Advocate Aurora Health, a major nonprofit healthcare system in the Midwest, is informing patients that the use of tracking pixels in web design and online services may leak sensitive information.
The security incident was reported to the Department of Health and Human Services on October 14, according to the agency’s database of irregularities currently under investigation. The entry describes the breach as an unauthorized disclosure of electronic medical records affecting 3 million individuals.
The organization is only the latest in a string of medical providers to reveal that efforts to better understand patient behaviors have left data exposed.
Over the summer, an investigation by The Markup found that 33 of the 100 best US hospitals ranked by Newsweek had leaked scheduling information to social media giant Meta via pixel tracking. Pixels, which are not visible to users on a website, are commonly used to measure online traffic and visitor behavior, but can be especially revealing if placed on websites that provide sensitive services, such as healthcare.
Advocate Aurora Health operates 27 hospitals and more than 500 outpatient clinics, according to its website. In a data breach notice posted online, attorney Aurora Health explained that breach-tracking pixels from Google and Meta or other similar tools share data, including some protected patient information, with third parties.
“Out of great caution, Advocate Aurora Health has decided to assume that all patients with an Advocate Aurora Health MyChart account (including users of the LiveWell app), as well as any patients who have used scheduling tools on the AAH platforms, may have been affected,” the FAQ said. to the patient.
The potentially compromised data included the patient’s IP addresses, insurance or medical record number, and information about appointments such as time, provider, and procedure. Advocate Aurora Health said it believes “no social security number, financial account, credit card or debit card information has been compromised.”
The organization wrote that it disabled these trackers on its services and “launched an internal investigation to better understand patient information sent to our vendors.”
Advocate Aurora Health was previously among about 170 healthcare providers who had patient information compromised in a cybersecurity breach for radiation service provider Elektra in 2021.
It’s not the only healthcare organization managing the ramifications of pixel tracking.
WakeMed, which operates several hospitals around Raleigh, made a similar announcement last week — reporting that currently disabled tracking pixels from Meta may have compromised patient scheduling information from 2018 through May.
Originally published at San Jose News Bulletin
No comments:
Post a Comment