The project manager in charge of launching the Obamacare website, Henry Chao, was blindsided to find out his boss, Tony Trenkle – CIO (Chief Information Officer for Healthcare.gov)  had written a memo to top officials saying the site could not be secured until mid-2014 or 2015.   Henry Chao was the launch approval project manager and shared to congressional committee he would not have approved if he knew.

The CMS Information Officer, Tony Trenkle, quit last week after his warning memo to CMS Administrator Marilyn Tavenner and HHS Secretary Kathleen Sebelius was revealed.  The Trenkle memo revealed the details of the site security risk, and Mr. Trenkle warned not to launch site.   His warnings were overridden by Ms. Tavenner.

CMS Head Marilyn Tavenner and HHS Secretary Kathleen Sebelius
CMS Head Marilyn Tavenner and HHS Secretary Kathleen Sebelius

SUMMARY:  So it appears that Marilyn Tavenner and Kathleen Sebelius knew the site was not secure.  Then, because of political fear, they kept Project Manager Chao in the dark, and told him to launch it regardless.  He launched it thinking the site was secure.

chao_244x183(CBS News) WASHINGTON — CBS News has learned that the project manager in charge of building the federal health care website was apparently kept in the dark about serious failures in the website’s security.   Those failures could lead to identity theft among buying insurance. The project manager testified to congressional investigators behind closed doors, but CBS News has obtained the first look at a partial transcript of his testimony.

Henry Chao, HealthCare.gov’s chief project manager at the Centers for Medicare and Medicaid Services (CMS), gave nine hours of closed-door testimony to the House Oversight Committee in advance of this week’s hearing. In excerpts CBS News has obtained, Chao was asked about a memo that outlined important security risks discovered in the insurance system.

Chao said he was unaware of a Sept. 3 government memo written by another senior official at CMS. It found two high-risk issues, which are redacted for security reasons. The memo said “the threat and risk potential (to the system) is limitless.” The memo shows CMS gave deadlines of mid-2014 and early 2015 to address them.

But Chao testified he’d been told the opposite.

What I recall is what the team told me, is that there were no high findings,” he said.

Chao testified security gaps could lead to identity theft, unauthorized access and misrouted data.

According to federal guidelines, high risk means “the vulnerability could be expected to have a severe or catastrophic adverse affect on organizational operations … assets or individuals.”

It was Chao who recommended it was safe to launch the website Oct. 1. When shown the security risk memo, Chao said, “I just want to say that I haven’t seen this before.”

A Republican staff lawyer asked, “Do you find it surprising that you haven’t seen this before?”

Chao replied, “Yeah … I mean, wouldn’t you be surprised if you were me?” He later added: “It is disturbing. I mean, I don’t deny that this is … a fairly nonstandard way” to proceed.

Late Monday, Health and Human Services told CBS News the privacy and security of consumers’ personal information are a top priority, and consumers can trust their information is protected by stringent security standards. The author of the security memo, Tony Trenkle, retired from CMS last week; no reason was given. (link)

BUSTED !

CMS Head Marilyn Tavenner and HHS Secretary Kathleen Sebelius
CMS Head Marilyn Tavenner and HHS Secretary Kathleen Sebelius
Share