For years, I have filed a HIPPA complaint with the privacy office of every website I go to that has a Google Analytics tag that serves my protected health information, like my doctor, MyChart, labs, pharmacies, home health, case management etc. I get brushed off. It just makes me uncomfortable.
'Read the Manual': Misconfigured Google Analytics Led to a Data Breach Affecting 4.7M
Personal health information on 4.7 million Blue Shield California subscribers was unintentionally shared between Google #Analytics and Google #Ads between April 2021 and January 2025 due to a misconfiguration error.
#hippa #Privacy #GoogleAds #Google #MedMastodon
https://it.slashdot.org/story/25/04/26/2042230/read-the-manual-misconfigured-google-analytics-led-to-a-data-breach-affecting-47m
BCBS NOTICE OF DATA BREACH: https://news.blueshieldca.com/notice-of-data-breach
"On February 11, 2025, Blue Shield discovered that, between April 2021 and January 2024, Google Analytics was configured in a way that allowed certain member data to be shared with Google’s advertising product, Google Ads, that likely included protected health information. Google may have used this data to conduct focused ad campaigns back to those individual members. We want to reassure our members that no bad actor was involved, and, to our knowledge, Google has not used the information for any purpose other than these ads or shared the protected information with anyone."