House Panel Demands Stronger Cybersecurity in Wake of Health Records Breach

April 19, 2023 by Tom Ramstack
House Panel Demands Stronger Cybersecurity in Wake of Health Records Breach
Rep. Nancy Mace, R-S.C.,

WASHINGTON — A month after cyberthieves looted a local health insurance database making off with the sensitive personal records of members of Congress and thousands of others, a member of a congressional panel looking into the incident on Wednesday declared “that may not be the full extent of the breach.”

The target of the cyberattack last month was the health insurance marketplace DC Health Link.

Names, Social Security numbers, birth dates and addresses of at least 56,415 people were stolen, including from members of Congress.

It was Rep. Nancy Mace, R-S.C., who raised the spector of an even larger breach, and as the investigation continues, suspicions are growing that more than 170,000 people might have had their personal data stolen. 

The hacker then offered the information for sale on the dark web.

“We all want to know how those who are responsible are going to be held accountable,” said Mace, who chaired the joint committee that held the hearing.

Several proposals are pending in Congress, all of them anticipating greater government oversight of public and private computer systems.

Mace said the growing use of artificial intelligence that makes penetrating computer networks easier means a solution must be reached quickly.

DC Health Link was created as the health insurance marketplace for the District of Columbia by the Obama administration’s Patient Protection and Affordable Care Act. In addition to average residents of Washington, D.C., many members of Congress are enrolled in DC Health Link.

On March 6, 2023, DC Health Link detected the data breach.

Days later, the hacker — who used the name Denfur — posted some of the data on the website BreachForums. Later that day, he added a message saying the “intended target WAS U.S. Politicians and members of U.S. Government.” The message also said, “Glory to Russia!”

The FBI took down BreachForums from the internet on March 15 and arrested the operator. The agency has not yet identified the cyberthief.

The cybersecurity firm NETSCOUT last month reported a surge in cyberattacks aimed at the U.S. government for its support of Ukraine in its war with Russia.

The attacks contributed to a Biden administration cybersecurity strategy announced last month that seeks tighter regulation and greater cooperation between industry and government.

Much of it is directed at protecting critical infrastructure, such as dams, hospitals and municipal water facilities.

In DC Health Link’s case, a cybersecurity review showed human error left the system vulnerable to attack. Computer architects who configured the system as early as 2018 left an IP address exposed without the need for authentication.

In other words, anyone who knew the IP address could gain access to two critical reports on DC Health Link’s website that listed personal data of thousands of its customers. No password was needed.

“The cause of this breach was a server that was misconfigured,” said Mila Kofman, executive director of the D.C. Health Benefit Exchange Authority. She called it “a mistake” that already has been corrected.

Nevertheless, the damage was done, leading some lawmakers to lament over the potential for more cyberthreats.

“Data breaches are only going to grow,” said Rep. Gerry Connolly, D-Va.

You can reach us at [email protected] and follow us on Facebook and Twitter

A+
a-

Corrections

Article headline was incorrectly updated after the original publication to read "Senate Panel" when the meeting was in the U.S. House of Representatives. The headline has since been corrected.

  • cybersecurity
  • Nancy Mace
  • In The News

    Health

    Voting

    Cybersecurity

    Americans Reporting Nationwide Cellular Outages From AT&T, Cricket Wireless and Others

    A number of Americans are dealing with cellular outages on AT&T, Cricket Wireless, Verizon, T-Mobile and other service providers, according... Read More

    A number of Americans are dealing with cellular outages on AT&T, Cricket Wireless, Verizon, T-Mobile and other service providers, according to data from Downdetector. AT&T had more than 73,000 outages around 9:30 a.m. ET, in locations including Houston, Atlanta and Chicago. The outages began at approximately... Read More

    States and Congress Wrestle With Cybersecurity at Water Utilities Amid Renewed Federal Warnings

    HARRISBURG, Pa. (AP) — The tiny Aliquippa water authority in western Pennsylvania was perhaps the least-suspecting victim of an international... Read More

    HARRISBURG, Pa. (AP) — The tiny Aliquippa water authority in western Pennsylvania was perhaps the least-suspecting victim of an international cyberattack. It had never had outside help in protecting its systems from a cyberattack, either at its existing plant that dates to the 1930s or the... Read More

    December 6, 2023
    by Dan McCue
    HHS Unveils Next Steps to Enhance Cybersecurity of Health Care Records

    WASHINGTON — The bad guys in cyberspace want your health care records.  Between 2018 and 2022, there was a 93%... Read More

    WASHINGTON — The bad guys in cyberspace want your health care records.  Between 2018 and 2022, there was a 93% increase in large breaches in the health care sector, with a 278% increase in large breaches involving ransomware, according to the Department of Health and Human... Read More

    Insider Q&A: Pentagon AI Chief on Network-Centric Warfare, Generative AI Challenges

    The Pentagon's chief digital and artificial intelligence offer, Craig Martell, is alarmed by the potential for generative artificial intelligence systems... Read More

    The Pentagon's chief digital and artificial intelligence offer, Craig Martell, is alarmed by the potential for generative artificial intelligence systems like ChatGPT to deceive and sow disinformation. His talk on the technology at the DefCon hacker convention in August was a huge hit. But he's anything... Read More

    October 31, 2023
    by Tom Ramstack
    US Workforce Unprepared for AI, Technology Experts Tell Senate

    WASHINGTON — President Joe Biden’s executive order Monday setting regulatory standards for artificial intelligence prompted witnesses at a Senate hearing... Read More

    WASHINGTON — President Joe Biden’s executive order Monday setting regulatory standards for artificial intelligence prompted witnesses at a Senate hearing Tuesday to say it is only a first step in a process likely to transform American workplaces. “Artificial intelligence will not only disrupt lives, it will... Read More

    July 18, 2023
    by Tom Ramstack
    Congress Told AI Holds Great Risks and Benefits for US Military

    WASHINGTON — Artificial intelligence experts warned Tuesday during a congressional hearing of ominous dangers for the United States if it... Read More

    WASHINGTON — Artificial intelligence experts warned Tuesday during a congressional hearing of ominous dangers for the United States if it falls behind in developing the technology but a bright future by taking the lead. One of the greatest risks would be defending against a foreign enemy... Read More

    News From The Well
    scroll top