News: 1655733992

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

US lawsuit alleges tool used by hospitals shares patient data with Meta

(2022/06/20)


Social media megacorp Meta is the target of a class action suit which claims potentially thousands of medical details of hospital patients were shared with its Facebook brand.

The proposed class action

[1]PDF

, filed on Friday, centers on the use of Facebook Pixel, a tool for website marketing and analytics.

An anonymous hospital patient, named John Doe in court papers, is bringing the case — filed in the Northern District of California — alleging Facebook has received patient data from at least 664 hospital systems or medical providers, per the suit.

[2]

"Despite knowingly receiving health-related information from medical providers, Facebook has not taken any action to enforce or validate its requirement that medical providers obtain adequate consent from patients before providing patient data to Facebook," the lawsuit stated.

UK health company EMIS bought by US insurance giant

Health records provider EMIS bought by US insurance giant UnitedHealth Group has agreed to acquire EMIS Group, a UK software company specialising in electronic health records, in a deal set to be worth £1.24 billion ($1.52 billion). EMIS is widely used in UK's NHS and it was the software systems selected by the £10bn National Programme for IT which ran from 2003 to 2011.

The lawsuit alleges: "Facebook monetizes the information it receives through the Facebook Pixel deployed on medical providers’ web properties by using it to generate highly-profitable targeted advertising on and off Facebook."

The plaintiff claims that Facebook also offers the ability to engage in remarketing based on positive targeting, "serving specific ad campaigns to patients based on the specific actions those patients took", or negative targeting such as "ensuring that ads are not shown to users who have taken specific action."

[3]

[4]

On its website, [5]Meta says : "If Facebook's signals filtering mechanism detects Business Tools data that it categorizes as potentially sensitive health-related data, the filtering mechanism is designed to prevent that data from being ingested into our ads ranking and optimization systems."

Under US law, a health care provider or business associate of a health care provider "may not use or disclose protected health information except as permitted or required by" the Health Insurance Portability and Accountability Act.

Meta Pixel article

The lawsuit comes days after a separate investigation by news website The Markup. The non-profit outlet alleged patients signing into hospitals' online portals to schedule appointments, for example, could end up sending details of the reason for the appoints or speciality involved — for example, pregnancy or Alzheimer's — to Facebook via the analytics tool.

[6]Markup has been running a series on Meta's Pixel's presence on sites containing private information. In April, the same project reported Meta Pixel's [7]presence on US federal student aid websites. That investigation claimed Pixel data was being sent to Facebook containing full names, phone numbers, zip codes, and email addresses.

In this instance, the Metal Pixel was found on a third of Newsweek's top 100 hospitals list, including Johns Hopkins Hospital, UCLA Reagan Medical Center, and the University of Chicago Medical Center.

From hospital websites, the Pixel was found capturing the text of buttons being clicked, like "schedule online," the name of the doctor, search terms used to find them on the site, and conditions selected from dropdown menus when making an appointment.

The news site went on to claim that it found seven hospitals had the Meta Pixel present inside password-protected patient portals. "The data sent to hospitals included the names of patients' medications, descriptions of their allergic reactions, and details about their upcoming doctor's appointments," The Markup report said.

Data sent by the Meta Pixel is SHA-256 hashed, which means Meta shouldn't be able to tell what's in it, though it could still use it for tracking purposes. The data is also tied to an IP address, which could enable Facebook's algorithms to narrow things down pretty quickly.

The Markup said it has been "unable to determine whether Facebook used the data to target advertisements, train its recommendation algorithms, or profit in other ways."

[8]Reg hack attends holographic WebEx meeting, blows away Zoom fatigue

[9]Facebook's Meta, tracking code, and the student financial aid website

[10]Meta strikes blow against 30% 'App Store tax' by charging 47.5% Metaverse toll

[11]Oracle plans US database for electronic health records

However, the lawsuit alleges: "Through its account managers and representatives, Facebook is aware that it is receiving patient data from hundreds of different medical providers in the United States without patient knowledge, consent, or valid HIPAA authorizations."

The complainant is seeking compensatory and punitive damages for breach of contract, violation of the federal Electronic Communications Privacy Act and a constitutional claim for invasion of privacy, among other allegations.

[12]

Meta has so far declined the opportunity to comment. ®

Get our [13]Tech Resources



[1] https://regmedia.co.uk/2022/06/20/meta_class_action_propsoed_suit.pdf

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrCZp6JQVPa1vQcCYKrFTgAAAAQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrCZp6JQVPa1vQcCYKrFTgAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrCZp6JQVPa1vQcCYKrFTgAAAAQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.facebook.com/business/help/361948878201809?id=188852726110565

[6] https://themarkup.org/pixel-hunt/2022/06/16/facebook-is-receiving-sensitive-medical-information-from-hospital-websites

[7] https://www.theregister.com/2022/04/30/meta_student_data/

[8] https://www.theregister.com/2022/06/01/cisco_webex_hologram_first_look/

[9] https://www.theregister.com/2022/04/30/meta_student_data/

[10] https://www.theregister.com/2022/04/13/meta_app_tax/

[11] https://www.theregister.com/2022/06/10/oracle_us_health_database/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrCZp6JQVPa1vQcCYKrFTgAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



Doctor Syntax

"UK health company EMIS bought by US insurance giant"

Parhaps such transactions should require the informed and specific consent of the data subjects.

Publish Zuck's medical information

alain williams

That would be a fitting punishment.

The USA is not alone

Mike 137

This kind of tracking on medical sites is not new or unique to the USA. It has been [1]widespread in Europe as well.

[1] https://www.cookiebot.com/media/1136/cookiebot-report-2019-ad-tech-surveillance-2.pdf

Such efforts are almost always slow, laborious, political, petty, boring,
ponderous, thankless, and of the utmost criticality.
-- Leonard Kleinrock, on standards efforts