HR9515
Referred to committee
MFA Act
- Federal
- House
- Introduced Jun 29, 2026
- Session 119
Bill Text
Version IHThis Act may be cited as the Marketplace Fraud Accountability Act or the MFA Act.
Section 1311(c) of the Patient Protection and Affordable Care Act (42 U.S.C. 18031(c)) is amended by adding at the end the following new paragraph:
Subject to subparagraph (B), not later than the date that is 1 year after the date of enactment of this paragraph, the Secretary shall require the use of multi-factor authentication to verify the identity of any individual attempting to access the healthcare.gov website (or any successor website) for purposes of—
enrolling in a qualified health plan offered through an Exchange; or
accessing any personalized information with respect to such enrollment.
Subparagraph (A) shall not apply in the case of an individual that does not have access to broadband service or cellular service, or is otherwise unable to use multi-factor authentication for reasons specified by the Secretary.
For purposes of this paragraph, the term multi-factor authentication means authentication through the verification of 2 or more of the following types of authentication factors:
Knowledge factors, such as a password.
Possession factors, such as a token.
Inherence factors, such as biometric characteristics.
The amendments made by this subsection shall apply with respect to plan years beginning on or after the date that is 1 year after the date of enactment of this subsection.
Section 1311(c) of the Patient Protection and Affordable Care Act (42 U.S.C. 18031(c)) is amended by adding at the end the following new paragraph:
Subject to subparagraph (B), not later than the date that is 1 year after the date of enactment of this paragraph, the Secretary shall require the use of multi-factor authentication to verify the identity of any individual attempting to access the healthcare.gov website (or any successor website) for purposes of—
enrolling in a qualified health plan offered through an Exchange; or
accessing any personalized information with respect to such enrollment.
Subparagraph (A) shall not apply in the case of an individual that does not have access to broadband service or cellular service, or is otherwise unable to use multi-factor authentication for reasons specified by the Secretary.
For purposes of this paragraph, the term multi-factor authentication means authentication through the verification of 2 or more of the following types of authentication factors:
Knowledge factors, such as a password.
Possession factors, such as a token.
Inherence factors, such as biometric characteristics.
The amendments made by this subsection shall apply with respect to plan years beginning on or after the date that is 1 year after the date of enactment of this subsection.
Legislative Timeline
3 actions-
Introduced in House
-
Introduced in House
-
Referred to the House Committee on Energy and Commerce.