Healthcare.gov ‘may already have been compromised,’ security expert says

Nov. 19, 2013: Security experts testify before a senate panel about security risks facing the healthcare.gov website. (FoxNews.com)

This screenshot made Monday, Oct. 28, 2013 shows the U.S. Department of Health and Human Services' main landing web page for HealthCare.gov. (AP Photo/U.S. Department of Health and Human Services)

Not only is healthcare.gov at risk, it may already have been compromised, a security expert testified before the Senate.

“Hackers are definitely after it,” said David Kennedy, CEO of information security firm TrustedSEC before a House Science, Space, and Technology committee hearing on security concerns surrounding the problematic Healthcare.gov website.

“And if I had to guess, based on what I can see … I would say the website is either hacked already or will be soon.”

Kennedy told FoxNews.com he based this on an analysis revealing a large number of SQL injection attacks against the healthcare.gov website, which are indicative of "a large amount" of hacking attempts.

[pullquote]

More On This...

    "Based on the exposures that I identified, and many that I haven’t published due to the criticality of exposures – if a hacker wanted access to the site or sensitive information – they could get it," he told FoxNews.com.

    A spokesman for the Department of Health and Human Services, which runs the nation's new healthcare website, did not immediately respond to a request to for more information.

    One key problem facing Healthcare.gov is that security wasn’t built into the site from the very beginning, he said -- an opinion shared by both Kennedy and Fred Chang, the distinguished chair in cyber security at Southern Methodist University.

    “There’s not a lot of security built into the site, at least that’s what we can see from a 10,000 foot view,” Kennedy told the committee. And although the site doesn’t house medical records, it integrates deeply with other sites, includes ecommerce information, and houses a vast array of data that presents a very salient target.

    “It’s not only social security numbers … it’s one of the largest collections of personal data, social security and everything else, that we’ve ever seen,” Kennedy said.

    Some members of the panel expressed surprise at the harsh words, noting that, among other things, people enter social security numbers all over the web.  Congresswoman Eddie Johnson, D.-Texas, a member of the committee, noted too the ready availability of medical records in the past.

    “Why is there such an outcry in this court when medical records have been so available [in the past],” she asked. “Is the healthcare industry lagging in these security measures?”

    That’s exactly the case, said Avi Rubin, technical director of Johns Hopkins University's Information Security Institute. The healthcare industry is indeed woefully behind.

    “It’s actually the most far behind in terms of security … there are even things in the operating room that surprise me. I think the healthcare it industry needs to learn a lot from some of the other industries to bring its security up to par,” Rubin said.

    Rubin called for a security review of the site, but stopped short of calling for a complete tear down and rebuild of the healthcare.gov site. Others were less cautious.

    “You can bolt a metal door on to make a house better, but if the foundation is bad…” Kennedy said.

    All four cyber security experts unanimously concurred that, given the security issues, Americans should not use the site at present.

    Load more..