An additional problem, as I see it, is that the Obama administration made unambiguous assurances that no PII was being collected as part of Healthcare.gov's use of web measurement tools. Here's the excerpt from the privacy policy:
HealthCare.gov uses a variety of Web measurement software tools. We use them to collect the information listed in the “Types of information collected” section above. The tools collect information automatically and continuously. No personally identifiable information is collected by these tools.https://www.healthcare.gov/privacy/
Note the last sentence is in bold on the actual web page.
A Department of Health and Human Services organ called the Centers for Medicare & Medicaid Services is responsible for the site. An enterprising HN reader might want to skim through the CMS (very long) privacy impact assessment to see if there are any other incorrect claims about Healthcare.gov:
http://www.hhs.gov/pia/cms-pia-summary-fy12q4.pdf
It will be interesting to see if anyone gets fired as a result of this particular privacy screwup. The buck should stop somewhere, right?
A Department of Health and Human Services organ called the Centers for Medicare & Medicaid Services is responsible for the site. An enterprising HN reader might want to skim through the CMS (very long) privacy impact assessment to see if there are any other incorrect claims about Healthcare.gov: http://www.hhs.gov/pia/cms-pia-summary-fy12q4.pdf
Is there any way to split this up so each person is responsible for a section? you'd miss a lot by missing context... but if the section readers bullet pointed everything, that could be combined into a larger context.
Or, in HN speak, we could crowdsource a real-world Map/Reduce job to support big data in the citizen-scientist.
I love the idea of a real-world map/reduce job. :) But before spending any time on this, please make sure it's the right PDF. It does mention Healthcare.gov, but only a few times, and I'm no expert on HHS organizational structure. Here's the full directory of PIAs: http://www.hhs.gov/pia/
Nice find. Considering the bug is literally staring every single user in the face on the URL bar, I would imagine it would be hard to pin blame on an individual.
I guess this is the final nail in the coffin for the 'many eyes' theory though.
At least it will make a good t-shirt;
"Query String Parameters Are Not Private"
"Friends Don't Let Friends Store PHI in Query Parameters"
I think the 'someone needs to be fired' is just press release journalism. It makes for an easy narrative. "There's a problem at healthcare.gov" is the first story. "What happened at healthcare.gov" is the second story. "Blah Jones has resigned" has everybody wiping their hands and looking for the next press release story to write about.
It's certainly possible that a given individual is meaningfully responsible for a problem and that they are incompetent, but it isn't necessarily the case. If the actual problem is organizational, a scapegoat just papers over it, it won't fix anything.
I didn't say "someone needs to be fired" -- that's a paraphrase of what I typed, not a quote.
My point is a broader one: When you have committees and subcommittees and working groups and HHS IT people and CMS IT people and task forces and contractors and subcontractors and new replacement contractors (Accenture) and undersecretaries and sub-sub contractors and assistant secretaries and White House aides and political consultants and PR firms and deputy chiefs of staff and deputy undersecretaries all participating to some extent in the $1B+ process that is the supremely functional Healthcare.gov site we all know and love, the buck can be passed endlessly.
But in all that morass of a process, someone was or should have been responsible for ensuring that standard privacy practices were followed. To her credit, Kathleen Sebelius resigned last year (though not immediately) as a result of what the NYT called the "disastrous rollout" of Helathcare.gov. It is worth looking at whether there is any accountability in the form of dismissals or resignations with this privacy snafu.
If there is not, we should draw our own conclusions.
Comments
An additional problem, as I see it, is that the Obama administration made unambiguous assurances that no PII was being collected as part of Healthcare.gov's use of web measurement tools. Here's the excerpt from the privacy policy:
HealthCare.gov uses a variety of Web measurement software tools. We use them to collect the information listed in the “Types of information collected” section above. The tools collect information automatically and continuously. No personally identifiable information is collected by these tools. https://www.healthcare.gov/privacy/
Note the last sentence is in bold on the actual web page.
A Department of Health and Human Services organ called the Centers for Medicare & Medicaid Services is responsible for the site. An enterprising HN reader might want to skim through the CMS (very long) privacy impact assessment to see if there are any other incorrect claims about Healthcare.gov: http://www.hhs.gov/pia/cms-pia-summary-fy12q4.pdf
It will be interesting to see if anyone gets fired as a result of this particular privacy screwup. The buck should stop somewhere, right?
Is there any way to split this up so each person is responsible for a section? you'd miss a lot by missing context... but if the section readers bullet pointed everything, that could be combined into a larger context.
Or, in HN speak, we could crowdsource a real-world Map/Reduce job to support big data in the citizen-scientist.
I love the idea of a real-world map/reduce job. :) But before spending any time on this, please make sure it's the right PDF. It does mention Healthcare.gov, but only a few times, and I'm no expert on HHS organizational structure. Here's the full directory of PIAs: http://www.hhs.gov/pia/
Nice find. Considering the bug is literally staring every single user in the face on the URL bar, I would imagine it would be hard to pin blame on an individual.
I guess this is the final nail in the coffin for the 'many eyes' theory though.
At least it will make a good t-shirt;
OK, never mind about the t-shirt.I think the 'someone needs to be fired' is just press release journalism. It makes for an easy narrative. "There's a problem at healthcare.gov" is the first story. "What happened at healthcare.gov" is the second story. "Blah Jones has resigned" has everybody wiping their hands and looking for the next press release story to write about.
It's certainly possible that a given individual is meaningfully responsible for a problem and that they are incompetent, but it isn't necessarily the case. If the actual problem is organizational, a scapegoat just papers over it, it won't fix anything.
I didn't say "someone needs to be fired" -- that's a paraphrase of what I typed, not a quote.
My point is a broader one: When you have committees and subcommittees and working groups and HHS IT people and CMS IT people and task forces and contractors and subcontractors and new replacement contractors (Accenture) and undersecretaries and sub-sub contractors and assistant secretaries and White House aides and political consultants and PR firms and deputy chiefs of staff and deputy undersecretaries all participating to some extent in the $1B+ process that is the supremely functional Healthcare.gov site we all know and love, the buck can be passed endlessly.
But in all that morass of a process, someone was or should have been responsible for ensuring that standard privacy practices were followed. To her credit, Kathleen Sebelius resigned last year (though not immediately) as a result of what the NYT called the "disastrous rollout" of Helathcare.gov. It is worth looking at whether there is any accountability in the form of dismissals or resignations with this privacy snafu.
If there is not, we should draw our own conclusions.
Sorry, I didn't mean to imply I was quoting you, limitations of the format.
To my point, Sebelius resigning didn't do anything to prevent this (apparent) mistake.