Health Exchange Security and Transparency Act of 2014

Floor Speech

Date: Jan. 10, 2014
Location: Washington, DC

Ms. DeGETTE. Mr. Speaker, some mornings in Congress I wake up and I say, now here is a solution in search of a problem; and this morning is one of those days.

We are hearing about how the Web site is not secure, how there can be security breaches. Ironically, we are hearing about security breaches with a private company, Target, and how terrible it is, and that is why we have to do a bill.

But, in fact, we haven't seen any security breaches with healthcare.gov or the Web sites around the Affordable Care Act. And I want to stress that.

I am the ranking Democrat on the Oversight and Investigations Subcommittee of Energy and Commerce, and we have had a number of hearings, and we have had classified briefings. Here is some information that is not classified information.

There has been not one successful hack into www.healthcare.gov. Let me say that again. Nobody has successfully been able to breach www.healthcare.gov. Furthermore, as we have recently learned in a briefing, www.healthcare.gov, interestingly, has not been targeted any more than any other Federal Web site for hackers.

So why are we doing this bill? I have got to associate myself with Ranking Member Pallone's comments, that the only reason we could be doing this bill is to try to have a chilling effect against people signing up to get health insurance through the Web sites.

Let me say it again. There have been no successful breaches of www.healthcare.gov.

Now, if we really wanted to do a bill that would strengthen privacy, I would be all for that. I think that consumer privacy is one of the most important things we can do. But really, when you look at the details of this bill, there is nothing here that furthers consumer notification or consumer privacy.

First of all, there is no exemption or consideration of law enforcement. What if law enforcement found a potential breach and needed to investigate it? What if they needed more than 48 hours to make sure that, in fact, there was a breach before they notified people? Consider the harm that would occur if law enforcement did not have enough time and resources to fully investigate a security breach before it went public. The consequences of hasty and incorrect notification could just make the problem worse.

Secondly, based on how the bill is drafted, if there is a data breach in a State that has chosen to run its own exchange, like my home State of Colorado, HHS seems to bear an unnecessary burden of reporting the breach in the State exchange having nothing to do with the Federal exchange.

Might I remind my colleagues, State exchanges are entirely independent from www.healthcare.gov. HHS does not run them. HHS did not build their Web sites, and HHS did not develop their security protocols. So why should HHS have to get involved in the State-run exchanges?

The SPEAKER pro tempore. The time of the gentlewoman has expired.

Mr. PALLONE. Mr. Speaker, I yield an additional 1 minute to the gentlewoman from Colorado.

Ms. DeGETTE. So security for these State-based exchanges should be the responsibility of the States that are running them.

I could go on and on. There are more problems with this bill than pages in the bill.

So let's get real. Instead of bringing legislation like this to the floor without any committee action, why can't we sit down together in a bipartisan way and improve the way the Affordable Care Act works for our constituents? That is what our constituents want. They want affordable health insurance. They want health care. And they don't want unwarranted scare tactics and attacks. So let's sit down. Let's work together. Let's fix this legislation. And let's get real.


Source
arrow_upward