A security expert who has testified before Congress and spoken to the media about vulnerabilities of the Healthcare.gov website has weighed in on the website’s latest security issue, which was first reported Thursday by THE WEEKLY STANDARD. David Kennedy, the CEO of TrustedSec, an information security firm, said that the unintended opening at Healthcare.gov detailed in the story would allow malicious scammers to fool users with a “website that’s legitimate to make them believe its something else.” He said the existence of this potential pitfall on the site is “absolutely amazing,” and added that “an attacker can basically create a functioning website and host any content they want there and under the umbrella of healthcare.gov.”
At issue is the profile feature of the data.healthcare.gov section of the website that allows anyone to set up a custom made page intended to host “data-sets” based on the insurance plan information database on the website. Users can sort, group, and otherwise manipulate the data to create unique presentations based on various criteria. However, the lack of disclaimers and other safeguards allow marketers, or worse, scammers and identity thieves, to establish what would appear to be legitimate Healthcare.gov webpages which can be used to redirect users to other sites.
Stay informed.Stay ahead.
Join Washington Examiner for unlimited access to the news, analysis, and commentary that matter most.
Already a member? Log in
