There seems to be a trivial DOS vector with which you can prevent a person insured at the hkk from logging into their account. If your attack is sophisticated enough (which any script kiddie should be able to manage), you might even be able to make it so that even manual intervention from customer support might be useless, though I cannot speak to that (yet)