Skip to main content

CROSS-POSTED AT ACASIGNUPS.NET
This AP Newswire story was published by WTSP, Sarasota/Tampa Bay at 5:23pm yesterday, September 24, 2015:
"Critical" flaw found in HealthCare.gov security

WASHINGTON -- The government's own watchdogs tried to hack into HealthCare.gov earlier this year and found what they termed a critical vulnerability - but also came away with respect for some of the health insurance site's security features.

Those are among the conclusions of a report released Tuesday by the Health and Human Services Department inspector general, who focuses on health care fraud.

The report amounts to a mixed review for the federal website that serves as the portal to taxpayer-subsidized health plans for millions of Americans. Open enrollment season starts Nov. 15.

So-called "white hat" or ethical hackers from the inspector general's office found a weakness, but when they attempted to exploit it like a malicious hacker would, they were blocked by the system's defenses.

It's the second independent security assessment in as many weeks to find problems, and it comes on the heels of the massive breach at Home Depot stores,which affected 56 million credit and debit cards.

The public version of the report is a condensed, heavily edited summary of detailed findings delivered to the Obama administration.

Yikes! That's definitely a serious issue which needs to be addressed ASAP, right?

Well...you know, except for the part where the actual article specifically states that "when they attempted to exploit it like a malicious hacker would, they were blocked by the system's defenses."

So...you know, not quite so "critical" after all, I guess.

However, there's one other little problem. You might note that there appears to be a typo in the third paragraph, which lists the start of Open Enrollment as November 15, when in fact it's actually November 1st; the HHS Dept. moved the start date up two weeks this year.

Here's the problem: That's no typo. Or, more accurately the entire article is a typo.

Here's what I mean...check out this AP Newswire article from September 23, 2014...exactly 1 year and one day earlier:

Obamacare website plagued by ‘critical' flaw, inspector general finds

The government's own watchdogs tried to hack into HealthCare.gov earlier this year and found what they termed a critical vulnerability - but also came away with respect for some of the health insurance site's security features.

Those are among the conclusions of a report being released Tuesday by the Health and Human Services Department inspector general, who focuses on health care fraud.

The report amounts to a mixed review for the federal website that serves as the portal to taxpayer-subsidized health plans for millions of Americans. Open enrollment season starts Nov. 15.

So-called "white hat" or ethical hackers from the inspector general's office found a weakness, but when they attempted to exploit it like a malicious hacker would, they were blocked by the system's defenses.

It's the second independent security assessment in as many weeks to find problems, and it comes on the heels of the massive breach at Home Depot stores, which affected 56 million credit and debit cards.

The public version of the report is a condensed, heavily edited summary of detailed findings delivered to the Obama administration.

Yep. The AP reposted the exact same story a full year later.

The "2015 version" is still posted as of 12:10am Friday. Here's the screen shot if you doubt me:

On the one hand, I'm assuming this was an honest mistake which will soon be corrected.

On the other hand, it's been over 6 hours and the story is still posted on at least one Tampa Bay/Sarasota, Florida newspaper website (and possibly their print edition as well?), just 5 weeks before the Open Enrollment period starts again. In addition, of course, no one who's read the "2015 version" has any idea that this refers to a year-old technical issue which was fixed nearly a year ago.

Anyone know who to contact at the AP to fix this??
See Update x2 below

UPDATE: Thanks to Michael Hiltzik of the L.A. Times for reminding me that I even wrote a blog entry about this exact story when it originally ran one year ago!!

Headline: "Critical Flaw at HC.gov!!" Article: "Blocked by System Defenses"
No wonder it seemed so familiar to me this evening!!

UPDATE x2: Thanks to Eileenb in the comments for noting that re-posting the story yesterday appears to be a screw-up by the local news station (WTSP, Tampa Bay/Sarasota), not by the AP itself...it looks like WTSP simply re-published the story from the AP archives.

Of course, this doesn't change the fact that the "Critical Flaw" headline was still bullshit in the first place.

Also, WTSP still has the article posted as of 8:40am Friday morning.

Title updated to reflect clarification.

UPDATE x3: Oh for heaven's sake. It turns out there really is a different, new AP story regarding other security issues at Healthcare.Gov...although, once again, according to the CMS division, those issues have already been resolved:

The government stored sensitive personal information on millions of health insurance customers in a computer system with basic security flaws, according to an official audit that uncovered slipshod practices.

The Obama administration said it acted quickly to fix all the problems identified by the Health and Human Services inspector general's office. But the episode raises questions about the government's ability to protect a vast new database at a time when cyberattacks are becoming bolder.

...The flaws uncovered by auditors included issues of security policy — where mistakes can have bigger consequences — as well as 135 database vulnerabilities, of which nearly two dozen were classified as potentially severe or catastrophic.

Among the policy mistakes: User sessions were not encrypted, contrary to standard practice on financial websites. "Not doing so is inexcusable for such sensitive data," said Michelle De Mooy, deputy director for consumer privacy at the Center for Democracy & Technology, an Internet rights group.

...In a written response to the audit, Medicare administrator Andy Slavitt said that "the privacy and security of consumers' personally identifiable information are a top priority" for his agency. Slavitt said all of the high vulnerabilities were addressed within a week of being identified, and that all of the IG's recommendations have been fully implemented.

The Medicare agency is conducting weekly vulnerability assessments of MIDAS, and an annual security review, Slavitt said.

Thanks to Matthew Martin in the comments over at ACASignups.net for the link. As he suggested, it sounds like what might have happened is that someone at WTSP probably heard something about an AP story about HC.gov security issues, pulled up the year-old story and ran that by mistake.

If so, that would rule out it being intentional...but it's still a pretty bad mistake which should be corrected. As of 9:30am, it still hasn't been...

UPDATE x4: Holy crap on a stick, this really IS a MASSIVE FAIL for the AP after all. Check out my follow-up story over at ACASignups.net.

Originally posted to Brainwrap on Thu Sep 24, 2015 at 09:39 PM PDT.

Also republished by DKos Florida.

EMAIL TO A FRIEND X
Your Email has been sent.
You must add at least one tag to this diary before publishing it.

Add keywords that describe this diary. Separate multiple keywords with commas.
Tagging tips - Search For Tags - Browse For Tags

?

More Tagging tips:

A tag is a way to search for this diary. If someone is searching for "Barack Obama," is this a diary they'd be trying to find?

Use a person's full name, without any title. Senator Obama may become President Obama, and Michelle Obama might run for office.

If your diary covers an election or elected official, use election tags, which are generally the state abbreviation followed by the office. CA-01 is the first district House seat. CA-Sen covers both senate races. NY-GOV covers the New York governor's race.

Tags do not compound: that is, "education reform" is a completely different tag from "education". A tag like "reform" alone is probably not meaningful.

Consider if one or more of these tags fits your diary: Civil Rights, Community, Congress, Culture, Economy, Education, Elections, Energy, Environment, Health Care, International, Labor, Law, Media, Meta, National Security, Science, Transportation, or White House. If your diary is specific to a state, consider adding the state (California, Texas, etc). Keep in mind, though, that there are many wonderful and important diaries that don't fit in any of these tags. Don't worry if yours doesn't.

You can add a private note to this diary when hotlisting it:
Are you sure you want to remove this diary from your hotlist?
Are you sure you want to remove your recommendation? You can only recommend a diary once, so you will not be able to re-recommend it afterwards.
Rescue this diary, and add a note:
Are you sure you want to remove this diary from Rescue?
Choose where to republish this diary. The diary will be added to the queue for that group. Publish it from the queue to make it appear.

You must be a member of a group to use this feature.

Add a quick update to your diary without changing the diary itself:
Are you sure you want to remove this diary?
(The diary will be removed from the site and returned to your drafts for further editing.)
(The diary will be removed.)
Are you sure you want to save these changes to the published diary?

Comment Preferences

Thumb, Doug in SF, buffalo soldier, Sylv, Radiowalla, copymark, glitterscale, Joan McCarter, Powered Grace, am, PeterHug, bosdcla14, Sprinkles, Emerson, wu ming, donna in evanston, Wintermute, Troutfishing, mslat27, xynz, elfling, red moon dog, Creosote, 88kathy, TracieLynn, afox, whenwego, highacidity, boadicea, themank, gakke, otto, roses, PeteZerria, Iberian, Alna Dem, wader, kharma, psnyder, TexDem, NYC Sophia, thoreau247365, Eyesbright, johanus, HeyMikey, Catte Nappe, Dood Abides, walkshills, Chris Reeves, zerelda, KayCeSF, tomjones, sawgrass727, Gowrie Gal, weelzup, Dirk McQuigley, Tinfoil Hat, jrooth, tle, Jeffersonian Democrat, LarisaW, Independent Musings, mjd in florida, democracy inaction, Simplify, basquebob, stagemom, Laurence Lewis, reflectionsv37, owlbear1, bleeding blue, Sun Tzu, ladybug53, Overseas, most peculiar mama, Steve in Urbana, jane123, illinifan17, Cecile, rb608, Ginny in CO, quiet in NC, daddybunny, peacestpete, tallen387, kathny, begone, martini, golem, Patriot Daily News Clearinghouse, edwardssl, Ky DEM, profundo, StrayCat, gpoutney, Rosaura, JVolvo, Preston S, Spock36, sceptical observer, ER Doc, middleagedhousewife, Joshua Bloxom, bumbi, thenekkidtruth, geekydee, Tom Anderson, bstotts, Temmoku, Aaa T Tudeattack, orrg1, tegrat, ammasdarling, sephius1, old wobbly, Sapere aude, BeninSC, Habitat Vic, Deadicated Marxist, ColoTim, paz3, karmsy, edsbrooklyn, FishOutofWater, Matt Z, jayden, Bridge Master, gchaucer2, carpunder, OIL GUY, Librarianmom, GeorgeXVIII, leonard145b, TexasTwister, TomP, gizmo59, JDWolverton, MKinTN, TruthFreedomKindness, TX Freethinker, OleHippieChick, Sixty Something, Aureas2, Cat Servant, alasmoses, jamess, monkeybrainpolitics, Calamity Jean, here4tehbeer, Lujane, Cassandra Waites, Jeff Y, elpacifico66, BYw, palantir, statsone, maggiejean, Bule Betawi, MufsMom, bleuet, clear SKies, bobatkinson, CanyonWren, Methinks They Lie, indres, DefendOurConstitution, Daily Activist, petral, MKSinSA, Denise Oliver Velez, kevinpdx, Keith Pickering, 57andFemale, maxzj05, haremoor, Tortmaster, jfromga, astral66, joe from Lowell, Leftcandid, Amber6541, Its the Supreme Court Stupid, henlesloop, T Maysle, serendipityisabitch, piers, CS11, appledown, elginblt, Puddytat, MsGrin, ericlewis0, soaglow, slice, Wisdumb, Onomastic, kerflooey, annominous, Captain Pants, slowbutsure, AdamR510, FarWestGirl, molunkusmol, cama2008, PedalingPete, marleycat, thomask, BarackStarObama, Grandma Susie, createpeace, worldlotus, foresterbob, sound of progress, Andrew F Cockburn, Joe Jackson, Marihilda, bloomin, Hayate Yagami, MichaelNY, No one gets out alive, Laurel in CA, livingthedream, bluezen, TheLizardKing, IndieGuy, ahumbleopinion, done lurking, 2thanks, FloridaSNMOM, Trotskyrepublican, exatc, congenitalefty, Forward is D not R, Denver11, etherealfire, Glen The Plumber, wasatch, databob, AZ Sphinx Moth, YsosadisticGOP, Raven Song, Greenfinches, Lily O Lady, smokey545, remembrance, eyo, goodpractice, techwriter, aresea, howabout, ET3117, tampaedski, cbgbz, richardvjohnson, Dodgerdog1, eagleray, thanatokephaloides, lrganassi, RhodeIslandAspie, paulex, hbk, Thyme4Thought, BMScott, suzi63, MiAtheistGal, Older and Wiser Now, coyote66, Blackwolf53, Antitheist, Mrcynical, TrixieB, Angela Marx, Stephanie Nicole, Heidi3

Subscribe or Donate to support Daily Kos.

Click here for the mobile view of the site