Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Feds identify security vulnerabilities in state healthcare exchange websites

By Benjamin Jensen on April 11, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

A Government Accountability Office (GAO) examination of the state-run health insurance exchanges for California, Kentucky and Vermont identified inadequate security measures in place to protect consumers’ personal information. While state officials from Kentucky and California denied that any security breaches had occurred or that any personal data had been compromised as a result of the security weaknesses, state officials acknowledged that several of the flaws have not yet been remedied. Accordingly, the GAO has recommended that the federal government monitor cybersecurity measures on the state-run sites on an ongoing basis.

The GAO examination, which covered the time period from October 2013 to March 2015, identified several basic security flaws in the systems, including the failure to encrypt passwords, to use filters to block hostile access attempts and to use proper encryption on servers. The GAO report did not specify which state websites suffered from each problem.

Although state officials were notified of the GAO findings in September 2015, responses by state officials from California and Kentucky made clear that not all of the problems had yet been addressed. Officials from Vermont declined to respond to the findings. Due to expenses, Kentucky is in the process of dismantling its state-run exchange and will be transferring to the federal exchange, Healthcare.gov, later this year.

Photo of Benjamin Jensen Benjamin Jensen

Benjamin Jensen is partner in the firm’s Business Litigation Group, where he is a member of the Intellectual Property Litigation and Data Privacy and Security Practice Teams. His practice involves representing clients in complex business litigation matters in state and federal courts, with…

Benjamin Jensen is partner in the firm’s Business Litigation Group, where he is a member of the Intellectual Property Litigation and Data Privacy and Security Practice Teams. His practice involves representing clients in complex business litigation matters in state and federal courts, with a focus on matters involving intellectual property, data security, and contract disputes. Benjamin’s practice also includes representing health care providers and corporate clients in regulatory matters before the Connecticut departments of Health, Social Services, and Banking. Read his rc.com bio here.

Read more about Benjamin JensenEmail
Show more Show less
  • Posted in:
    Health Care and Life Sciences, Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo