Was the response I got when I explained the issue with Google Analytics in patient portals.
In most cases these same clients never even look at the analytics as the dashboard is too confusing and generating reports too cumbersome.
Most (all?) of which could be developed on their own of course, but that costs more than a one liner to set up Google Analytics.
And again, none of this info was ever actually used. They just felt very strongly that they needed it to better understand their users and improve the experience at some far off future date.
This includes the pages to contact my doctor, view test results or even the feedback link for my complaint.
They played dumb for a while, but finally said "the website is a convenience". They also would not delete my account.
I can't speak to why the consequences weren't more obvious. I don't know. I do know that Epic cares deeply about this and I know that it pisses me off that this happens. But the tech people at hospitals are people and make mistakes. They're likely driven by the business needs and don't have time to fully vet everything.
I think this is a consequence of the American health system and want to implement these products to increase profitability.
Edit: I didn't read far enough into the story. I see that Epic was mentioned by name.
I stand by my assertion that it's on the EHR vendor. Did those hospitals specifically enable the private health data be sent?