Affordable Care Act Website Security Tests Unfinished Before Lau - WSPA.com

Affordable Care Act Website Security Tests Unfinished Before Launch

Posted: Updated:
WASHINGTON, D.C. - A CBS News analysis finds key tests to ensure the security and privacy of customer information on troubled Obamacare website fell behind schedule. 

A deadline for final security plans was delayed three times over the summer, and final top-to-bottom security tests never were finished before the launch.

All of that is adding to concerns about the safety of personal information on the site.

Technology experts say this website did not go through proper security testing before it went live on October 1 -- and they've shared with CBS News several flaws that could expose personal information. Now we're starting to see real-like examples of what can go wrong.

With critics openly mocking the Obama administration about problems with HealthCare.gov, officials insist on one thing: at least the website is safe. White House Press Secretary Jay Carney said, "Consumers can trust that their information is protected by stringent security standards."

South Carolina attorney Thomas Dougall is not so sure. He said: "My information is out there, and I want it deleted from their website."

Dougall and his wife signed up on the website in October, but over the weekend got a disturbing call about a man in North Carolina who also registered, and was shocked to get the Dougalls' eligibility letters, including their names and home address.

"It's just a system that we've continually been told was secure and now I've found out it's not secure," Dougall said.

A spokeswoman for the Department of Health and Human Services confirmed: "An incident involving the personal information of one consumer was reported...and we took immediate steps. We identified a piece of software code that needed to be fixed and that fix is now in place."

But other problems are not fixed. Software experts tell CBS News they have identified multiple security issues, including with user names and passwords.

We gave one technology expert the real HealthCare.gov user name of a CBS employee. Within seconds, he identified the specific security questions she selected to reset her password.

Shawn Henry, president of the cyber security firm Crowdstrike Services and the former assistant director of the FBI's Cyber Division, said: "If somebody's got the ability to look at the source code and be able to reverse engineer that and identify what somebody's personal questions are, that should be of concern."

On "CBS This Morning," CBS News correspondent Jan Crawford reported House Intelligence Committee Chairman Rep. Mike Rogers, R-Mich., tells her this is just one more reason the website should be taken down and tested for security vulnerabilities --and Democrats are also making that point -- concerns that will likely be raised when Health and Human Services Secretary Kathleen Sebelius testifies again before Congress on Wednesday.

  • Top StoriesTop StoriesMore>>

  • Swinney Responds To Group Over Faith

    Swinney Responds To Group Over Faith

    Wednesday, April 23 2014 5:06 PM EDT2014-04-23 21:06:58 GMT
    "I have recruited and coached players of many different faiths," wrote Swinney. "Players of any faith or no faith at all are welcome in our program.""I have recruited and coached players of many different faiths," wrote Swinney. "Players of any faith or no faith at all are welcome in our program."
    Clemson football coach Dabo Swinney says players "of any faith or no faith at all are welcome in our program." Swinney issued a written response after a group recently accused his program of violating players' constitutional rights by promoting Christianity.
    Clemson football coach Dabo Swinney says players "of any faith or no faith at all are welcome in our program." Swinney issued a written response after a group recently accused his program of violating players' constitutional rights by promoting Christianity.
  • No Suspension For Simpsonville Mayor Eichor Until May

    No Suspension For Simpsonville Mayor Eichor Until May

    Wednesday, April 23 2014 4:50 PM EDT2014-04-23 20:50:52 GMT
    Simpsonville Mayor Perry Eichor won't be suspended from office by Governor Haley until at least next month. The governor indicated she would suspend Eichor once she got indictments against him.
    Simpsonville Mayor Perry Eichor won't be suspended from office by Governor Haley until at least next month. The governor indicated she would suspend Eichor once she got indictments against him.
  • MUGS: 10 Arrested, 10 Sought In Oconee Co. Drug Roundup

    MUGS: 10 Arrested, 10 Sought In Oconee Co. Drug Roundup

    Wednesday, April 23 2014 4:44 PM EDT2014-04-23 20:44:24 GMT
    Officials in Oconee County made several arrests as part of a continuing drug operation. Many more remain on the loose. It's part of the Oconee County Sheriff's Office's "Operation Infinity." Wednesday marked the fourth installment of the major drug roundup.
    Officials in Oconee County made several arrests as part of a continuing drug operation. Many more remain on the loose. It's part of the Oconee County Sheriff's Office's "Operation Infinity." Wednesday marked the fourth installment of the major drug roundup.
Powered by WorldNow

250 International Dr.
Spartanburg, S.C. 29303

Telephone: 864.576.7777
Fax: 864.587.5430
Email: webmaster@wspa.com

Can't find something?
Powered by WorldNow
All content © Copyright 2000 - 2014 Media General Communications Holdings, LLC. A Media General Company.