Marketplace Fraud Accountability Act
A BILL
To amend the Patient Protection and Affordable Care Act to require the use of multi-factor authentication to access certain information through healthcare.gov.
Sec. 2 Requiring the use of multi-factor authentication to access certain information through healthcare.gov
“(8) Multi-factor authentication
“(A) In general—Subject to subparagraph (B), not later than the date that is 1 year after the date of enactment of this paragraph, the Secretary shall require the use of multi-factor authentication to verify the identity of any individual attempting to access the healthcare.gov website (or any successor website) for purposes of—
“(i) enrolling in a qualified health plan offered through an Exchange; or
“(ii) accessing any personalized information with respect to such enrollment.
“(B) Exceptions—Subparagraph (A) shall not apply in the case of an individual that does not have access to broadband service or cellular service, or is otherwise unable to use multi-factor authentication for reasons specified by the Secretary.
“(C) Multi-factor authentication defined—For purposes of this paragraph, the term multi-factor authentication means authentication through the verification of 2 or more of the following types of authentication factors:
“(i) Knowledge factors, such as a password.
“(ii) Possession factors, such as a token.
“(iii) Inherence factors, such as biometric characteristics.”