Security flaws found in 3 state health insurance websites - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
April 7, 2016 Newswires
Share
Share
Post
Email

Security flaws found in 3 state health insurance websites

Associated Press

FRANKFORT, Ky. (AP) — Federal investigators found significant cybersecurity weaknesses in the health insurance websites of California, Kentucky and Vermont that could enable hackers to get their hands on sensitive personal information about hundreds of thousands of people, The Associated Press has learned. And some of those flaws have yet to be fixed.

The vulnerabilities were discovered by the Government Accountability Office, the investigative arm of Congress, and shared with state officials last September. Vermont authorities would not discuss the findings, but officials in California and Kentucky said this week that there was no evidence hackers succeeded in stealing anything.

Regulators said that given the number of weaknesses they discovered in just the three states studied, other state-run health insurance exchanges could be vulnerable, too. The GAO recommended the federal government continually monitor cybersecurity at such sites.

Created under President Barack Obama's health care overhaul, the exchanges are online marketplaces where people who have no health insurance through their jobs can buy government-subsidized private coverage. Only a dozen states ran their own websites this year; the rest either switched to the federal one or jointly operate their exchanges with Washington.

Computer security flaws are the just latest headache for the state exchanges. Some, like Oregon's, suffered crippling technical problems when they were launched in 2013. Some states, like Hawaii, turned operations back to the federal government because of cost concerns.

The GAO report examined the three states' systems from October 2013 to March 2015 and released an abbreviated, public version of its findings last month without identifying the states. On Thursday, the GAO revealed the states' names in response to a Freedom of Information request from the AP.

According to the GAO, one state did not encrypt passwords, potentially making it easy for hackers to gain access to individual accounts. One state did not properly use a filter to block hostile attempts to visit the website. And one state did not use the proper encryption on its servers, making it easier for hackers to get in. The report did not say which state had what problem.

Kentucky's Steve Beshear, who was governor when the security flaws were discovered, said through a spokeswoman that "because of the time required to fix the technical issues, not all those issues had been addressed" by the time Gov. Matt Bevin took office in early December. But Beshear added: "It is important to note that there were never any security breaches of any kind, and no one's information was ever compromised."

Doug Hogan, a spokesman for the Bevin administration's Cabinet for Health and Family Services, said efforts to fix the problems "are in various stages of completion and implementation." He added that privacy and security of sensitive information are "of the utmost importance" to Bevin's administration.

Kentucky's insurance exchange, kynect, will be dismantled later this year. While the system is credited with helping reduce Kentucky's uninsured rate from more than 20 percent in 2013 to 7.5 percent last year, Bevin says it is too expensive. He wants to transfer the more than 93,000 people who bought private coverage on kynect to the federal exchange, Healthcare.gov.

But Kentuckians' information might not be any safer on the federal exchange.

According to the GAO report, Healthcare.gov had 316 security incidents between October 2013 and March 2015. Such incidents can include unauthorized access, disclosure of data or violations of security practices. None resulted in lost or stolen data, but the GAO said technical weaknesses with the federal system "will likely continue to jeopardize the confidentiality, integrity and availability of Healthcare.gov."

In Vermont, Lawrence Miller, director of health reform for Democratic Gov. Peter Shumlin, said the state had changed vendors since the period of the GAO review. During the transition, "we ensured the correct controls were in place" to meet a federal standard, he wrote in an email.

In California, a spokesman for the state's exchange, Roy Kennedy, would not say how Covered California was addressing the problems, citing security concerns. He pointed instead to a letter sent in October to members of Congress.

In its, Covered California Executive Director Peter Lee said there have been no successful breaches of website security. However, he said personal information may have been exposed in a few instances because of human error or other mistakes.

Lee said that Covered California adopted 37 of the GAO's 41 recommendations for improving security. He said his agency disagreed with three technical security recommendations and is constrained by state laws and union contracts from adopting a fourth — requiring background checks for existing employees.

Since the GAO audit, Lee's letter said, Covered California conducts more frequent scans to identify threats, and any critical findings will be immediately fixed.

"Protecting data is our highest priority," Lee wrote. "From day one, Covered California has followed the rigorous guidelines outlined in federal and state security regulations designed to protect our consumers' private information."

Alonso-Zaldivar reported from Washington. Associated Press reporters Jonathan J. Cooper in Sacramento, California, and David Gram in Montpelier, Vermont, contributed to this report.

Older

Viesel Fuel, Martin County addressing lingering effects of last year’s fire

Advisor News

  • Finseca and IAQFP announce merger
  • More than half of recent retirees regret how they saved
  • Tech group seeks additional context addressing AI risks in CSF 2.0 draft profile connecting frameworks
  • How to discuss higher deductibles without losing client trust
  • Take advantage of the exploding $800B IRA rollover market
More Advisor News

Annuity News

  • Somerset Re Appoints New Chief Financial Officer and Chief Legal Officer as Firm Builds on Record-Setting Year
  • Indexing the industry for IULs and annuities
  • United Heritage Life Insurance Company goes live on Equisoft’s cloud-based policy administration system
  • Court fines Cutter Financial $100,000, requires client notice of guilty verdict
  • KBRA Releases Research – Private Credit: From Acquisitions to Partnerships—Asset Managers’ Growing Role With Life/Annuity Insurers
More Annuity News

Health/Employee Benefits News

  • Blood test for colorectal cancer screening now available for military in La.
  • Restoring a Health Care System that Puts Patients First
  • Indiana to rebid $68 billion in Medicaid contracts
  • AI, health insurance stocks drove a bumpy week for markets
  • Medicare Advantage insurers face new curbs on overcharges in Trump plan
More Health/Employee Benefits News

Life Insurance News

  • U-Haul Holding Company Reports Third Quarter Fiscal 2026 Financial Results
  • MetLife Announces Full Year and 4Q 2025 Results
  • Somerset Re Appoints New Chief Financial Officer and Chief Legal Officer as Firm Builds on Record-Setting Year
  • Indexing the industry for IULs and annuities
  • AI in life and health: Poised for a 2026 breakthrough?
Sponsor
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Elevate Your Practice with Pacific Life
Taking your business to the next level is easier when you have experienced support.

LIMRA’s Distribution and Marketing Conference
Attend the premier event for industry sales and marketing professionals

Get up to 1,000 turning 65 leads
Access your leads, plus engagement results most agents don’t see.

What if Your FIA Cap Didn’t Reset?
CapLock™ removes annual cap resets for clearer planning and fewer surprises.

Press Releases

  • Prosperity Life Group appoints industry veteran Rona Guymon as President, Retail Life and Annuity
  • Financial Independence Group Marks 50 Years of Growth, Innovation, and Advisor Support
  • Buckner Insurance Names Greg Taylor President of Idaho
  • ePIC Services Company and WebPrez Announce Exclusive Strategic Relationship; Carter Wilcoxson Appointed President of WebPrez
  • Agent Review Announces Major AI & AIO Platform Enhancements for Consumer Trust and Agent Discovery
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet