Health insurance giant, Blue Shield of California shared the private health data of millions with Google for years (news.blueshieldca.com)
from Tea@programming.dev to technology@lemmy.world on 23 Apr 16:22
https://programming.dev/post/29115507

On February 11, 2025, Blue Shield discovered that, between April 2021 and January 2024, Google Analytics was configured in a way that allowed certain member data to be shared with Google’s advertising product, Google Ads, that likely included protected health information. Google may have used this data to conduct focused ad campaigns back to those individual members.

Blue Shield severed the connection between Google Analytics and Google Ads on its websites in January 2024.

What information was involved

  • Insurance plan name, type and group number;
  • city;
  • zip code;
  • gender;
  • family size;
  • Blue Shield assigned identifiers for members’ online accounts;
  • medical claim service date and service provider, patient name, and patient financial responsibility;
  • “Find a Doctor” search criteria and results (location, plan name and type, provider name and type).

#technology

threaded - newest

jws_shadotak@sh.itjust.works on 23 Apr 16:33 next collapse

That’s a huge HIPAA violation. Can’t wait to see them get a slap on the wrist.

Reverendender@sh.itjust.works on 23 Apr 17:23 next collapse

In theory there would be large fines for every violation, of which there would be millions in this case

sunzu2@thebrainbin.org on 23 Apr 17:50 next collapse

These people kill low quality domestic slaves for sports and profit....

They are above the law and selling your data is a nice revenue stream

What you gonna do about it? Switch your insurance?

jaybone@lemmy.zip on 23 Apr 20:06 collapse

I’ll be holding my breath.

sunzu2@thebrainbin.org on 23 Apr 17:49 next collapse

Call an ambulance!!!

unconfirmedsourcesDOTgov@lemmy.sdf.org on 23 Apr 20:10 collapse

Arguably the only potential PHI is the association between provider names and individuals, but with the current clown show running HHS, I’m not going to hold my breath and wait for accountability here.

jared@mander.xyz on 23 Apr 16:34 next collapse

Fuck google, fuck blue shield!

drool@lemmy.catsp.it on 23 Apr 16:44 next collapse

Infuriating

pelespirit@sh.itjust.works on 23 Apr 16:44 next collapse

I saw an ad for Amazon telehealth a couple of weeks ago. I’m not digging the times we’re in. I also hope we don’t look back on this time with nostalgia.

jaybone@lemmy.zip on 23 Apr 20:07 collapse

After the nuclear winter, we will look back on these times with nostalgia.

lka1988@lemmy.dbzer0.com on 23 Apr 23:23 collapse

“Yes, the planet got destroyed. But for a beautiful moment in time we created a lot of value for shareholders”

sunzu2@thebrainbin.org on 23 Apr 17:49 next collapse

But HIPaA 🤡

Love seeing normies cite some law without understanding how the regime actually operates on practice.

Useful fucking idiots

Tronn4@lemmy.world on 23 Apr 18:34 next collapse

<img alt="" src="https://lemmy.world/pictrs/image/870dba60-4110-4ac6-ab61-ee2ac9734a6f.jpeg">

What are these supposed benefits they speak of? Allowing Google access for what end?

real_squids@sopuli.xyz on 23 Apr 18:36 next collapse

“Better” ads most likely, aka more personalized.

edit:

Google may have used this data to conduct focused ad campaigns back to those individual members.

That’s their exact language

stankmut@lemmy.world on 23 Apr 19:21 collapse

Allowing Google to run an ad campaign targeting their members wasn’t the benefit Blue Cross was talking about, that’s a side effect from them not turning off the data sharing option in the Google analytics settings.

The analytics data is used for prioritizing development work. If a tool they have on the website relies on a library that isn’t compatible with a new version of React, for instance, do they know how many people use it? Having analytics allows you to decide what’s worth spending the development time to maintain.

stankmut@lemmy.world on 23 Apr 19:10 next collapse

The analytics would be for the web development team to see which pages/features are used. Usually a product manager uses that data for setting priorities on what gets worked on.

Tronn4@lemmy.world on 23 Apr 19:21 next collapse

SHUSH! 😄 We trying to burn this whole thing to the ground! Don’t come here with all that sense making talk! 🤣 /s

undefined@lemmy.hogru.ch on 24 Apr 06:29 collapse

But you can do all that without selling out your users to third parties.

ayyy@sh.itjust.works on 24 Apr 00:01 collapse

It’s quite possible to self host this stuff.

undefined@lemmy.hogru.ch on 24 Apr 06:28 collapse

As a web developer that blocks all this shit, that’s the line I always use. I would just use first-party analytics from the same domain the website is hosted from. The added bonus is that people like me wouldn’t even be able to block it without blocking the entire website (at least with DNS).

SharkEatingBreakfast@sopuli.xyz on 23 Apr 21:22 next collapse

Dear Blue Shield members: what improvements in “”“services”“” from Blue Shield have you seen?

Tronn4@lemmy.world on 23 Apr 22:24 collapse

I ain’t seen shit. Premiums continually go up doe

chaospatterns@lemmy.world on 23 Apr 22:22 collapse

Google Analytics gives you insights on what pages people visit, how long they spend, what kind of browsers and devices they use. That can give them data on what pages are important to customers and what screen sizes to support

I’d rather they self host this data vs use Google Analytics, but there are benefits.

NotMyOldRedditName@lemmy.world on 23 Apr 23:43 collapse

It goes further than that. They can track how people interact with the page, order of buttons pressed, if or when they abort a workflow etc. You can go as deep down the rabbit hole of analytics and optimizations as you want.

takeda@lemm.ee on 23 Apr 19:01 next collapse

This is why you always block ads and trackers. It never pays to worry about revenue of “poor sites”

chaospatterns@lemmy.world on 23 Apr 22:24 next collapse

Here’s a good reason why you should run an ad blocker. Block the Google Analytics script from loading entirely.

phoenixz@lemmy.ca on 23 Apr 23:32 next collapse

Jail those involved.

I’m serious, jail them. This is again corpos making millions from us plebs and then they’ll get a fine that is a fraction of what they made and since they don’t pay taxes anyway, it’s still nothing.

Jail them

Find out who was in charge and either that person can show evidence that it was someone else without their knowledge or YOU JAIL THEM. Both at Google and at that torture company blue shield

Jail them! Jail them now. Jail them for years, at least.

undefined@lemmy.hogru.ch on 24 Apr 06:26 collapse

This is why I’m such a cunt about blocking this stuff at the DNS and/or IP level. Google Analytics is essentially everywhere including IRS web pages with your Social Security number in the DOM.