96% of US hospital websites share visitor info with Meta, Google, data brokers
theregister.com
theregister.com
It may have been 2 years ago or so, but the process stopped working and wouldn't accept my confirmation after giving my credit card info. I've got a handful of privacy tools on my browser. I finally gave in and temporarily white listed the pharmacy and still cleared out any trackers. Sent the web admin a basic, "WTF, folks?" and got a BS non answer.
Fast forward to maybe November or December last year. Refill time, and the trackers were even worse. I kind of need my meds though. So I created a new account on my computer, and ordered my meds.
Then I filed a complaint of a possible HIPAA violation, starting at https://www.hhs.gov/hipaa/filing-a-complaint/index.html and was polite, factual, and provided some non hysterical examples of how a prescription could indicate a specific health issue with resulting advertising or PII release to parties not needing it.
I received an email at the end of February. I was probably not the only person that sent a complaint, but the end result is that KP is being investigated.
Yay.
This was years ago, but I complained that kaiser had trackers throughout its website for doubleclick and googletagmanager. (nowadays they don't use those domains and go directly to google.com, I assume because people don't block that)
I complained.
To be clear, the tracking links traverse the entire website - communication with your doctor, test results, prescriptions, even the complaint form I filed out.
I got the same sort of non-answers. I pushed and pushed and finally, I did get an answer - "the website is a convenience".
I blocked the trackers, and pretty soon to continue to use the website, I had to agree to the privacy policy.
I didn't agree. I stopped using the website.
But they wouldn't let me delete my account. (I think california law allows you to ask.) I called multiple times. I still have an account and get emails from them.
I do wonder whether it's possible to inject harmless stubs for these trackers so you don't have to deal with the bureaucracy of filing a complaint though. Then again, stubbing helps a few techy people, filing a formal complaint helps everyone.
Given the government is actually enforcing the law for once, this is one of the few times I've seen people take regulation like this seriously.
[0] https://themarkup.org/pixel-hunt/2022/06/16/facebook-is-rece...
[1] https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...
[2] https://www.ftc.gov/news-events/news/press-releases/2023/07/...
[3] https://www.ftc.gov/news-events/news/press-releases/2023/02/...
[4] https://finance.yahoo.com/news/costco-sued-accused-sharing-c...
(Frankly, the script should not be present at all on the sensitive origin. Ever heard of fetch or service workers or any other same-origin mechanism of collecting data?)
Yes, people do bad decisions all the time. Hospitals are not perfect and mistakes happens. They should however not continue doing mistakes that harms patients.
Tracking website visitors is bad, but is something I 100% expect. If others aren't expecting this, that's a serious problem. People should absolutely be warned when it happens (or, better, laws should exist to prevent it from happening).
But web visitor tracking is not nearly as sensitive as tracking visitors to the hospitals (or any other health care provider premises) themselves.
I avoid the data leakage for sensitive things like health care by never using websites related to those things. I know that people often forget this, but at least in the US, using a website to interact with health care providers is not actually mandatory.
It is not mandatory but is made extremely onerous. I can get on the web site, authenticate while tracked, enter my request, or I can call an automated maze, get repeatedly dropped, talked to a ChatGPT knock-off, get dropped again, and maybe I get a human to answer my request. Then, I get an email asking if I am satisified with the service.
I need to stop complaining about my hospital. Apparently, this is one area where they're above the grade. But even if my phone experience was like yours, I'd still use the phone instead of the web site due to privacy concerns.
In the end, as with all privacy/security issues, there's an inherent tradeoff between convenience and security. Everyone has a different place on that spectrum where they're most comfortable. But at least we can choose how much of a tradeoff we're willing to engage in.
The tracking is continued post authentication, making the identity to PHI significantly stronger.
Legislation is in order to define what analytics companies cannot do with data from healthcare sites.
I’m not sure if there are other categories which ought to be protected, but healthcare is certainly one.
[EDIT: my karma is now 667. Would someone please remove their upvote just for a bit? A screenshot of "devilbunny (666)" from HN would be a great little digital memento.]
[karma whirring up and down could power a small city]
America is capitalist and federalist. That means either hospitals are for profit entities, non-profit entities or government owned entities.
Ducks quack, for profit entities attempt to grow profits, non-profit entities attempt to grow donors and government entities attempt to keep the things way they were yesterday.
As a society, we can pick which models we allow and in which allocation, but we can't ask a duck to be a swan - each option has positives and negatives.
When we ask for the positives without the negatives, then complain when the inevitable negatives come, is the fault with the model or with our expectations?
The better way is to iterate and grapple with the rewards in the system and where transparency should be forced or legislated. Change the incentives and you'll change the behavior. Unfortunately, you will also encounter new and unexpected negative effects...see: ducks quack.
While the TFA might be about hospitals specifically, your suggestion that we need regulation should not be focused on just healthcare/HIPPA type situations. These data hoarders need to be reigned in if not just eliminated.
https://jamanetwork.com/journals/jamanetworkopen/fullarticle...
And at a quick glance it looks like it is mostly related to website information, not PHI or PII.
If you are looking for an oncologist or abortions or whatever else, that's PHI. We know well that the industry has profiles on Americans and probably can identify you.
From[0]:
> if an individual were looking at a hospital’s webpage listing its oncology services to seek a second opinion on treatment options for their brain tumor, the collection and transmission of the individual’s IP address, geographic location, or other identifying information showing their visit to that webpage is a disclosure of PHI to the extent that the information is both identifiable and related to the individual’s health or future health care
[0] https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...
https://sharps.org/ https://thaw.org/
One research group analyzed how patient data is shared inside medical systems and found that in some cases as many 300 different entities had access to your data. The billing companies, consultants, out of network clinicians, staff, testing companies, supply companies, IT management companies, outside expert consultations, insurance companies, medical device companies, data analysis companies, and many more. In some cases it was unclear if the data was further shared with subcontractors and other third parties.
It's how building a profile works. No one tells Google or Facebook "Zack likes Ferrari", but Zack's browsing of Ferrari articles tells that about him.
> Regulated entities may also have unauthenticated webpages, which are webpages that do not require users to log in before they are able to access the webpage, such as a webpage with general information about the regulated entity like their location, visiting hours, employment opportunities, or their policies and procedures. Tracking technologies on many unauthenticated webpages do not have access to individuals’ PHI; in this case, a regulated entity’s use of such tracking technologies is not regulated by the HIPAA Rules. However, in some cases, tracking technologies on unauthenticated webpages may have access to PHI, in which case the HIPAA Rules apply to the regulated entities’ use of tracking technologies and disclosures to the tracking technology vendors. Regulated entities are required to “[e]nsure the confidentiality, integrity, and availability of all electronic PHI the [regulated entity] creates, receives, maintains, or transmits.” Thus, regulated entities that are considering the use of online tracking technologies should consider whether any PHI will be transmitted to a tracking technology vendor, and take appropriate steps consistent with the HIPAA Rules.
Thankfully I’m working with a conscientious marketing firm and our client is diligent and well meaning, so it’s easy to avoid the pitfalls, but naively following many integration walkthroughs could have you sending entire form content to Google (or others). I’m sure that’s one of the reason Google explicitly says “don’t put us on your EMR pages” (paraphrased).
Just using the same massive aggregator as your metrics provider is where it gets wrong.
Most people aren’t going to be browsing the Betty Ford clinic for fun. They’re looking for something specific. That’s juicy for analytics. I’m glad I don’t have to deal with that challenge.
(Conversion matching quality isn’t a fun challenge either. We’ve landed at “the practice will have to do that themselves to avoid the privacy obstacles”.)
Not to far from being a cigarette salesmen at Philip Morris in 1980 these days, just like when the data was coming out on how toxic the product was, PM was hiring scientists to put out competing public studies and threatening funding of university research that countered them (Meta is doing this currently…), on and on.
Keep working there and ignore the growing research and civil impact like this article? Or..