Skip to content

Comment on HealthCare.gov Sends Personal Data to Dozens of Tracking Websitesparent

Comments

Reading the example more closely, that's part of a URL:

https://4037109.fls.doubleclick.net/activityi;src=4037109;ty...?

Unfortunately, a quick Google search doesn't explain what the oref parameter does but from the name I'm assuming it's something like "original referrer".

You don't need malice to explain this – it's entirely plausible to imagine that some people wanted to track user activities and they had a staggering lapse in HIPAA auditing due to the rush of getting the site out and stabilized.

it's entirely plausible to imagine that some people wanted to track user activities and they had a staggering lapse in HIPAA auditing due to the rush of getting the site out and stabilized.

Considering they spent 1.7 billion on the site, I simply cannot believe that they were so unorganised and lazy on their testing that they couldn't find this. Otherwise I don't know what to think anymore.

I don't think it's accurate to say "they spent 1.7 billion on the site".

I think the $1.7 billion figure comes from this OIG report http://oig.hhs.gov/oei/reports/oei-03-14-00231.pdf

However, the OIG report has a number of important caveats:

* The list of 60 contracts in the report includes contracts to support state websites and for programs unrelated to the website (for instance, I found an $85 million contract related to accountable care organizations, which doesn't seem to have any connection to the website).

* The $1.7 billion is not the amount expended, it's the estimated value at the time the contract was awarded if all the options are exercised. When you look at the individual contracts, this estimated value turns out not to be very useful. Some contracts had double the estimated expenditure, some had $0 expended. Looking at the total amount expended, you get a figure of $500 million.

So I think it's more reasonable to say that they spent $500 million on various projects to implement the law, including both the user-facing website and all the behind-the-scenes stuff.

rush of getting the site out and stabilized.

I agree that there's no evidence, at least not yet, of malicious intent. But remember that the "rush of getting the site out" took place back in 2012-2013, with a launch in 2013. It's 2015 now.

Oh, sure – I just suspect that project has been in death-march mode for the last few years. I'd be shocked if the initial launch & stability rush wasn't immediately followed by “now that that's done, we have this backlog of postponed requirements…”

Would it excuse it if it were, say, not HealthCare.gov but rather some private company's website?

(probably not)

I don't see anyone excusing it – only discounting the supposition that it was intentional.

The only reason this is particularly newsworthy is that it's a .gov service connected to a contentious political issue – I mean, my health insurance company uses the same DoubleClick tracking service and I doubt I could even get a reporter to call me back if I tried to peddle some conspiracy theory about it.

Good digging, and I think you're right, this certainly explains how the data could have inadvertently made it from Referrer into the request.

There is also such a thing as criminal negligence, right?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.