Site last updated: Thursday, July 23, 2026

Log In

Reset Password
Butler County's great daily newspaper

Report: Health care site still vulnerable

The HealthCare.gov Web portal used by millions to get health insurance under President Barack Obama's law logged 316 security incidents in less than 18 months, according to a report released Wednesday.
It has logged 316 security incidents

WASHINGTON — The Web portal used by millions of consumers to get health insurance under President Barack Obama’s law has logged more than 300 cybersecurity incidents and remains vulnerable to hackers, nonpartisan congressional investigators said Wednesday.

The Government Accountability Office said none of the 316 security incidents appeared to have led to the release of sensitive data on HealthCare.gov, such as names, birth dates, addresses, Social Security numbers, financial information, or other personal information.

Most of the incidents over nearly 18 months seemed to have involved electronic probing by hackers. HealthCare.gov offers subsidized private health insurance for people who don’t have access to workplace coverage.

Although GAO said the administration is making progress, its report concluded that security flaws “will likely continue to jeopardize the confidentiality, integrity and availability of HealthCare.gov.”

Investigators identified weaknesses protecting sensitive information that flows through a key part of the system, called the data services hub. Operating behind the scenes, the hub pings federal agencies such as Social Security, IRS and Homeland Security to verify the personal details of consumers.

The report also found “significant weaknesses” in health insurance sites operated by states, which connect to the data hub. Currently, 12 states and Washington, D.C., run their own websites.

Federal computer systems are frequent targets for hackers. The HealthCare.gov incidents took place between October 2013 and March 2015.

HealthCare.gov’s data hub is one of the administration’s major technology projects, and has generally been regarded as successful. Even as the consumer-facing part of the system crashed during the botched rollout of the health care law in 2013, the hub continued to operate smoothly.

However, GAO said it found shortcomings, including insufficiently tight restrictions on “administrator privileges” that allow a user broad access throughout the system, inconsistent use of security fixes and an administrative network that was not properly secured.

Overall, 41 of the security incidents involved personal information that was either not properly secured or was exposed to someone who wasn’t authorized to see it. Nearly all of those were classified as having a moderately serious impact.

In another type of incident, a list of government-employee account IDs, including passwords, was transmitted to staffers in an unencrypted e-mail. That prompted a crash effort to create new passwords.

More in Business

Subscribe to our Daily Newsletter

* indicates required
TODAY'S PHOTOS