BREAK IN TRANSCRIPT
Mr. BILIRAKIS. Thank you, Mr. Chairman. I appreciate it very much.
Mr. Speaker, I rise today in support of the Health Exchange Security and Transparency Act. I am pleased to be an original cosponsor of this legislation, and I am glad we are addressing this very important issue on the House floor today.
Each day, I hear from constituents in Florida's 12th Congressional District who are experiencing the negative impacts of ObamaCare. Contrary to the very promises the law was sold on, my constituents have lost their health care coverage, have seen their premiums rise, and were forced to choose new doctors. Now they are faced with concerns regarding their personal information and whether it is compromised--all because the President's signature law was never really ready for prime time.
The Energy and Commerce Committee, which I am a member of, has held numerous hearings into the failed Web site and the lack of testing that occurred to ensure the Web site was properly secured.
In these hearings, we have learned that 30 to 40 percent of the Web site isn't built; end-to-end security testing wasn't performed; and CMS' own chief security information officer recommended against an Authority to Operate because of cybersecurity concerns.
Her memo even stated:
There is no confidence that personally identifiable information will be protected.
It was the administrator of CMS, not that chief information officer, that signed off on the ATO.
Mr. Speaker, does this sound like a safe and secure Web site? Millions of Americans were forced to sign up for the exchanges in order to avoid individual mandate fines. And now each of these individuals, including myself and many in this Chamber, are potential victims of identity theft.
While privacy in the health care realm is typically protected by HIPAA, it does not apply to HHS or the federally run exchanges. Furthermore, data notification is critical to maintaining security, and individuals should be notified when their personal information could be compromised. Yet, in the final rules HHS published in August, it did not finalize a data breach notification rule. Instead, it stated that it is up to ``CMS to determine whether a risk of harm exists and if individuals need to be notified.''
A government bureaucrat, Mr. Speaker, should not be given the power to determine whether the loss of personally identifiable information constitutes harm. We do not know how many breaches have occurred on healthcare.gov, whether due to the accidental sharing of information or otherwise, because there is currently no public disclosure requirement. The Health Exchange Security and Transparency Act will bring accountability and transparency to the administration and the health care exchanges.
I strongly urge my colleagues in the House to support this bill today, and I urge all, of course, our colleagues in the Senate to swiftly take up this bill so that we may pass it into law.
BREAK IN TRANSCRIPT