logo

Explaining security issues with healthcare.gov

ID: 426c305f-bd23-5e0a-9612-73fa4c079076

STIX ID: report--426c305f-bd23-5e0a-9612-73fa4c079076

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-03-25

Date Updated: 2026-05-01

...
...

David Kennedy (TrustedSec) summarizes his congressional testimony and blog post about security problems on healthcare.gov, explaining that passive reconnaissance and Google search techniques revealed approximately 70,000 exposed user records without any active hacking; he criticizes reliance on compliance (FISMA) as insufficient, calls out ongoing configuration and development flaws, and urges stronger federal oversight and comprehensive security testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.