Like every other piece of software put on the Internet by the government, banks, health care consortiums, arms manufacturers, cat sharing startups or network equipment vendors, Healthcare.gov will achieve some semblance of security over the long term by having the crap beat out of it in production. Hopefully by good people first. They won't get there by starting over on the advice like this.
This story is an embarrassment for my field.
† I found the "report" to Congress; documented vulnerabilities include "undisclosed", open redirects, attacker control over the XML output of a search endpoint, a "test" subdomain on the Internet (no additional findings), Google search results with the token "test" in them (no additional findings), publicly indexed profiles on DATA.HEALTHCARE.GOV (the public dataset site), username enumeration via "this name taken" errors, the fact that they use Experian, the presence of jquery.fileupload.js, and CORS. I'm not sure any of these would even be sev:medium in a Matasano report; many would be sev:info, and a few, like Experian, wouldn't be documented at all.