HomeinetHospital websites continue to leak patient data to advertisers

Hospital websites continue to leak patient data to advertisers

A new Bloomberg -Feroot investigation reveals that nine of the ten largest U.S. healthcare companies are still leaking patient data to third parties. History is repeating itself because nothing has stopped it.

See also: Medtronic confirms data breach

patient data
Hospital websites continue to leak patient data to advertisers

There's now a familiar format in internet surveillance investigations: A journalist or researcher loads a web page, watches what's loading in the background, and discovers, often shockingly, where the data is going.

The latest Bloomberg survey, published this month, found that almost nothing has changed in the corner of the internet where it would be hardest to defend this fact: the websites of America's largest health care companies.

Working with privacy compliance firm Feroot Security, Bloomberg examined the websites of the 10 largest publicly traded health insurance companies, hospitals and laboratories in the U.S. Nine out of the 10 had advertising and analytics trackers installed on user registration or login pages.

About 15 percent of the broader sample of health websites the team examined could accurately read keystrokes on login pages, meaning that third parties involved could, in principle, collect social security numbers, usernames, passwords, email addresses, appointment times, billing details, and medical diagnoses.

It is, depending on how you frame it, either a story of persistence or a story of regulatory failure. Probably both. The shape of the problem has been visible for years. An academic study published in Health Affairs found that 98.6 percent of U.S. hospital websites included third-party tracking.

In 2022, it was reported that 33 of the top 100 hospital websites in the US had Meta’s Pixel sending data to Facebook every time a patient clicked a button to schedule an appointment. A research team showed in 2023 that nearly every hospital website in the country was leaking visitor data to ad tech vendors despite explicit privacy promises.

See also: Data breaches at healthcare organizations affect 600,000 people

Memorial Hospital and Manor ransomware attack
Hospital websites continue to leak patient data to advertisers

Federal regulators followed suit. The Office for Civil Rights and the Federal Trade Commission jointly warned about 130 hospitals and telemedicine providers in 2023 that using tracking technologies on patient-facing pages risked violating HIPAA and the Consumer Financial Protection Act.

The healthcare industry fought back. In June 2024, a federal judge in Texas sided with hospital associations, ruling that HHS had overstepped its authority by trying to extend HIPAA to a category of unauthenticated web monitoring. The agency’s appetite for enforcement has noticeably waned since then.

The result is a category of online activity that everyone involved knows is sensitive, that has been the subject of academic study, regulatory warnings, and federal litigation, and that, according to Bloomberg data, is no less common in 2026 than it was in 2022.

The third parties most frequently detected by Feroot's tools are well-known: Meta's tracking pixel, Google Analytics, LinkedIn Insights, TikTok Pixel , and a long line of advertising and brokerage data vendors.

The data they receive may include the page URL, search terms entered into a hospital’s symptom finder, scheduling actions, and, in typeable cases, fields entered before submission. Once this data leaves the hospital’s domain, the hospital, according to industry consensus, has limited control over what happens to it.

The business case for trackers is simple. They support ad performance, conversion measurement, and audience building, the same functions they exist for on retail or media websites.

See also: CareCloud cyberattack: Investigation into potential data exposure

Hospital websites continue to leak patient data to advertisers

The defense, when offered, is that the trackers are configured not to record protected health information and that hospitals have business associate agreements (or don't need them) with the relevant vendors.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS