海角大神

海角大神 / Text

Obamacare website: Does it violate privacy rights?

At a congressional hearing Thursday, Republicans implied that the Obamacare website violates a federal privacy law 鈥 a characterization that prompted one Democrat to say, 'I will not yield to this monkey court!'

By Mark Trumbull, Staff writer
Washington

Lawmakers in Congress exchanged heated words Thursday about the Obamacare website 鈥 and the issue they were concerned about was privacy, not just the site鈥檚 technical troubles.

Republicans implied that the website violates a federal privacy law.

Democrats objected to that characterization, with one saying, 鈥淚 will not yield to this monkey court!"

The privacy law at issue is the Health Insurance Portability and Accountability Act (HIPAA), which includes provisions to safeguard Americans鈥 privacy in the arena of health care.

At a congressional hearing Thursday on the website, an indignant Rep. Joe Barton of Texas led the Republican attack by citing a nugget of information reported recently by The Weekly Standard. The conservative publication reported that 鈥渂uried in the source code of Healthcare.gov is this sentence that could prove embarrassing: 鈥榊ou have no reasonable expectation of privacy regarding any communication or data transiting or stored on this information system.鈥 鈥

鈥淗ow in the world can this be HIPAA compliant?鈥 Representative Barton asked panelists at the hearing 鈥 federal contractors who had helped build the website.

Cheryl Campbell, an executive at the contractor CGI Federal, passed the buck on that question to the agency that took the lead role in creating the website, the Centers for Medicare & Medicaid Services.

Some technology experts, however, said it鈥檚 not unusual for source code to contain extraneous verbiage that鈥檚 not relevant or intended to be read by users. The Weekly Standard article itself referred to the no-privacy statement as something 鈥渘ot visible to users and obviously not intended as part of the terms and conditions鈥 for use of the website.

Some Democrats at the hearing fired back at Barton.

Rep. Frank Pallone of New Jersey accused him of trying to 鈥渟care people鈥 about the Affordable Care Act. The HIPAA privacy standards focus specifically on the sharing of personal medical information, and such information is not moving across the Obamacare website, Representative Pallone said.

It was when Barton asked Pallone to yield so he could respond that the New Jersey congressman erupted: 鈥淚 will not yield to this monkey court!鈥

Another Democrat at the hearing made the same point about privacy, noting that the Obamacare enrollment process asks whether an individual smokes and for some other personal details (age, name, income, etc.), not for medical information.

The Health and Human Services Department, on its website, says, 鈥渢he HIPAA Privacy Rule ... protects the privacy of individually identifiable health information.鈥

Democrats appeared to get the upper hand on the issue with their pushback. That doesn鈥檛 mean, however, that the HealthCare.gov website won鈥檛 continue to draw scrutiny and concern over privacy issues.

Several million American households are expected to enter personal information, such as about their finances and current health-insurance status, on the website in coming months. Both outside security experts and some members of Congress are concerned that the safeguarding of that information is at risk.

Rep. Mike Rogers (R) of Michigan, who also chairs the House Intelligence Committee, voiced concern that vast amounts of information, passing back and forth among Obamacare computers systems and insurance firms or other federal agencies, will be vulnerable to data theft.

鈥淚 am more nervous [than] when I got here," he said partway through the hearing.