News: 1714155252

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Kaiser Permanente handed over 13.4M people's data to Microsoft, Google, others

(2024/04/26)


Millions of Kaiser Permanente patients' data was likely handed over to Google, Microsoft Bing, X/Twitter, and other third-parties, according to the American healthcare giant.

Kaiser told The Register it has started notifying 13.4 million current and former members and patients that "certain online technologies, previously installed on its websites and mobile applications, may have transmitted personal information to third-party vendors," when customers used its websites and mobile applications.

Kaiser has since removed that tech from its websites and apps, and said it is not aware of "any misuse of any member's or patient's personal information."

[1]

In other words, this seems to be the result of Kaiser placing [2]user tracking and analytics tools, offered by Big Tech and advertising brokers, on its websites and apps, and only realizing now what information exactly was being transmitted by that code when people visited and used those sites and applications.

[3]

[4]

The tech world has come [5]come under fire for allowing this kind of thing to happen – collecting information for advertising and tracking purposes – especially when it involves health-related data and services. A bunch of UK and US government websites were found this week [6]carrying ad-tech that pinged advertising exchanges when visitors dropped by.

Earlier this month, as [7]spotted by TechCrunch, Kaiser Permanente formally disclosed to the US Department of Health and Human Services that it had caused a security snafu.

[8]

Screenshot from the US Department of Health and Human Services security [9]breach portal , showing an entry for the 13.4M Kaiser leak

The information given to third parties includes individuals' "IP address, name, information that could indicate a member or patient was signed into a Kaiser Permanente account or service, information showing how a member or patient interacted with and navigated through the website, and mobile applications, and search terms used in the health encyclopedia," according to Kaiser's statement to us.

Kaiser emphasized no usernames, passwords, Social Security numbers, financial account information, or credit card numbers were shared with the third parties. So while super sensitive information wasn't leaked, having health knowledge base search terms and site usage handed over isn't terribly great.

[10]

"Kaiser Permanente conducted a voluntary internal investigation into the use of these online technologies, and subsequently removed them from the websites and mobile applications," the Oakland, California-based consortium said in its statement. "In addition, Kaiser Permanente has implemented additional measures with the guidance of experts designed to safeguard against recurrence of this type of incident."

[11]96% of US hospital websites share visitor info with Meta, Google, data brokers

[12]Ignore Uncle Sam's 'voluntary' cybersecurity goals for hospitals at your peril

[13]UnitedHealth admits IT security breach could 'cover substantial proportion of people in America'

[14]Ransomware feared as IT 'issues' force Octapharma Plasma to close 150+ centers

The health care and coverage super-group, one of the largest in the US, has 12.5 million members across 10 states with 40 hospitals and 618 medical offices. It employs 24,600 physicians, 73,600 nurses, and 235,000 other employees.

This disclosure comes as research published earlier this month revealed American hospitals [15]regularly use tracking technologies on their websites that pass user information to Google, Meta, data brokers, and other third parties.

Academics at the University of Pennsylvania analyzed a nationally representative sample of 100 non-federal acute care hospitals and found 96 percent of their websites transmitted user data to third parties.

Plus, not all of the websites had a privacy policy. Of the 71 percent that did, 56 percent disclosed specific third-party companies that could receive user information. ®

Get our [16]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ziwj-XKrpsTHOtQWvkPfXAAAAI4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2023/05/16/google_abortion_tracking_suit/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ziwj-XKrpsTHOtQWvkPfXAAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ziwj-XKrpsTHOtQWvkPfXAAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/03/03/ftc_online_counseling_betterhelp/

[6] https://www.theregister.com/2024/04/24/ads_on_gov_uk_websites/

[7] https://techcrunch.com/2024/04/25/kaiser-permanente-health-plan-millions-data-breach/

[8] https://regmedia.co.uk/2024/04/26/screenshot_kaiser_data_leak.png

[9] https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ziwj-XKrpsTHOtQWvkPfXAAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2024/04/11/hospital_website_data_sharing/

[12] https://www.theregister.com/2024/02/05/us_voluntary_cybersecurity_goals_hospitals/

[13] https://www.theregister.com/2024/04/23/unitedhealth_admits_breach_substantial/

[14] https://www.theregister.com/2024/04/18/ransomware_octapharma_plasma/

[15] https://www.theregister.com/2024/04/11/hospital_website_data_sharing/

[16] https://whitepapers.theregister.com/



Having your privacy surgically removed without consent or anesthetic

Anonymous Coward

In other words, this is probably the result of Kaiser placing user tracking and analytics tools, offered by Big Tech and data brokers, on its websites and apps, and only realizing now what information exactly was being transmitted --- I take the lack of "/s" as intentional because the author trusts we're grown up enough not to need it, and not because we need an anesthetic.

Treating the status quo as a data breach

Bendacious

I see this as amazing news. Yes it’s wrong what they allowed onto their website and it should be treated this seriously but I’ve never seen this done before. Firstly they recognise that doing what most other websites do unthinkingly is wrong. Then they say that sharing visitor data with Google is wrong. Wrong enough that it requires a breach announcement to customers. Amazing.

Maybe this will give web developers more ability to push back when marketing insist on Google Analytics on every page. Slowly we can chip away at the current culture that defaults to ten 3rd party scripts on every page, including the page into which you type your credit card number. Reg readers know this happens and can block it but they shouldn’t have to. If this makes one or two CTOs nervous I’ll be happy.

Interesting poll results reported in today's New York Post: people on the
street in midtown Manhattan were asked whether they approved of the US
invasion of Grenada. Fifty-three percent said yes; 39 percent said no;
and 8 percent said "Gimme a quarter?"
-- David Letterman