This is a short work week, and the coming days promise miserable winter weather set to ruin travels for lots of Americans . . . so this is a great time for the administration to announce that Healthcare.gov won’t be fixed on November 30 like they promised.
Perhaps it all comes down to how you define “fixed.”
Jeff Zients, the Obama-administration troubleshooter brought in to oversee the Healthcare.gov repairs, hinted at the wiggle room Friday:
There will not be a magic moment at the end of the month when our work will be complete.
But the current line is that almost all is well:
The government’s lead official for fixing HealthCare.gov said Friday that the healthcare exchange website will be ready by the end of November to handle the traffic volumes for which it was originally designed.
Except that “handling traffic volumes” is only one part of the problem. This basically is an assurance it won’t crash during the session.
First, the “estimated subsidies” on the site’s anonymous shopping feature are still wrong:
The troubled federal website allows visitors to anonymously surf the site for exchange plans sold in their areas and provides them with estimated prices for each health plan. But here’s the problem: The monthly premium estimates provided on the website do not consider a person’s specific age, household size or tobacco use — all critical factors when estimating premiums.
Wait, it’s worse. It suggests the premium shown is an overestimate, not an underestimate:
HealthCare.gov visitors using the site’s window-shopping tool are repeatedly told that “the final premium you pay may be lower, perhaps much lower, than the prices shown” once they fill out an application and apply for government subsidies. But what the site doesn’t say is that the actual premium may be higher, perhaps much higher, than the estimated premiums shown on the site.
But more importantly, the site’s security isn’t fixed:
“When you develop a website, you develop it with security in mind. And it doesn’t appear to have happened this time,” said David Kennedy, a so-called “white hat” hacker who tests online security by breaching websites. He testified on Capitol Hill about the flaws of HealthCare.gov last week.
“It’s really hard to go back and fix the security around it because security wasn’t built into it,” said David Kennedy, chief executive of TrustedSec. “We’re talking multiple months to over a year to at least address some of the critical-to-high exposures on the website itself.”
And the breaches are starting . . .
Officials overseeing the Vermont Health Connect website confirmed Friday there was a security breach on the system last month in which one user got improper access to another user’s Social Security number and other data.
A report from state to federal officials overseeing the health insurance exchanges set up under the Affordable Care Act said a consumer reported the incident with the Vermont Health Connect website on Oct. 17.
The consumer, whom officials would not identify, reported that he received in the mail — from an unnamed sender — a copy of his own application for insurance under the state exchange.
Vermont officials insist this has only happened once. Kennedy testified to the House last week that if an estimate of attempted hacks is low, it simply may be that the site doesn’t have the right software to detect the hacks, attempted or successful.
David Kennedy, CEO of information security consulting firm TrustedSEC, echoed that assessment, saying there was no way that HealthCare.gov had been targeted only 16 times in the first six weeks after it launched. “What this statement shows is the lack of a formal detection and prevention capability within the website and its infrastructure,” said Kennedy. “On average, while working for an international Fortune 1000 company, our main website was attacked over 230 — averaged [out to] 232 attacks a day for the year of 2012 — times a day.”