Healthcare.gov has been racked with technical problems since the site’s launch, but a new vulnerability may have unintentionally exposed users. Last week, researcher Ben Simo reported that the site’s Password Reset function was vulnerable to social engineering, and that by manipulating the site, an attacker could deduce whether a given username was in use and what email address was associated with that username. The vulnerability was reportedly fixed on Monday, but for days after, crucial user info was exposed to anyone with rudimentary web skills.
Security hole in Healthcare.gov exposed user email addresses


The email exposure may sound minor, but it’s crucial info for healthcare fraudsters, who may seek to target citizens as they enter the exchange. It’s also a bad sign for the overall design of the site, since the hack in question is relatively simple to execute or predict. On Twitter, the researcher was careful to note that he did not hack any Healthcare.gov accounts, but deduced the vulnerability from observing publicly available documents and disclosed it in the spirit of public safety.
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
Most Popular
Most Popular
- The Apple Watch Series 12 is the start of a new wearable era
- OpenAI and Microsoft knew they were starting a ‘doom loop’ for the web
- The 2.5-hour AI-generated Odyssey movie is 2.5 hours too long
- The iPhone 18 Pro’s big camera update is all about the small gains
- This cartridge-playing Game Boy clone is smaller and cheaper than Analogue’s Pocket









