A class action lawsuit has been filed in the Northern District of California against Meta (Facebook), UCSF Medical Center, and Dignity Health Medical Foundation, alleging that the organizations illegally collect sensitive healthcare data about patients for targeted advertising.

See also: Australian charged with developing Imminent Monitor RAT
This monitoring and data collection is reportedly taking place on medical portals beyond login walls, where patients enter highly sensitive information about themselves, their condition, doctors, prescription medications , and more.
According to the lawsuit, neither the hospitals nor Meta inform patients about the data collection, no user consents are sought, and there is no visible indication of this process.
The plaintiffs became aware of the violation of their privacy when Facebook, the social networking platform owned by Meta, began targeting them with ads tailored to their medical condition.
See also: Phishing attack manipulates victims into handing over their passwords
Meta Pixel
Meta Pixel is a piece of code that can be inserted into any website to help with visitor profiling, data collection, and targeted advertising.
It occupies the space of a single pixel, hence the name and secrecy, and helps collect data such as button clicks, scrolling patterns, data entered into forms, IP addresses, and more.
This data collection occurs for all users even if they do not have a Facebook account. However, for Facebook users the data collected is linked to account for better relevance.
Because the Meta Pixel is installed on multiple websites, users will be tracked and targeted with specific ads across multiple locations on the Internet.
A recent survey by The Markup found the Meta Pixel on 30% of the top 80,000 most popular websites, including many anti-abortion clinics and other healthcare providers.
See also: Microsoft links Raspberry Robin malware to Evil Corp attacks
The lawsuit alleges that Meta's tracking code is present on 33 websites of the top 100 hospitals in the United States , and in seven cases, the code goes beyond password - protected patient portals .
According to the complaint, the 33 hospitals found to have Meta Pixel collectively handled over 26 million inpatient and outpatient visits in 2020 alone.

Privacy violation
The plaintiffs felt they were violated as they had never agreed to the collection of sensitive medical data, let alone its use in targeted advertising.
Meta and the healthcare providers are accused of knowing that their data collection operation was illegal, yet continuing to do it and hiding it from the people they were monitoring.
Meta's efforts to filter sensitive medical information from the data it collects have proven ineffective, according to The Markup and the New York State Department of Financial Services, which reviewed the issue in February 2021.
In conclusion, plaintiffs, on behalf of anyone in a similar situation, are seeking claims for relief regarding invasion of privacy , breach of confidentiality of medical information , breach of contract , the Computer Data Access Act , and more.
Information source: bleepingcomputer.com
