Health care data hub gets authority to operate

health data

A key piece of technology needed to enroll applicants in the insurance marketplaces created by the 2010 health care overhaul has received authorization to operate, setting the stage for the exchanges' Oct. 1 launch.

News of the authorization stunned many observers, given that a  report from the Health and Human Services Inspector General revealed that testing for the data hub had fallen behind schedule, and that security authorization wasn't due to be completed until Sept. 30, one day before the hub is scheduled to go online.

Former Social Security Commissioner Michael Astrue called assurances that the data hub meets security standards "untrue or problematic" in testimony Sept. 11 before the Homeland Security Cybersecurity, Infrastructure Protection, and Security Subcommittee. "Despite the [CMS] letter this morning, many states will be unready for Oct. 1," he added.

According to Astrue, the system needs to store data in order to investigate reports of security breaches, although CMS continues to stress in public statements that the system does not store data.

According to CMS, the system is protected by continuous monitoring and other security systems to detect anomalous behavior and possible breaches. Potential security incidents would be reported to authorities, including the HHS Office of Inspector General Cyber Crimes Unit which are authorized to investigate.

Despite the doubters, administration officials hailed the latest development.

"The hub is critical to the operation of both the Federally Facilitated Marketplace and State-Based Marketplaces, enabling them to provide accurate and timely eligibility determinations,” Federal Chief Technology Officer Todd Park said in an e-mailed statement. “After over two years of work, it is built and ready for operation, and we have completed security testing and certification to operate.  This is an important step in being ready for open enrollment on October 1."

Security testing for the data hub, which connects information from a variety of government databases to determine individual eligibility for insurance coverage, was completed Aug. 23, and the authority to operate was issued Sept. 6, according to a letter from Marilyn Tavenner, administrator of the Centers for Medicare and Medicaid Services, to Rep. Bennie Thompson of Mississippi, ranking Democrat on the Homeland Security Committee.

"The completion of this testing confirms that the hub comports with the stringent standards," Tavenner wrote, including the requirements of the Federal Information Security Management Act and other federal laws, as well as internal standards from the Office of Management and Budget, the Department of Homeland Security, the National Institute of Standards and Technology, and other agencies.

The size of the system presents a potentially inviting target to hackers and information thieves. Stephen Parente, an academic who specializes in health insurance technology, said the combined databases connected under the hub, "constitute the largest personal data integration government project in the history of the republic, with up to 300 million American citizen records needing to be combined from five federal agencies."

Rep. Patrick Meehan (R-Pa.), chairman of the subcommittee that held the hearing, said that he is concerned that "personally identifiable information for every applicant and their families will pass through the data hub." He's worried about the "increasing sophistication" of online malefactors, "including state-sponsored actors who may wish to do us harm."

Many of the critical specifications of the data hub remain a secret, even from Congress and the inspector general, in large part as a security measure, so it's not possible to evaluate assurances from CMS that the system does not store data. Parente noted that, "the fact that only a handful of individuals know truly how this will operate may preserve some security," but he said that more transparency would strengthen the overall operation of the hub.

CMS still needs to conclude service level agreements with federal partners before the hub can be operational. These are expected to be wrapped up by Sept. 27, according to the HHS Assistant Inspector General Kay Daly.

About the Author

Adam Mazmanian is FCW's senior staff writer, and covers Congress, health IT and governmentwide IT policy. Connect with him on Twitter: @thisismaz.

The 2015 Federal 100

Meet 100 women and men who are doing great things in federal IT.


  • Shutterstock image (by venimo): e-learning concept image, digital content and online webinar icons.

    Can MOOCs make the grade for federal training?

    Massive open online courses can offer specialized IT instruction on a flexible schedule and on the cheap. That may not always mesh with government's preference for structure and certification, however.

  • Shutterstock image (by edel): graduation cap and diploma.

    Cybersecurity: 6 schools with the right stuff

    The federal government craves more cybersecurity professionals. These six schools are helping meet that demand.

  • Rick Holgate

    Holgate to depart ATF

    Former ACT president will take a job with Gartner, follow his spouse to Vienna, Austria.

  • Are VA techies slacking off on Yammer?

    A new IG report cites security and productivity concerns associated with employees' use of the popular online collaboration tool.

  • Shutterstock image: digital fingerprint, cyber crime.

    Exclusive: The OPM breach details you haven't seen

    An official timeline of the Office of Personnel Management breach obtained by FCW pinpoints the hackers’ calibrated extraction of data, and the government's step-by-step response.

  • Stephen Warren

    Deputy CIO Warren exits VA

    The onetime acting CIO at Veterans Affairs will be taking over CIO duties at the Office of the Comptroller of the Currency.

  • Shutterstock image: monitoring factors of healthcare.

    DOD awards massive health records contract

    Leidos, Accenture and Cerner pull off an unexpected win of the multi-billion-dollar Defense Healthcare Management System Modernization contract, beating out the presumptive health-records leader.

  • Sweating the OPM data breach -- Illustration by Dragutin Cvijanovic

    Sweating the stolen data

    Millions of background-check records were compromised, OPM now says. Here's the jaw-dropping range of personal data that was exposed.

  • FCW magazine

    Let's talk about Alliant 2

    The General Services Administration is going to great lengths to gather feedback on its IT services GWAC. Will it make for a better acquisition vehicle?

Reader comments

Thu, Sep 12, 2013

It is sad we continue down this road. Everyone knows its not going to work as everyone thinks - its driving up health care, not lowering it. Come on people, swallow your pride and admit it was wrong. How do you sleep at night? Its not about you its about the US. Even if it wasn't ready, they are not going to tell us. The Feds have never released new software with a big problem - LOL.

Thu, Sep 12, 2013

As an IT professional,this is downright scary. With so few really knowing how this works (according to the article this is by design), and misadventure might be very difficult to trace and like a video camera showing a crime, the horse is out of the barn before a real person gets involved. There's going to be identity theft (at least) with this.

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above