Advocate Aurora Health (AAH), a 26-hospital healthcare system in Wisconsin and Illinois, is notifying patients of a breach that stole the personal information of 3,000,000 patients.
See also: UK: Meta receives final order to sell Giphy

The incident was caused by the inappropriate use of Meta Pixel on AAH websites, where patients log in and enter sensitive personal and medical information.
Meta Pixel is a JavaScript that helps website operators understand how visitors interact with the website, helping them make targeted improvements.
However, the tracker also sends sensitive data to Facebook , which then shares it with a vast network of marketers who target patients with ads tailored to their needs.
Meta Pixel is used by many hospitals in the country, exposing millions of people to third parties and triggering class action lawsuits against the relevant organizations.
In August 2022, US healthcare provider Novant Health revealed the inappropriate use of Meta Pixel in its “ MyChart ” portal application , which exposed 1.3 million patients.
See also: Russia puts Meta on the terrorist list

AAH's data breach notification states that the following information may have been exposed through Meta Pixel:
- IP address
- Dates, times, and locations of scheduled appointments
- Medical provider information
- Type of appointment or procedure
- Communications between MyChart users, which may have included first and last names and medical record numbers
- Insurance information
- Proxy account information
AAH reported that the breach affected 3 million people at the U.S. Department of Health.
The healthcare provider has disabled the Pixel on all systems and is implementing safeguards to prevent a similar exposure from happening again.
See also: Meta: App developers sued for stealing over 1 million WhatsApp accounts
Patients are advised to use their web browser's tracking blocking features or use incognito mode when logging into medical portals. Those with a Facebook or Google account should check their privacy settings.
AAH has also compiled a FAQ page to help patients find answers to common questions about the data breach.
