Welcome to City-Data.com Forum!
U.S. CitiesCity-Data Forum Index
Go Back   City-Data Forum > General Forums > Politics and Other Controversies
 [Register]
Please register to participate in our discussions with 2 million other members - it's free and quick! Some forums can only be seen by registered members. After you create your account, you'll be able to customize options and access all our 15,000 new posts/day with fewer ads.
View detailed profile (Advanced) or search
site with Google Custom Search

Search Forums  (Advanced)
Reply Start New Thread
 
Old 12-28-2013, 09:19 AM
 
41,110 posts, read 25,719,480 times
Reputation: 13868

Advertisements

Despite the fact that private companies are required to publicly disclose any incidents. State laws also require many of the 14 state-run insurance exchanges to disclose such information, but no such law exists for the federally run exchange, which 36 states rely upon.

When asked HHS to ensure the exchanges would promptly notify affected enrollees in the event of a data breach or unauthorized access to the exchange’s databases. HHS responded: “We do not plan to include the specific notification procedures in the final rule. Consistent with this approach, we do not include specific policies for investigation of data breaches in this final rule.” In other words, the government doesn’t have to tell you about a security breach unless it decides it wants to.

Hiding the Hacking at HealthCare.gov
Reply With Quote Quick reply to this message

 
Old 12-28-2013, 09:25 AM
 
1,825 posts, read 1,418,542 times
Reputation: 540
There is a very simple answer and that is for states to create their own exchanges. Most of the states that use the federal exchange are Republican run so it would be simple for them to fix this problem if they wanted to.
Reply With Quote Quick reply to this message
 
Old 12-28-2013, 10:08 AM
 
26,660 posts, read 13,730,981 times
Reputation: 19118
I think its pretty clear at this point in time that entering ones data into the federal exchange is extremely risky. From the very beginning computer security experts have noted that the exchange is not well protected. One even called the website, "a hacker's wet dream". It's pretty disgusting that they have built a website that is not secure and barely works, forced many Americans into using it and then not doing the right thing in case of a security breach which would be to notify people. This is a huge mess.
Reply With Quote Quick reply to this message
 
Old 12-28-2013, 11:07 AM
 
33,016 posts, read 27,443,387 times
Reputation: 9074
Quote:
Originally Posted by petch751 View Post
Despite the fact that private companies are required to publicly disclose any incidents. State laws also require many of the 14 state-run insurance exchanges to disclose such information, but no such law exists for the federally run exchange, which 36 states rely upon.

When asked HHS to ensure the exchanges would promptly notify affected enrollees in the event of a data breach or unauthorized access to the exchange’s databases. HHS responded: “We do not plan to include the specific notification procedures in the final rule. Consistent with this approach, we do not include specific policies for investigation of data breaches in this final rule.” In other words, the government doesn’t have to tell you about a security breach unless it decides it wants to.

Hiding the Hacking at HealthCare.gov

And millions of Americans are deciding they don't have to sign up for Obamacare unless they decide they want to.

What happens when people start suing HHS after a data breach results in identity thefts?
Reply With Quote Quick reply to this message
 
Old 12-28-2013, 11:11 AM
 
33,016 posts, read 27,443,387 times
Reputation: 9074
Quote:
Originally Posted by Egbert View Post
There is a very simple answer and that is for states to create their own exchanges. Most of the states that use the federal exchange are Republican run so it would be simple for them to fix this problem if they wanted to.

Can states opt in at any time or is it too late once the federal exchange is established?
Reply With Quote Quick reply to this message
 
Old 12-28-2013, 11:15 AM
 
Location: Portland, Oregon
46,001 posts, read 35,161,783 times
Reputation: 7875
Quote:
Originally Posted by petch751 View Post
Despite the fact that private companies are required to publicly disclose any incidents. State laws also require many of the 14 state-run insurance exchanges to disclose such information, but no such law exists for the federally run exchange, which 36 states rely upon.

When asked HHS to ensure the exchanges would promptly notify affected enrollees in the event of a data breach or unauthorized access to the exchange’s databases. HHS responded: “We do not plan to include the specific notification procedures in the final rule. Consistent with this approach, we do not include specific policies for investigation of data breaches in this final rule.” In other words, the government doesn’t have to tell you about a security breach unless it decides it wants to.

Hiding the Hacking at HealthCare.gov
Aren't those 36 states mostly Republican governor run states? Guess Republican governors don't care about security or they would of had their state run their own exchange programs so that they could better monitor it themselves instead of relying on the federal government.
Reply With Quote Quick reply to this message
 
Old 12-28-2013, 11:22 AM
 
Location: Great State of Texas
86,052 posts, read 84,442,711 times
Reputation: 27720
Quote:
Originally Posted by Egbert View Post
There is a very simple answer and that is for states to create their own exchanges. Most of the states that use the federal exchange are Republican run so it would be simple for them to fix this problem if they wanted to.
27 states are not running their own exchanges.
Reply With Quote Quick reply to this message
 
Old 12-28-2013, 11:24 AM
 
33,016 posts, read 27,443,387 times
Reputation: 9074
Quote:
Originally Posted by urbanlife78 View Post
Aren't those 36 states mostly Republican governor run states? Guess Republican governors don't care about security or they would of had their state run their own exchange programs so that they could better monitor it themselves instead of relying on the federal government.

Did anyone expect that HHS would be so crass as to shrug at security issues?
Reply With Quote Quick reply to this message
 
Old 12-28-2013, 11:25 AM
 
Location: Great State of Texas
86,052 posts, read 84,442,711 times
Reputation: 27720
Quote:
Originally Posted by MissTerri View Post
I think its pretty clear at this point in time that entering ones data into the federal exchange is extremely risky. From the very beginning computer security experts have noted that the exchange is not well protected. One even called the website, "a hacker's wet dream". It's pretty disgusting that they have built a website that is not secure and barely works, forced many Americans into using it and then not doing the right thing in case of a security breach which would be to notify people. This is a huge mess.
HHS was told by the government IT security person it wasn't ready and HHS went forward anyway so they wouldn't miss the date.

She testified that to Congress. The memo to HHS was dated September 2013.
Reply With Quote Quick reply to this message
 
Old 12-28-2013, 11:26 AM
 
Location: Portland, Oregon
46,001 posts, read 35,161,783 times
Reputation: 7875
Quote:
Originally Posted by freemkt View Post
Did anyone expect that HHS would be so crass as to shrug at security issues?
Sure, we have a do nothing Congress with tons of Republicans bragging about not wanting to create new laws.
Reply With Quote Quick reply to this message
Please register to post and access all features of our very popular forum. It is free and quick. Over $68,000 in prizes has already been given out to active posters on our forum. Additional giveaways are planned.

Detailed information about all U.S. cities, counties, and zip codes on our site: City-data.com.


Reply
Please update this thread with any new information or opinions. This open thread is still read by thousands of people, so we encourage all additional points of view.

Quick Reply
Message:


Over $104,000 in prizes was already given out to active posters on our forum and additional giveaways are planned!

Go Back   City-Data Forum > General Forums > Politics and Other Controversies
Similar Threads

All times are GMT -6.

© 2005-2024, Advameg, Inc. · Please obey Forum Rules · Terms of Use and Privacy Policy · Bug Bounty

City-Data.com - Contact Us - Archive 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37 - Top