8 ms·
Healthcare.gov confirms hackers stole income, immigration and tax data
- dmead 8y agoIs this before or after it was moved from usds to a contractor?
- fjsolwmv 8y agoHealtgcare.gov wasn't hacked. It's users' systems were hacked, and the hacked client systems logged in to healthcare.gov through normal means.
- khazhou 8y agoThis distinction is not useful to the people whose information was accessed. Perhaps healthcare.gov could have been designed in such a way that sensitive user information was not available to client systems, or somehow required that clients have higher levels of security to prevent this from happening.
- CobrastanJorji 8y agoThis is big, east coast, many-contractor design. By the time things made it to the point that somebody was thinking about security, a rule like "providers will be given access to the following fields for a client upon request" was likely already written into a half dozen contracts between seventeen sub-contractors.
- isoskeles 8y agoYes, take note east coasters. This doesn't happen on the west coast.
- dpkonofa 8y agoIt is explicitly limited by geography. The magnetic pull of the earth on the west coast, because of the San Andreas fault, prevents this from happening there.
- CobrastanJorji 8y agoIs that not a thing? I had thought "west coast" described startupy, in-house, vaguely agile type of software development, and "east coast" described government contracting, sub-sub-sub contracting, waterfall-style development. Maybe I just picked it up from the folks around me and thought it was more universal.
- gloryless 8y agoUsds never "had it", it's always been handled by MULTIPLE contractors. This last version one contractor works on backed, one works on frontend, one is responsible for documentation and testing, and none of them communicate.
- ObsoleteNerd 8y agoAustralians, don't forget to opt-out[0] of MHR before November 15th (eg, do it NOW). Our Government can't even run a census[1], let alone be trusted to keep our medical data safe. [0] https://www.myhealthrecord.gov.au/for-you-your-family/opt-out-my-health-record https://www.myhealthrecord.gov.au/for-you-your-family/opt-ou... [1] https://www.lifehacker.com.au/2016/08/what-organisations-can-learn-from-the-abs-census-fail/ https://www.lifehacker.com.au/2016/08/what-organisations-can...
- microcolonel 8y agoThings are grim in Ontario as well, the ministry of health is trying to centralize EHRs (rather than do the sensible thing Alberta's chose: a standard viewer application mapped on a distributed records system), and they don't give one solitary fuck about the data integrity or privacy outcomes their effort has (ask anyone involved, and they'll tell you it's somebody else's job).
- chii 8y ago> alone be trusted to keep our medical data safe. Not just against malicious attackers, but "legitimate" abuse like insurance companies or employers getting access without you knowing!
- dibstern 8y agoDude wtf, we need this data to help treat patients and save lives.
- whatshisface 8y agoImagine I was running a charity that accepted donations by asking people to post their bank login credentials on a corkboard outside my house.
- ouid 8y agothat's not really secure enough, you should require that they confirm how much they want you to withdraw as a line item next to their password.
- reaperducer 8y agoI started the signup process when I was between jobs, but stopped because I got an offer. For months I kept receiving e-mail reminding me that my application was incomplete, and cajoling me to finish. I wonder if the hackers got my partial information, or if it was only stored in affected systems after completion.
- youeseh 8y agoIs data in http://coveredca.com http://coveredca.com also affected by this?
- social_quotient 8y agoMaybe stop asking for back doors until you’ve gotten all of your front doors secure?
- Novashi 8y agoThe original Healthcare.gov was a clusterfuck because contractors did a shit job. They did a relaunch, but I'm wondering how much of it was actually rewritten. I'm putting my money on brokers/agents having weak passwords and someone did some guessing like firstname.lastname@something.gov/<password>
- heelix 8y agoI was one of the poor souls sent in as part of the tech surge to fix it. Ah, what a cluster fuck that was. CGI spent most of the time making UML diagrams, with the hopes that a UML > Java > XML generator would do the job... only to discover they missed out on the data modeling. Always fun to see CNN show a twitter feed the moment you take down something for patching.
- simplify 8y agoOh wow. I would love to hear more stories if you have any.
- heelix 8y agoDay 0, when it went live, ACA successfully processed six people. :P Will give a few more tomorrow, when I have something more than a phone.
- josh-wrale 8y agoCan you expound on the data modeling they missed out on? Is the UML code generator a bad way to go in your opinion or did they just not do due diligence with data modeling? (Asking because I'm starting a new data-heavy project and I'm considering generating code from UML.)
- exabrial 8y agoOne of the best $150 million dollar websites the taxpayer had ever bought!
- exabrial 8y agoWhoops, sorry apparently its $319 million according to Sebelius. https://www.washingtonpost.com/news/fact-checker/wp/2013/10/24/how-much-did-healthcare-gov-cost/ https://www.washingtonpost.com/news/fact-checker/wp/2013/10/...
- finkin1 8y agoAccording to Wikipedia: "The original budget for CGI was $93.7 million, but this grew to $292 million prior to launch of the website. While estimates that the overall cost for building the website had reached over $500 million prior to launch, the Office of Inspector General released a report finding that the total cost of the HealthCare.gov website had reached $1.7 billion." https://en.wikipedia.org/wiki/HealthCare.gov https://en.wikipedia.org/wiki/HealthCare.gov Here's the report claiming $1.7B total cost: https://oig.hhs.gov/oei/reports/oei-03-14-00231.asp https://oig.hhs.gov/oei/reports/oei-03-14-00231.asp
- exabrial 8y agoI guess I need to get in the business of making websites for the government.
- joering2 8y agoAbsolutely, however the market is heavily taken by friends and families of politicans in charge. Thats why they can shit out a jquery website done by indians and charge government half a billion dollar without single person being accused for this crime in bright day. Of course CGI is better than ever! Working on multitude of “successful” government projects ;)
- shaki-dora 8y ago
- xfactor973 8y agoDammit. I wish you could delete accounts. I have tons of accounts and can’t seem to find links or settings to delete any of them to reduce my exposure to this crap.
- thsowers 8y agoIn many systems "deleting" your account just means turning on a flag in your profile. Plus there is the issue of deleted accounts information previously existing in backups. It seems like once we give any data to any company/entity/organization in this age that it will likely be around, somewhere, forever :(
- Jaepa 8y agoWell, you could try to do an account remove under GDPR. It would be pretty entertaining in this case.
- mychael 8y agoAmerican taxpayers paid over 500 million for Healthcare.gov. https://en.wikipedia.org/wiki/HealthCare.gov https://en.wikipedia.org/wiki/HealthCare.gov
- acdha 8y agoIt sounds like that’s irrelevant because the problem was compromised accounts using the system: > On October 16, 2018, we found that a number of agent and broker accounts engaged in excessive searching for consumers, and through those searches, had access to the personal information of people who are listed on Marketplace applications.
- saalweachter 8y ago$500 million -> optimistically 2000 developer-years, assuming no budget for hardware, management or profit. I'm not saying someone didn't mess up or that the security breach wasn't preventable, I have no knowledge of that, but I hope no one on HN is surprised that building a site that on the frontend handles traffic from a significant fraction of the US and on the backend interfaces with basically every insurer in 30-some states is something that might take hundreds of developers a few years to develop. (Which again, is not meant to imply that there wasn't any waste or that the project was completely as efficiently as possible, but when people say they could have done it in a quarter with 5 people, I say, what is wrong with you?)
- beambot 8y agoZenefits raised $583M to build their platform... So to first order: seems reasonable.
- hedvig 8y agoNo, but you see, shareholders may eventually profit from that. But if its publicly funded and the public benefits, its a bad thing because how can capital get some sweet returns in this scenario?
- stevenicr 8y agoWould be nice if they would publish the known search strings. Right now I am assuming "expected income >= 100,000" - that could give many a sigh of relief perhaps. Article mentions "engaged in excessive searching” and some of the details taken include "expected income" At this point hackers could be a better source of credit rating given that they could combine info from hacks like this and the other credit agency (experian?) hacks with other insurance hacks (anthem?) - I wonder if my signup app info is still in this system from a couple years ago or has been removed?
- specialist 8y agoData leaks like this are inevitable. Plan for it, moot the problem with proper design. The correct answer is to encrypt all demographic data (PII) at rest using translucent database techniques. Just like a properly salted, encrypted password store. Because of data interchange, individuals will need globally unique identifiers, eg Real ID. (These systems still require access & audit logs.)