Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > News > Tech News > Hacker infiltrates Healthcare.gov, no personal information stolen

Hacker infiltrates Healthcare.gov, no personal information stolen
Thread Tools
NewsPoster
MacNN Staff
Join Date: Jul 2012
Status: Offline
Reply With Quote
Sep 4, 2014, 09:40 PM
 
Health care exchanges continue to hit rough patches, as the United States government has revealed that the federal health care portal Healthcare.gov was breached. While there is no evidence that any personal information from the 5.4 million people applying through the site was stolen during the event, the attack marks the first time an intrusion has successfully accessed systems attached to the website.

The system that was breached is said to be a server that is only used to test code for the website, officials told the Wall Street Journal. However, the server was connected to parts of the Heathcare.gov site that does house sensitive data, according to an official at the Department of Health and Human Services (HHS). That area of the network contains better security, so while a compromise of the data could have occurred, the intruder would have had a tough time accessing it. The agency found evidence of the breach on August 25 in a routine scan.

"Our review indicates that the server did not contain consumer personal information; data was not transmitted outside the agency, and the website was not specifically targeted," said HHS. "We have taken measures to further strengthen security."

Currently, officials don't know how the hacker gained access to the system, but the Department of Homeland Security (DHS), the Federal Bureau of Investigation (FBI) and the National Security Agency were called in to investigate. It isn't believed that the attack was by a "state-backed actor" at this time, even with some of the IP addresses traced back to overseas locations.

DHS spokesman S.Y. Lee also confirmed that there was no evidence that data had been stolen during the breach. He added that the agency would continue to "monitor the situation and help develop and implement precautionary mitigation strategies as necessary."

It's believed that the hacker that gained access wasn't specifically attempting to target the portal, as "malicious software" was injected to be used in future attacks on other sites. The intrusion was traced back to July by the investigators involved, finding nothing but the installation of the software to be used in denial-of-service (DoS) attacks. Information from the investigation pointed to both private and federal sites being scanned by the hacker.

What's troublesome is the server that was accessed was never intended to be connected to the Internet. Because of this, it had "low security settings" and a default password required for access. Officials are concerned that the hacker was able to gain access via the basic security flaw.

These sorts of attacks are common on Internet-connected sites, something that the industry treats as an annoyance more than anything else. The HHS says it takes cybersecurity seriously, telling the paper that it undergoes quarterly audits through an outside security firm. It also does daily scans and "drill-hacking exercises." DHS notes that had such a breach happened to anywhere other than Healthcare.gov, "it wouldn't be news."

News of a breach comes at a troubling time for the insurance gateway, as the next open enrollment period is ramping up for November. Citizens that weren't able to obtain health insurance by the last deadline, or because of issues with state programs, will be flocking to the site to sign up in order to avoid penalties.
( Last edited by NewsPoster; Sep 16, 2014 at 04:15 AM. )
     
TheGreatButcher
Senior User
Join Date: Jun 2000
Location: Sydney, Australia
Status: Offline
Reply With Quote
Sep 4, 2014, 11:12 PM
 
Michael Daniel, you're doing a heckuva job.
     
Mr. Strat
Dedicated MacNNer
Join Date: Jan 2002
Location: State of WA
Status: Offline
Reply With Quote
Sep 5, 2014, 10:30 AM
 
Two more years of this inept administration? Jeez! Repeal this awful legislation before this clown destroys what's left of this country.
     
DiabloConQueso
Grizzled Veteran
Join Date: Jun 2008
Status: Offline
Reply With Quote
Sep 5, 2014, 11:51 AM
 
Hehe... if the sentiment is that our problems will be solved once this administration is out of office, then I believe that demonstrates a lack of undertstanding of both our problems and the administration.
     
Flying Meat
Senior User
Join Date: Jan 2007
Location: SF
Status: Offline
Reply With Quote
Sep 5, 2014, 02:17 PM
 
True enough, Diablo. It amazes me.
     
TheGreatButcher
Senior User
Join Date: Jun 2000
Location: Sydney, Australia
Status: Offline
Reply With Quote
Sep 5, 2014, 05:33 PM
 
Concur, a change of administration isn't going to fix this. It seems both parties are far out of touch with reality.
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 09:11 PM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,