Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

HealthCare.gov Ducked Final Security Requirements Before Launch
CBS News ^ | 11/4/13 | CBS News

Posted on 11/04/2013 10:30:29 PM PST by Lmo56

CBS News) WASHINGTON -- The health care website went down again Monday for an hour and a half, and no one is sure why. It's being taken offline on purpose every night from 1 a.m. to 5 a.m. for repairs. Millions are still having trouble buying insurance on it, and it turns out that even when the website works, it may not be secure enough to protect privacy.

As HealthCare.gov was being developed, crucial tests to ensure the security and privacy of customer information fell behind schedule.

CBS News analysis found that the deadline for final security plans slipped three times from May 6 to July 16. Security assessments to be finished June 7 slid to August 16 and then August 23. The final, required top-to-bottom security tests never got done.

The House Oversight Committee released an Obama administration memo that shows four days before the launch, the government took an unusual step. It granted itself a waiver to launch the website with "a level of uncertainty ... deemed as a high (security) risk."

(Excerpt) Read more at cbsnews.com ...


TOPICS: Government
KEYWORDS: obamacare
Ding !!! Ding !!! Ding !!!

We got a Fall Guy winner - Marilyn Tavenner !!!

1 posted on 11/04/2013 10:30:29 PM PST by Lmo56
[ Post Reply | Private Reply | View Replies]

This web site / data collection system is dealing with both financial information AND medical information. Medical providers MUST meet HIPPA security requirements. Financial institutions MUST meet SOX security requirements. I can't speak for HIPPA, but with SOX, both the CIO and CEO can be held CRIMINALLY LIABLE for not meeting SOX requirements. I'm willing to bet that healthcare.gov doesn't meet either one.

I work for a financial company, and we spend a lot of time dealing with paperwork and record-keeping for SOX audits, and we have to hire an independant auditor EVERY year. The record keeping for just adding a user and assigning rights to the network more than doubles the time it takes to actually add the user. We've got at least 3 full time employees who do NOTHING but SOX compliance throughout the year!

Mark

2 posted on 11/04/2013 10:46:06 PM PST by MarkL (Do I really look like a guy with a plan?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MarkL

I work in IT ...

Despite the legal ramifications - the CMS had ethical considerations to adhere to. The fact that there was even a SMALL chance of compromising system integrity should have been enough to halt the rollout in its tracks ...

The waiver was approved by an ignorant, incompetent boob of a bureaucrat ...

They shoulda done it the way that they did the Manhattan Project. They selected an EXCELLENT Project Manager, General Leslie Groves, who managed the building of the Pentagon [on time AND under budget]. He then had Robert Oppenheimer oversee the technical work of the project ...


3 posted on 11/04/2013 11:01:50 PM PST by Lmo56 (If ya wanna run with the big dawgs - ya gotta learn to piss in the tall grass ...)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Lmo56

The only free time I have is between 1-5 am.

How am I ever gonna sign up?

Wait....I’ll be asleep.


4 posted on 11/04/2013 11:06:24 PM PST by Vendome (Don't take life so seriously-you won't live through it anyway-Enjoy Yourself ala Louis Prima)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Lmo56

A down website is pretty secure. It’s during those infrequent intervals that the thing is up that the problems start.


5 posted on 11/04/2013 11:16:47 PM PST by JohnBrowdie (http://forum.stink-eye.net)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Lmo56; All
I am an ACA certified “Exchange Agent”

I had a “background check” online, before they would let me take the training and tests.

They asked me what my previous address had been, and gave me about 20 choices.

The ONLY address that I recognized was that of my Ex-Wife.

I have NEVER lived there.

The system approved me when I checked that address.

6 posted on 11/04/2013 11:18:30 PM PST by Kansas58
[ Post Reply | Private Reply | To 1 | View Replies]

To: Vendome

That’s another thing. The daily shutdowns tell me that they don’t even fully understand what the scope of the problem really is. They are watching the site struggle through a period of time, identifying the top 10 or 20 problems, shutting it down, throwing a quick and dirty fix at it, and bringing it back up to identify (hopefully) the next 10 or 20 biggest problems.

They’ve already thrown one major design change in; prices before subsidies. It simplified things, but what the hell else is out there.

It’s insane. It’s non-existent cycle time. it tells me they’re pretty terrified of what they’re looking at.


7 posted on 11/04/2013 11:33:36 PM PST by JohnBrowdie (http://forum.stink-eye.net)
[ Post Reply | Private Reply | To 4 | View Replies]

To: JohnBrowdie
The daily shutdowns tell me that they don’t even fully understand what the scope of the problem really is. They are watching the site struggle through a period of time, identifying the top 10 or 20 problems, shutting it down, throwing a quick and dirty fix at it, and bringing it back up to identify (hopefully) the next 10 or 20 biggest problems.

Trouble with on-the-fly changes is that NO end-to-end regression testing is being performed as they make changes to the code.

Regression testing is required for ALL functionality, even if you change ONE character in code. Things that worked BEFORE you made the change may NOT work now, the change you made to correct a certain problem may NOT work, and you may have introduced NEW problems. That is why you need to regression test end-to-end ...

8 posted on 11/04/2013 11:47:21 PM PST by Lmo56 (If ya wanna run with the big dawgs - ya gotta learn to piss in the tall grass ...)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Kansas58
I have NEVER lived there.

The system approved me when I checked that address.

Part of the authentication process is to get info from one of the credit reporting agencies. A past address listed on one of the agency reports, had me living at my brother's father-in-law address.

9 posted on 11/05/2013 3:25:21 AM PST by EVO X
[ Post Reply | Private Reply | To 6 | View Replies]

To: Kansas58
I have NEVER lived there.

The same thing happened to me except it was the address my daughter lived for a while after she left home to strike out on her own.

10 posted on 11/05/2013 4:58:57 AM PST by ken in texas
[ Post Reply | Private Reply | To 6 | View Replies]

To: MarkL

I’m glad to see CBS doing these reports. Question is: are enough people watching to realize how bad Obamacare is?

And does this report make the contractor the fall guy, instead of the Democrats?


11 posted on 11/05/2013 5:16:17 AM PST by tbw2
[ Post Reply | Private Reply | To 2 | View Replies]

To: Lmo56
They shoulda done it the way that they did the Manhattan Project. They selected an EXCELLENT Project Manager, General Leslie Groves, who managed the building of the Pentagon [on time AND under budget]. He then had Robert Oppenheimer oversee the technical work of the project ...

Instead, they hired the American subsidiary of a Canadian company that, IIRC, was fired TWICE by the Canadian government, for gross incompetence, the inability to deliver a working system, and cost overruns that I believe were several orders of magnitude on the gun registration. But I suppose their #1 qualification was that the people in charge of the company were buddies of the Angry Wookie.

Mark

12 posted on 11/05/2013 5:52:26 AM PST by MarkL (Do I really look like a guy with a plan?)
[ Post Reply | Private Reply | To 3 | View Replies]

To: JohnBrowdie
A down website is pretty secure. It’s during those infrequent intervals that the thing is up that the problems start.

You're right, but as usual, the ministry of propaganda focuses on the LEAST of the problems, the web site itself, since that's all they can understand.

The web site itself is nothing, other than an interface to the underlying programs that are supposed to process and store your data. Adding encryption to hide the data being transmitted isn't a big deal. The real problem is the security of the "back end," and it appears that it's really got problems. There are reports of a lawyer being contacted by someone in a different state, who after logging on, downloaded private data and information of the lawyer. And we've heard of insurance companies getting customer information that is incorrect, or multiple instance of the information. Those are indications of a total database query, storage, and indexing problems, as well as a total failure of data security. This is NOT something that can be "patched." It indicates a total failure of system architecture and design.

Mark

13 posted on 11/05/2013 6:05:17 AM PST by MarkL (Do I really look like a guy with a plan?)
[ Post Reply | Private Reply | To 5 | View Replies]

To: tbw2
And does this report make the contractor the fall guy, instead of the Democrats?

Well,the fact is that, thanks to the Angry Wookie, HHS hired a contractor with a proven history of failure, the inability to deliver a working product, and unbelievably HUGE cost overruns that would embarrass any DoD contractor! So the contractor DOES deserve SOME of the blame.

But the REAL blame does belong with those in charge, but it will never happen. I'll bet dollars to donuts that the blame will be placed on the pubbies, who opposed ObamaCare from the start, and the ministry of propaganda will joyfully report it, over and over again!

Mark

14 posted on 11/05/2013 6:11:03 AM PST by MarkL (Do I really look like a guy with a plan?)
[ Post Reply | Private Reply | To 11 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson