Open enrollment begins Nov. 9, the annual window for federal employees to review their health benefits and choose from new options. Due to the nature of information involved in this process, it is also an active time for fraudsters intent on stealing personal data.
Feds have become acutely aware of the dangers of lax cybersecurity in recent months and the open enrollment period is no time to slouch.
CYBERCON 2015: Sign up now for CyberCon 2015 to learn how best to protect your agency’s networks
“There are things that folks can do to make sure they are protecting their backsides and make sure their information isn’t compromised,” said Tom Greiner, director of technology for Accenture Federal Services, which provides cybersecurity and health IT solutions to the government.

Greiner offered four tips to feds to keep in mind during the open enrollment process:
- The password is not dead yet and logging into an enrollment system will likely include registering and creating a password. As bad actors get better at cracking passwords, Greiner said it is increasing important to make them strong and difficult to guess.
- Access the site in a secure manner. Greiner suggested using your government computer or a home computer on an encrypted network connection, “Rather than going down to your local public library or another public access site.”
- If you do have to enroll somewhere more public than your home, be sure no one is looking over your shoulder, he added.
- And be particularly wary of phishing emails during this time. Don’t click on unfamiliar links and inspect the URL to make sure the domain name matches the website you’d expect.
“These are all good basic hygiene things folks can do to be more secure when providing their protected health information,” Greiner said.
And the government is doing its part to improve security and privacy during this year’s enrollment period.
“An important part of that is continuing to protect your privacy when you’re shopping for health coverage,” he said in an Oct. 9 blog post.
Those updates include a new privacy manager tool and a Do Not Track option to prevent browsers from storing information and sharing it with advertisers.
“If you choose to opt-out, you’ll still have access to everything on the site but we won’t use information from your visit to analyze the site’s technical performance or use digital advertising to remind you about helpful information like deadlines,” Counihan said.
And once open enrollment is over, Greiner suggested keeping tabs on your credit and benefits over the next few months to make sure nothing leaked out.




