Daines Secures New Obamacare Website Security Provisions in Cybersecurity Bill

Press Release

Date: Jan. 15, 2014
Location: Washington, DC

WASHINGTON, D.C. -- Representative Steve Daines today successfully secured new security measures to protect Americans' personal information while using federal websites, including the Obamacare website, healthcare.gov.

Daines' amendment to H.R. 3696, the "National Cybersecurity and Critical Infrastructure Protection Act of 2013," was approved this afternoon during a Homeland Security Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies mark-up of the bill.

"The Obamacare website's failed launch and "limitless' security risks have allowed Americans to see firsthand the security flaws present in our federal websites," Daines stated. "It is unacceptable that federal agencies have knowingly put Americans' personal information at risk by failing to seriously address these problems, and it's clear that greater accountability and stronger efforts to protect Americans' personal information is needed. My amendment works to provide this needed oversight and puts new security and accountability measures in place to better protect Americans using all federal websites, including healthcare.gov."

Daines' amendment expands upon the security and accountability measures contained in the Cyber Awareness and Recovery Enhancement, a bipartisan bill Daines recently introduced with Representative Ron Barber (D-AZ) to address security risks plaguing the Obamacare marketplace website, and works to ensure that Americans' personal information is better protected while using any federal website.

The amendment directs the National Cybersecurity and Communications Integration Center (NCCIC) to assist Federal agencies in preventing and responding to data breaches involving personally identifiable information (PII). It provides technical assistance to federal agencies to prevent and respond to data breaches involving PII, requires federal agencies to notify all potential victims of a data breach involving PII within two business days, and ensures PII data breaches on federal networks are being reported to the NCCIC within 2 days as well as to Congress.

Republicans and Democrats on the Subcommittee applauded Daines' amendment, noting its timeliness and importance to protecting Americans' privacy.

"I have no objections, and just to complement our colleague on this very timely amendment to this legislation, and I look forward to supporting it," stated Ranking Member Yvette D. Clarke (D-NY).

"I also want to take a moment to express my deep appreciation to the gentleman for his work on this issue of privacy and private information," added Subcommittee Chairman Patrick Meehan (R-PA). "I mention again the comments that I made in my opening statements regarding the tremendous amount of work that went into ensuring the protection of personally identifying information, and I think this bill and the gentlemen's amendment have gone a long way in working out that balance."

A recent December 2013 Government Accountability Office report found that federal agencies are not effectively leveraging DHS' cybersecurity expertise, with 22,156 security incidents having taken place in 2012 alone and millions of Americans' personal information being put at risk due to "limitless" security risks in the Obamacare website.


Source
arrow_upward