Security flaws found in 3 state health insurance websites
The vulnerabilities were discovered by the
Regulators said that given the number of weaknesses they discovered in just the three states studied, other state-run health insurance exchanges could be vulnerable, too. The GAO recommended the federal government continually monitor cybersecurity at such sites.
Created under President
Computer security flaws are the just latest headache for the state exchanges. Some, like
The GAO report examined the three states' systems from
According to the GAO, one state did not encrypt passwords, potentially making it easy for hackers to gain access to individual accounts. One state did not properly use a filter to block hostile attempts to visit the website. And one state did not use the proper encryption on its servers, making it easier for hackers to get in. The report did not say which state had what problem.
But Kentuckians' information might not be any safer on the federal exchange.
According to the GAO report, Healthcare.gov had 316 security incidents between
In
In
In its, Covered California Executive Director
Lee said that Covered California adopted 37 of the GAO's 41 recommendations for improving security. He said his agency disagreed with three technical security recommendations and is constrained by state laws and union contracts from adopting a fourth — requiring background checks for existing employees.
Since the GAO audit, Lee's letter said, Covered California conducts more frequent scans to identify threats, and any critical findings will be immediately fixed.
"Protecting data is our highest priority," Lee wrote. "From day one, Covered California has followed the rigorous guidelines outlined in federal and state security regulations designed to protect our consumers' private information."
Alonso-Zaldivar reported from



Viesel Fuel, Martin County addressing lingering effects of last year’s fire
Advisor News
- Finseca and IAQFP announce merger
- More than half of recent retirees regret how they saved
- Tech group seeks additional context addressing AI risks in CSF 2.0 draft profile connecting frameworks
- How to discuss higher deductibles without losing client trust
- Take advantage of the exploding $800B IRA rollover market
More Advisor NewsAnnuity News
- Somerset Re Appoints New Chief Financial Officer and Chief Legal Officer as Firm Builds on Record-Setting Year
- Indexing the industry for IULs and annuities
- United Heritage Life Insurance Company goes live on Equisoft’s cloud-based policy administration system
- Court fines Cutter Financial $100,000, requires client notice of guilty verdict
- KBRA Releases Research – Private Credit: From Acquisitions to Partnerships—Asset Managers’ Growing Role With Life/Annuity Insurers
More Annuity NewsHealth/Employee Benefits News
- Blood test for colorectal cancer screening now available for military in La.
- Restoring a Health Care System that Puts Patients First
- Indiana to rebid $68 billion in Medicaid contracts
- AI, health insurance stocks drove a bumpy week for markets
- Medicare Advantage insurers face new curbs on overcharges in Trump plan
More Health/Employee Benefits NewsLife Insurance News