
Cerebral , a telemedicine startup focused on mental health that rose to prominence during the early stages of the pandemic, has revealed that it has exposed the personal data of 3.1 million U.S. patients to companies social media and advertisers including Google, Meta and TikTok. According to a notice recently posted on Cerebral’s website, the company has been using “ pixels ” and other similar technologies tracking offered by companies including Meta, Google and TikTok for advertising purposes and thus collecting user data . This has been happening since October 2019, when Cerebral began operations.
See also: Blackbaud fined for concealing full extent of ransomware attack
After a recent review of its software, Cerebral found that through these tracking technologies, it was disclosing to third parties (Meta, Google, TikTok) certain patient information that may be “deemed protected health information” under the Health Insurance Portability and Accountability Act (HIPAA). The data Cerebral exposed includes names, phone numbers, dates of birth, and insurance information, among other things. In some cases, the company may also have exposed information it collected through mental health self-assessments that some patients to schedule appointments with a specialist or access other services. According to Cerebral, no social security numbers, bank details, or credit card numbers were disclosed.
See also: Akamai successfully thwarted a massive 900Gbps DDoS attack

Cerebral claims that since it became aware of the exposure of this data, it has “disabled, reconfigured, and/or removed” the tracking pixels that were responsible . “ In addition, we have enhanced our information security practices and control processes to further mitigate the risk of such information being shared in the future .” The U.S. Department of Health and Human Services is investigating Cerebral following the incident. It is worth noting that the Federal Trade Commission recently fined GoodRx $1.5 million for sharing patient information with Meta and Google.
In addition to being scrutinized for whether it violated HIPAA regulations, Cerebral is facing investigations by the Department of Justice and the Drug Enforcement Administration over its prescription of controlled substances, such as Adderall and Xanax. It has since stopped prescribing those drugs.
See also: Xenomorph Android malware: Now stealing data from 400 banks
Data breaches are serious issues that have the potential to cause irreparable damage, both financially and to reputation. That's why it's important for both website owners and businesses to take steps to protect themselves from such breaches.
Source: www.engadget.com
