The government stores personal information on millions of Americans who have used the Healthcare.gov system, a situation which is raising privacy concerns as the recent successful attack that compromised Office of Personnel Management data makes plain the damage that hackers can do.
Called the Multidimensional Insurance Data Analytics System, or MIDAS, the system stories names, Social Security numbers, financial accounts and other sensitive personal information. But according to an Associated Press report, there is no plan in place to destroy old records, raising eyebrows among cybersecurity experts.
Special Report: The OPM Data Breach: What You Need To Know
Privacy requires not retaining data any longer than necessary, said Lee Tien, a senior staff attorney at the Electronic Frontier Foundation, as cited in the article.
The government plans to store information in the database, maintained by CACI, indefinitely, according to an article in HIPAA Journal. The government estimates it has data on 1 million people in the system, but the HIPAA Journal article describes that estimate as “extremely conservative.”
The matter has caught the attention of some members of Congress. Rep. Diane Black, R-Tenn., has introduced a bill, the Federal Exchange Data Breach Notification Act of 2015, to enhance the responsibility of agencies to inform people when their personal information might be compromised.
“The Obama Administration’s incompetence when it comes to protecting taxpayers’ personal information knows no bounds and, to make matters worse, there is still no federal law in place requiring the government to simply notify you if your data is breached on Healthcare.gov,” Black said in a written statement.




