security testing of the HealthCare.gov system that used all of the security controls specified by the government ahead of the site's launch. Testing remained incomplete as of June 2014, GAO said.

The agency also hadn't set up an alternate processing site for HealthCare.gov systems that would allow them to be recovered in the event of a disruption, the watchdog found.

Other weaknesses included lax enforcement of password-strength requirements and inconsistent application of security patches to the system.

Certain systems supporting the site's infrastructure weren't restricted from accessing the Internet, which increased the risk that unauthorized users could get to data.

Moreover, one of the federal agency's contractors hadn't properly secured its administrative network, which could allow unauthorized access to the HealthCare.gov system.

Many of the problems stemmed from the agency's disagreements about security roles and responsibilities with the various contractors, states and federal agencies that exchange information as part of the HealthCare.gov system, the watchdog said.’ - Federal Health Care Website Faces Security Risks, Watchdog Finds, WSJ, 09/16/2014

 

Link to the entire article appears below:

http://online.wsj.com/articles/federal-health-care-website-faces-security-risks-watchdog-finds-1410895828



Update 09/18/2014: Government Insider Warned of HealthCare.gov Security Risks: ‘I Am Tired of the Cover Ups’, dailysignal.com

http://dailysignal.com/2014/09/18/government-insider-warned-healthcare-gov-security-risks-tired-cover-ups/?utm_source=heritagefoundation&utm_medium=email&utm_campaign=morningbell&mkt_tok=3RkMMJWWfF9wsRons63JZKXonjHpfsX56OgvWa%2BylMI%2F0ER3fOvrPUfGjI4DSMBlI%2BSLDwEYGJlv6SgFQrLBMa1ozrgOWxU%3D

Friday, August 22, 2014

ACA/Obamacare: The Ongoing Saga of Cyber Security and the ACA Web Site

Make special note of 3:04 to 3:39 of the video regarding the description of the pathways along which one's sensitive personal information travels.

Sunday, July 13, 2014

ACA/Obamacare: Where Web Security is Job 57

‘A Romanian attacker hacked the Vermont health exchange’s development server last December, gaining access at least 15 times and going undetected for a month, according to records obtained by National Review Online.

CGI Group, the tech firm hired to build Vermont Health Connect, described the risk as “high” in a report about the attack. It also found possible evidence of sophisticated “counter-forensics activity performed by the attacker to cover his/her tracks.” ‘ - Another Security Breach for Obamacare, NRO, 07/01/2014

Link to entire article appears below:

http://www.nationalreview.com/article/381640/another-security-breach-obamacare-jillian-kay-melchior

Thursday, December 19, 2013

Oversight Report on Obamacare Navigator Program Reveals Mismanagement and Lax Oversight, Committee on Oversight & Government Reform, U.S. House of Representatives, 12/16/2013

"WASHINGTON – The House Oversight and Government Reform Committee today released a new staff report on the Obama Administration’s Navigator and Assister program in conjunction with today’s field hearing in Dallas, Texas. The report explains how the Administration’s serious mismanagement of these outreach programs exposes Americans to fraud and poses a threat to the safety of consumers’ personal information.

The Navigator program was created by ObamaCare as an outreach program to encourage and facilitate enrollment in health insurance exchanges. The Assister program was created by the Administration with dubious legal authority as a way around ObamaCare’s clear statutory prohibition on using federal exchange establishment funds on Navigators.

Months before the launch of ObamaCare on October 1, the Oversight Committee initiated an investigation into potential problems with the Navigator and Assister program. The Committee released a preliminary staff report in September that highlighted the significant risks for fraud, abuse, and misinformation due to the lack of background checks, inadequate training standards, and weak Administration oversight plan for Navigators and Assisters.

The new report makes clear that U.S. Department of Health and Human Services (HHS) officials lacked a contingency plan for the Navigator and Assister program after HealthCare.gov failed, leaving consumers open to the risk of identity theft due to confusion surrounding enrollment for health exchanges."

Link to the entire Congressional report appears below:

http://oversight.house.gov/release/oversight-report-obamacare-navigator-program-reveals-mismanagement-lax-oversight/


 


 


Sunday, December 8, 2013

Healthcare.gov: Stop Sending Paper Applications! Use Our Unsecured Website! Damn the Cybersecurity, Full Speed Ahead!

'So it's come to this. During the past week, the Associated Press reported today, "Federal health officials," meaning "the Obama administration," began "urging" (i.e., "telling") counselors and navigators around the country to stop using paper applications for Obamacare coverage, "because of concerns those applications would not be processed in time." It seems that either Team Obama or AP (my money is on AP) doesn't mind risking criticism for waiting to let this news out until a weather- and sports-dominated Saturday. It's apparently okay to keep those who don't know any better, i.e., those who went to the trouble of printing a paper app on their own, in the dark.

So you shouldn't use paper. But the vastly under-reported but inarguable fact is that HealthCare.gov isn't secure; experienced IT security experts strongly warn against using it. So consumers shouldn't be going online either, meaning that there's no defensible way to apply for coverage before the end of the year.’ - As Feds Say to Stop Using Paper Obamacare Apps, AP Again 'Forgets' That HealthCare.gov Is Not Secure, Newbusters, 12/07/2013


‘For the love of Jiminy Cricket, how much cybersecurity incompetence are American citizens expected to accept and excuse while also footing the $660 million bill? Online security experts say the “new and improved” Healthcare.gov site may actually be more insecure now than before it was fixed!

An operational progress report quoted Jeffrey Zients, a management consultant on repairs to the Obamacare site, as stating, “The bottom line -- HealthCare.gov on December 1st is night and day from where it was on October 1st.” Well if this is “day,” then it’s an Arctic Alaskan daytime with no sunlight as “experts” blindly attempt to bolt on security to a system that was developed without a care about the security or privacy of Americans.

David Kennedy, founder and principal security consultant of TrustedSec, warned that the Healthcare.gov was not secure. In fact, Kennedy previously told CNBC that it’s hard to bolt on security after a site is developed and that “no security was ever built into the Obamacare site.”

So how many of the security risks were eliminated now that the administration “fixed” the site? None according to what Kennedy told the Washington Free Beacon. “It doesn’t appear that any security fixes were done at all.” He added:

“There are a number of security concerns already with the website, and that’s without even actually hacking the site, that’s just a purely passive analysis of [it]. We found a number of critical exposures that were around sensitive information, the ability to hack into the site, things like that. We reported those issues and none of those appear to have been addressed at all.”

“They said they implemented over 400 bug fixes,” he said. “When you recode the application to fix these 400 bugs—they were rushing this out of the door to get the site at least so it can work a little bit—you’re introducing more security flaws as you go along with it because you don’t even check that code.”

Well that’s just peachy keen and that’s before considering the “hacker” threat. But, hey, it’s not like the feds are required to notify citizens if there is a breach; after all, it’s so much easier to leave that headache to each state. Just ask Vermont, since Vermont Health Connect had to admit to a security breach that allowed “improper access to another user’s Social Security number and other data.”

Kennedy also said that:

the team working on Healthcare.gov is more likely to hide its security flaws than address them. When it was revealed that the most popular searches on the website were hack attempts—confirmed by entering a semicolon in the search bar—the website simply removed the tool.

“The top results were hacker attempts,” Kennedy said. “Their fix for it wasn’t, ‘Hey let’s restrict people from inputting malicious code into the website,’—because that’s how hackers break into websites—it was, ‘we’re just going to completely disable that entire function completely, and not even show the search results back.’”

“We’ve deployed 12 large, dedicated servers,” states the operation progress report. Oh goodie gumdrops, it “can now handle about as many shoppers as the average custom T-shirt site,” pointed out Human Events. The site has “a remodeled 404 Error page that pretends to be a ‘waiting room,’ where you can ‘queue up’ and leave an email address to be notified” when it’s your turn to fill out all your private info.

Julie Bataille, Director of Communications, Centers for Medicare & Medicaid Services, summed up the newly “fixed” site’s progress report [pdf] as having an upgraded and reconfigured firewall that protects the system while allowing “more than five times the network throughput.” The “improved shopping” experience on Healthcare.gov supposedly can handle 50,000 people logged on to the website at once, and “more than 800,000 visitors a day;” but even with a lower number of “shoppers,” the Associated Press reported that many visitors faced “the same old sputters and even crashes.” ‘ - Healthcare.gov more vulnerable to hacking & privacy breaches after 'fix', Computerworld, 12/03/2013



Links to above mentioned articles appear below:

http://newsbusters.org/blogs/tom-blumer/2013/12/07/feds-say-stop-using-paper-obamacare-apps-ap-again-forgets-healthcaregov-

http://blogs.computerworld.com/application-security/23226/healthcaregov-more-vulnerable-hacking-privacy-breaches-after-fix