US cybersecurity chief says he had pre-launch concerns about Obamacare website

Advertisement
By Associated Press | Updated: 18 January 2014 12:21 IST
The top cyber-security officer for the Health and Human Services Department said he was concerned about potential vulnerabilities ahead of the launch of the Obama administration's health care website.

But Kevin Charest told congressional investigators he was unable to get answers to his questions from others inside the department. He concluded that the testing of the site was substandard.

(Also see: Overhauled Obama healthcare website faces new test on New Year's Day)

"I would say that it didn't follow best practices," Charest testified a Jan. 8 deposition. Excerpts of his testimony were provided to The Associated Press by the House Oversight and Government Reform Committee.

Advertisement

Charest and Teresa Fryer - another government cybersecurity professional who also had qualms - were to testify before the panel Thursday.

Advertisement

Chairman Darrell Issa, R-Calif., investigating the chaotic rollout of the HealthCare.gov website, contends the administration risked the personal information of millions of Americans in its zeal to meet a self-imposed Oct. 1 deadline. The online federal insurance market is the main portal to coverage under President Barack Obama's signature program.

The panel's senior Democrat, Rep. Elijah Cummings of Maryland, says the administration addressed the potential security issues through added vigilance instituted before the site went live. He says despite initial operational problems, the site has not been successfully hacked. Cummings says it is Republicans who are risking the privacy of average citizens by demanding detailed blueprints that, if leaked, would become a road map for hackers.

Advertisement

With "Obamacare" expected to be a polarizing issue in the midterm congressional elections, both political parties are at battle stations. Republicans have raised security issues but have yet to produce a smoking gun.

As chief information security officer for HHS, Charest offered a look an insider concerns during the weeks and days before the website went live. Technical problems developed immediately and many potential customers were frozen out. The site seems to be working well now, but the administration's signup campaign hasn't fully recovered its momentum.

Advertisement

"I get paid to be paranoid," Charest said in the transcript. "And so I wanted to understand the exact controls in place, what environment, what procedures, what policies."

But the Centers for Medicare and Medicaid Services - the departmental division running the health care rollout - wasn't sharing.

"I was frustrated by a number of requests I made that I did not receive," Charest said. The requests were not just related to security, he said, but other operational issues as well.

He said he came to believe that CMS - as the division is known- was deliberately keeping information to itself. "I can't explain it," he said.

While he did not have direct chain-of-command authority over the rollout, "I have responsibility for incident control," Charest testified. "Putting my bad-guy hat on, this would be something I would think would be desirable for someone to want to attack."

HealthCare.gov has two major components: an electronic "back room" that got full operational and security certification and a consumer-facing "front room" that was temporarily certified Sept. 27.

The back room, known as the federal data services hub, pings government agencies to verify applicants' personal information. It does not store data.

But the front room does. That's where consumers in the 36 states served by the federal website create and save their accounts. Individual components of the front room did undergo security testing. But the system as a whole could not be tested because it was being worked on until late in the process - and it was also crashing.

Charest testified that security testing usually takes place on a fully built, stable system that represents real-world functionality.

The path followed by HealthCare.gov was "not typical," he said. "In a perfect world, the system is completely done when you test it."

Charest testified that he did not get to review a key outside contractor's security evaluation until November, a month into the rollout. He found out only through media reports that the consumer-facing part of the website had been issued a provisional six-month operational and security certificate.

Despite the unusual process that administration officials followed with the website, Charest expressed cautious optimism over the added vigilance and testing measures put in place to reduce risks.

"I have no reason to believe that these broad mitigation strategies, if followed through in detail, would not mitigate the risk," he told the committee.

Fryer, who is the CMS chief information security officer, has testified that she recommended against issuing a full certification for the consumer-facing part of the website. She put her concerns in a Sept. 24 memo, but it was never sent.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  2. Logitech MX Master 4 Launches in India With These Features
  3. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  4. Jio Launches Happy New Year 2026 Prepaid Plans: Check Price, Benefits
  5. Apple Fitness+ Service Is Now Available in India: See Features
  6. Oppo Reno 15c With Snapdragon 7 Gen 4 SoC Launched at This Price
  7. Motorola Edge 70 With 5,000mAh Battery Launched in India at This Price
  8. MacBook Air (2025) With M4 Chip Available at This Discounted Price
  9. Vivo S50, S50 Pro Mini With Snapdragon Chips Launched at These Prices
  10. Mrs Deshpande OTT Release Date: Madhuri Dixit's Starrere to Premiere on This Date
  1. The End of 16GB RAM Phones? AI Boom Forces Smartphone Makers to Bring Back 4GB Models
  2. Xiaomi 17 Ultra Tipped to Launch Alongside Redmi Turbo 5 Series, New Wearables
  3. Mrs Deshpande OTT Release Date: Madhuri Dixit’s Psychological Thriller Premieres on This Date
  4. Knives Out Now Streaming on Lionsgate Play: What You Need to Know
  5. The Copenhagen Test OTT Release Date: When and Where to Watch it Online?
  6. Tell Me Softly Out on OTT: Everything You Need to Know About This Spanish Teen Romance Film
  7. Vivo S50 Pro Mini Launched With Snapdragon 8 Gen 5 SoC, Vivo S50 Tags Along: Price, Specifications
  8. Clair Obscur: Expedition 33 Gets New 'Thank You' Update After Winning at The Game Awards
  9. Apple Fitness+ Now Available in India With Custom Workout Programmes: Price and Other Details
  10. Samsung Could Reportedly Strike a Deal With AMD to Build Future 2nm Process Chipsets
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.