HealthCare.gov audit reveals ‘critical’ cybersecurity risks

A federal audit has found the health records of millions of HealthCare.gov users have been stored in a computer system with basic security flaws, according to an Associated Press report.

Advertisement

MIDAS, the $110 million electronic database used to store the information of registered HealthCare.gov users, does not include medical information, but does contain Social Security numbers, names, birth dates and phone numbers.

The flaws, uncovered by HHS auditors, included 135 database vulnerabilities, some of which were labeled potentially severe or catastrophic. Security lapses ranged from unencrypted user sessions and failure to conduct automated vulnerability scans to software bugs.

The Medicare agency is now conducting weekly MIDAS vulnerability assessments and has addressed all of the auditor’s findings within a week of their identification, according to a statement from Medicare administrator Andy Slavitt.

More articles on health IT:
Mayo Clinic CISO Jim Nelms resigns
Cybersecurity: No silver bullet for healthcare’s insider/outsider threats
GAO report: CMS won’t know ICD-10 readiness until code processing begins

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Health IT

Advertisement

Comments are closed.