Site last updated: Sunday, September 13, 2026

Log In

Reset Password
Butler County's great daily newspaper

Data warehouse raises privacy fears

Personal info on millions stored by gov't

WASHINGTON — A government data warehouse stores personal information forever on millions of people who seek coverage under President Barack Obama’s health care law, including those who open an account on HealthCare.gov but don’t sign up for coverage.

At a time when major breaches have become distressingly common, the vast scope of the information — and the lack of a clear plan for destroying old records — have raised concerns about privacy and the government’s judgment on technology.

“A basic privacy principle is that you don’t retain data any longer than you have to,” said Lee Tien, a senior staff attorney with the Electronic Frontier Foundation. “The more data you keep, the more harm an attacker or unauthorized person can do.”

Electronic record-keeping systems are standard for businesses and government agencies. But they are supposed to have limits on how long data is kept.

The health care system, known as MIDAS, is described on a federal website as the “perpetual central repository” for information that the Affordable Care Act authorizes federal agencies to collect.

“Data in MIDAS is maintained indefinitely at this time,” says another document, a government privacy assessment dated Jan. 15.

It lists the kinds of information stored, including names, Social Security numbers, birthdates, addresses, phone numbers, passport numbers, employment status and financial accounts.

Before HealthCare.gov went live in 2013, Obama administration officials assured lawmakers and the public that an individual’s personal information would be used mainly to determine eligibility for coverage, and that the nation’s newest social program would have a limited impact on privacy.

Marilyn Tavenner, the Medicare administrator at the time, told a congressional hearing that the program’s technology infrastructure was designed “to minimize all possible security vulnerability.”

In the new wired world, every few weeks brings news of another security breach. Personnel records of millions of federal employees, including background information for security clearances, were compromised in the latest attacks making headlines. Earlier this year, health insurer Anthem reported that information on 80 million customers was hacked.

The Obama administration says MIDAS is essential to the smooth operation of the health care law’s insurance markets and meets or exceeds federal security and privacy standards

MIDAS has been criticized in opinion articles by former Social Security commissioner Michael Astrue, a Republican who disapproves of Obama administration policies. Independent experts on technology and privacy echoed some of the concerns.

“I accept they have an operational reason, if not a legal obligation, to keep data for a reasonable period,” said Astrue, commissioner from 2007-2013. But there’s no justification for keeping data indefinitely, he added.

Michelle De Mooy, deputy director for consumer privacy at the Center for Democracy & Technology, said consumers have no way of knowing that their data is being routed to MIDAS. It’s not mentioned on the HealthCare.gov website.

Although the policy does not mention MIDAS specifically, the administration says its general functions are described.

MIDAS stands for Multidimensional Insurance Data Analytics System. It’s owned by the federal Centers for Medicare and Medicaid Services and operated by CACI.

More in National News

Subscribe to our Daily Newsletter

* indicates required
TODAY'S PHOTOS