Novant Health admits leak of 1.3m patients' info to Facebook
(2022/08/23)
- Reference: 1661205612
- News link: https://www.theregister.co.uk/2022/08/22/novant_meta_data/
- Source link:
Novant Health confirmed that it may have disclosed 1.3 million patients' sensitive data, including email addresses, phone numbers, financial information - even doctor's appointment details - to Meta.
This admission by the health-care network, which spans 800 hospitals and clinics across North Carolina, South Carolina and Georgia, follows a class action lawsuit against Meta that claims Facebook illegally received patient data from at least 664 hospital systems or medical providers.
Novant finally copped to sending letters to "some of its patients following possible disclosure of protected health information (PHI) resulting from an incorrect configuration of a pixel, an online tracking tool," in a [1]statement released late on Friday. A spokesperson later confirmed to The Register that 1.3 million patients received these letters.
[2]
According to the healthcare firm, leaked data also potentially included computer IP addresses, emergency contact information, advanced care planning contacts, appointment types and dates, patients' physicians, and various information types into text boxes or selected from drop-down menus and buttons via its patient portal.
[3]
[4]
"The information did not include Social Security numbers or other financial information unless it was typed into a free text box by the user," the statement said. "The letter sent to each patient will specifically state whether such financial information may have been involved."
Novant added that it's not aware of any "improper use or attempted use" of patient info by Meta or any other third party.
[5]
However, considering that Meta, after being served with a subpoena, [6]handed over Facebook chats between a Nebraska mother and her daughter that were later used to build a criminal case against the teen for getting a now-illegal abortion in her home state, "improper use" sounds very subjective.
Following the breach, the healthcare giant added better "structure, governance and policies around the use of pixels and is taking actions to ensure this does not happen again."
Here's what did happen, according to Novant.
[7]
Back in May 2020, the healthcare corporation launched a promotional campaign to get more patients to sign up for its patient portal, ostensibly to make it easier for patients to receive care virtually at a time when in-person doctors' visits were extremely limited by the COVID-19 pandemic.
This campaign involved Facebook advertisements and a tracking pixel — this is a piece of code used to track users activity on a particular website for marketing and analytics purposes — on the Novant Health website. The pixel was supposed to track the Facebook ad campaign's success. But this didn't quite go as planned.
"In this case, the pixel was configured incorrectly and may have allowed certain private information to be transmitted to Meta from the Novant Health website and MyChart portal," Novant admitted.
[8]US lawsuit alleges tool used by hospitals shares patient data with Meta
[9]Facebook hands over chats to cops in post-Roe abortion case
[10]1.9m patient records exposed in healthcare debt collector ransomware attack
[11]Googlers demand abortion searches 'never be saved or treated as a crime'
Once Novant realized the pixel had been sending patient information to Meta, the health-care company said it "immediately" disabled and removed the code, and then launched an investigation into what information had been shared with the social media giant.
"Based on that investigation, Novant Health determined on June 17, 2022, that it was possible sensitive information or PHI might have been disclosed to Meta, depending upon a user's activity within the Novant Health website and MyChart portal."
Shortly after, an anonymous hospital patient [12]filed a class-action lawsuit against Meta, alleging Facebook received patient data from at least 664 hospital systems or medical providers in violation of the Health Insurance Portability and Accountability Act.
"Facebook monetizes the information it receives through the Facebook Pixel deployed on medical providers' web properties by using it to generate highly-profitable targeted advertising on and off Facebook," the lawsuit claims
According to Meta's Terms and Conditions around [14]sensitive health-care data , its policies and filters block personal data and do not use it in their ad manager software.
It says: "If Facebook's signals filtering mechanism detects Business Tools data that it categorizes as potentially sensitive health-related data, the filtering mechanism is designed to prevent that data from being ingested into our ads ranking and optimization systems." ®
Get our [15]Tech Resources
[1] https://www.prnewswire.com/news-releases/novant-health-notifies-patients-of-potential-data-privacy-incident-301609387.html
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YwRQ3We5kEkuz8Hsq19pmwAAABQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YwRQ3We5kEkuz8Hsq19pmwAAABQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YwRQ3We5kEkuz8Hsq19pmwAAABQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YwRQ3We5kEkuz8Hsq19pmwAAABQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2022/08/10/meta_abortion_charges/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YwRQ3We5kEkuz8Hsq19pmwAAABQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/06/20/us_lawsuit_alleges_meta_tool/
[9] https://www.theregister.com/2022/08/10/meta_abortion_charges/
[10] https://www.theregister.com/2022/07/13/19m_patients_medical_data_exposed/
[11] https://www.theregister.com/2022/08/18/google_abortion_data/
[12] https://www.theregister.com/2022/06/20/us_lawsuit_alleges_meta_tool/
[13] https://regmedia.co.uk/2022/06/20/meta_class_action_propsoed_suit.pdf
[14] https://www.facebook.com/business/help/361948878201809?id=188852726110565
[15] https://whitepapers.theregister.com/
This admission by the health-care network, which spans 800 hospitals and clinics across North Carolina, South Carolina and Georgia, follows a class action lawsuit against Meta that claims Facebook illegally received patient data from at least 664 hospital systems or medical providers.
Novant finally copped to sending letters to "some of its patients following possible disclosure of protected health information (PHI) resulting from an incorrect configuration of a pixel, an online tracking tool," in a [1]statement released late on Friday. A spokesperson later confirmed to The Register that 1.3 million patients received these letters.
[2]
According to the healthcare firm, leaked data also potentially included computer IP addresses, emergency contact information, advanced care planning contacts, appointment types and dates, patients' physicians, and various information types into text boxes or selected from drop-down menus and buttons via its patient portal.
[3]
[4]
"The information did not include Social Security numbers or other financial information unless it was typed into a free text box by the user," the statement said. "The letter sent to each patient will specifically state whether such financial information may have been involved."
Novant added that it's not aware of any "improper use or attempted use" of patient info by Meta or any other third party.
[5]
However, considering that Meta, after being served with a subpoena, [6]handed over Facebook chats between a Nebraska mother and her daughter that were later used to build a criminal case against the teen for getting a now-illegal abortion in her home state, "improper use" sounds very subjective.
Following the breach, the healthcare giant added better "structure, governance and policies around the use of pixels and is taking actions to ensure this does not happen again."
Here's what did happen, according to Novant.
[7]
Back in May 2020, the healthcare corporation launched a promotional campaign to get more patients to sign up for its patient portal, ostensibly to make it easier for patients to receive care virtually at a time when in-person doctors' visits were extremely limited by the COVID-19 pandemic.
This campaign involved Facebook advertisements and a tracking pixel — this is a piece of code used to track users activity on a particular website for marketing and analytics purposes — on the Novant Health website. The pixel was supposed to track the Facebook ad campaign's success. But this didn't quite go as planned.
"In this case, the pixel was configured incorrectly and may have allowed certain private information to be transmitted to Meta from the Novant Health website and MyChart portal," Novant admitted.
[8]US lawsuit alleges tool used by hospitals shares patient data with Meta
[9]Facebook hands over chats to cops in post-Roe abortion case
[10]1.9m patient records exposed in healthcare debt collector ransomware attack
[11]Googlers demand abortion searches 'never be saved or treated as a crime'
Once Novant realized the pixel had been sending patient information to Meta, the health-care company said it "immediately" disabled and removed the code, and then launched an investigation into what information had been shared with the social media giant.
"Based on that investigation, Novant Health determined on June 17, 2022, that it was possible sensitive information or PHI might have been disclosed to Meta, depending upon a user's activity within the Novant Health website and MyChart portal."
Shortly after, an anonymous hospital patient [12]filed a class-action lawsuit against Meta, alleging Facebook received patient data from at least 664 hospital systems or medical providers in violation of the Health Insurance Portability and Accountability Act.
"Facebook monetizes the information it receives through the Facebook Pixel deployed on medical providers' web properties by using it to generate highly-profitable targeted advertising on and off Facebook," the lawsuit claims
[13]PDF
.According to Meta's Terms and Conditions around [14]sensitive health-care data , its policies and filters block personal data and do not use it in their ad manager software.
It says: "If Facebook's signals filtering mechanism detects Business Tools data that it categorizes as potentially sensitive health-related data, the filtering mechanism is designed to prevent that data from being ingested into our ads ranking and optimization systems." ®
Get our [15]Tech Resources
[1] https://www.prnewswire.com/news-releases/novant-health-notifies-patients-of-potential-data-privacy-incident-301609387.html
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YwRQ3We5kEkuz8Hsq19pmwAAABQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YwRQ3We5kEkuz8Hsq19pmwAAABQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YwRQ3We5kEkuz8Hsq19pmwAAABQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YwRQ3We5kEkuz8Hsq19pmwAAABQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2022/08/10/meta_abortion_charges/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YwRQ3We5kEkuz8Hsq19pmwAAABQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/06/20/us_lawsuit_alleges_meta_tool/
[9] https://www.theregister.com/2022/08/10/meta_abortion_charges/
[10] https://www.theregister.com/2022/07/13/19m_patients_medical_data_exposed/
[11] https://www.theregister.com/2022/08/18/google_abortion_data/
[12] https://www.theregister.com/2022/06/20/us_lawsuit_alleges_meta_tool/
[13] https://regmedia.co.uk/2022/06/20/meta_class_action_propsoed_suit.pdf
[14] https://www.facebook.com/business/help/361948878201809?id=188852726110565
[15] https://whitepapers.theregister.com/
The Fiction of a Private EHR (Electronic Health Record)
Auntie Dix
Repeated stories like this highlight the scum who are in control of our private information and the lack of strict regulation and severe punishment for abuses.
EHR? Go F yourselves.
Let me get this straight
"This admission by the health-care network, which spans 800 hospitals and clinics across North Carolina, South Carolina and Georgia, follows a class action lawsuit against Meta that claims Facebook illegally received patient data from at least 664 hospital systems or medical providers."
So Novant Health, not content with the money they were making from their hospital systems and medical providers, sold a pixel tracker to Meta.
They misconfigured it and the tracker dumped everything to Meta instead of just almost everything.
When they realized it they tried to sweep it under the rug until a lawsuit was brought.
Meanwhile, Meta is shocked, SHOCKED, that its filters didn't catch this.
And Meta makes no mention of trying to remove the data from its databases which are already putting the victims into ad categories for their customers (or police).