Thursday, October 20, 2022

Healthcare system says pixel penetration tracking may have affected 3 million patients

Advocate Aurora Health, a major nonprofit healthcare system in the Midwest, is informing patients that the use of tracking pixels in web design and online services may leak sensitive information.

The security incident was reported to the Department of Health and Human Services on October 14, according to the agency’s database of irregularities currently under investigation. The entry describes the breach as an unauthorized disclosure of electronic medical records affecting 3 million individuals.

The organization is only the latest in a string of medical providers to reveal that efforts to better understand patient behaviors have left data exposed.

Over the summer, an investigation by The Markup found that 33 of the 100 best US hospitals ranked by Newsweek had leaked scheduling information to social media giant Meta via pixel tracking. Pixels, which are not visible to users on a website, are commonly used to measure online traffic and visitor behavior, but can be especially revealing if placed on websites that provide sensitive services, such as healthcare.

Advocate Aurora Health operates 27 hospitals and more than 500 outpatient clinics, according to its website. In a data breach notice posted online, attorney Aurora Health explained that breach-tracking pixels from Google and Meta or other similar tools share data, including some protected patient information, with third parties.

“Out of great caution, Advocate Aurora Health has decided to assume that all patients with an Advocate Aurora Health MyChart account (including users of the LiveWell app), as well as any patients who have used scheduling tools on the AAH platforms, may have been affected,” the FAQ said. to the patient.

The potentially compromised data included the patient’s IP addresses, insurance or medical record number, and information about appointments such as time, provider, and procedure. Advocate Aurora Health said it believes “no social security number, financial account, credit card or debit card information has been compromised.”

The organization wrote that it disabled these trackers on its services and “launched an internal investigation to better understand patient information sent to our vendors.”

Advocate Aurora Health was previously among about 170 healthcare providers who had patient information compromised in a cybersecurity breach for radiation service provider Elektra in 2021.

It’s not the only healthcare organization managing the ramifications of pixel tracking.

WakeMed, which operates several hospitals around Raleigh, made a similar announcement last week — reporting that currently disabled tracking pixels from Meta may have compromised patient scheduling information from 2018 through May.

Andrea (they/them) is a senior political reporter at The Record and a long-time cybersecurity journalist covering ThinkProgress Technology Policy (RIP), and then The Washington Post from 2013 until 2016, before conducting deep investigations into public records at Project on Government Oversight. and American censorship. Their work has also been published in Slate, Politico, The Daily Beast, Ars Technica, Protocol and other outlets. Peterson also produces independent creative projects under her Plain Great Productions brand and can generally be found online as kansasalps.



Originally published at San Jose News Bulletin

No comments:

Post a Comment

The best events of the ninth week

There were eruptions – a lot of eruptions – in the ninth week. There were also surprises when a field goal in the last second lifted St Ig...