Healthcare.gov gets stronger locks—but only if you can reach them
H.R. 9515 — MFA Act · Filed by Glenn Grothman (R-WI) · 3 cosponsors · Introduced Jun 29, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the federal healthcare.gov website to use multi-factor authentication (MFA)—a second verification method like a text code or fingerprint—when people enroll in health plans or access their enrollment information. The requirement takes effect one year after passage, with exceptions for people without broadband or cellular service or who cannot use MFA for other reasons the Secretary specifies.
Why we flagged it
The bill's sole operative mechanism is a security requirement—mandating MFA on a federal health-insurance portal. It is a straightforward cybersecurity measure, not a subsidy, deregulation, or appropriation.
What the text implies
- The Secretary's discretion to define additional exceptions ("reasons specified by the Secretary") creates regulatory flexibility but also potential for inconsistent application across demographic groups if not carefully administered.
- MFA requirement may create a temporary enrollment barrier during the transition period (1 year) if implementation is rushed or user education is inadequate, potentially reducing plan enrollment among less tech-savvy populations.
The full analysis lists 3 implications of this text.
Who stands to gain
cybersecurity software and authentication service providers (MFA platform vendors)