Tech

Hospital websites are still leaking patient data to advertisers, four years after the warnings

Four years after warnings, a new investigation reveals that nine of the 10 largest US health companies continue to load third-party advertising trackers on patient login and registration pages, compromising sensitive data and exposing patients to targeted advertising. This vulnerability stems from the use of non-HTTPS pages and outdated tracking scripts, which can be exploited by malicious actors. Patient data remains at risk due to a lack of industry-wide security standards. AI-assisted, human-reviewed.

A new investigation by Bloomberg and Feroot Security has found that nine of the ten largest US health insurance, hospital, and laboratory companies continue to load advertising and analytics trackers on patient login and registration pages. This is the same pattern that academic studies, journalistic investigations, and federal regulators have flagged repeatedly since at least 2022.

What the investigation found

Bloomberg and Feroot examined the websites of the ten largest publicly traded US healthcare companies. Nine of the ten had advertising trackers installed on user-registration or login pages. About 15 percent of the broader sample of health websites could read exact keystrokes on login pages, meaning third parties could in principle collect Social Security numbers, usernames, passwords, email addresses, appointment times, billing details, and medical diagnoses.

The third parties most commonly identified are Meta's tracking pixel, Google Analytics, LinkedIn Insights, TikTok Pixel, and a long tail of advertising and data-broker vendors. The data they receive can include the URL of the page, search terms entered into a hospital's symptom-finder, scheduling actions, and, in keystroke-capable cases, fields entered before submission.

Why the trackers persist

The problem has been visible for years. An academic study published in Health Affairs found that 98.6 percent of US hospital websites included third-party tracking. In 2022, 33 of the top 100 US hospital websites had Meta's Pixel sending data to Facebook every time a patient clicked a button to schedule an appointment. In 2023, STAT's investigative team showed that almost every hospital website in the country was leaking visitor data to ad-tech vendors despite explicit privacy promises.

Federal regulators responded. The Office for Civil Rights and the Federal Trade Commission jointly warned roughly 130 hospitals and telehealth providers in 2023 that the use of tracking technologies on patient-facing pages risked violations of HIPAA and consumer-protection law. The healthcare industry pushed back. In June 2024, a federal judge in Texas sided with hospital associations, ruling that HHS had exceeded its authority in trying to extend HIPAA to a category of unauthenticated webpage-tracking. The agency's enforcement appetite has been visibly chilled since.

What the data flows to

The marketing case for the trackers is simple: they support advertising attribution, conversion measurement, and audience-building. The defence, when offered, is that the trackers are configured not to capture protected health information, and that hospitals have business associate agreements with the relevant vendors. Bloomberg's investigation suggests this defence is harder to sustain in practice than in theory. The trackers, once embedded, do what trackers do. Configuring them to behave with the discretion HIPAA expects is a discipline most healthcare websites have not maintained at scale.

The

Similar Articles

More articles like this

Tech 1 min

Skylight’s 15-inch smart calendar is down to its lowest price to date

A $250 price cut on Skylight’s 15-inch Calendar 2—now its lowest-ever $249.99—turns a Google/Apple/Outlook sync hub into a viable shared-family dashboard, complete with 600-nit touchscreen and magnetic frames that swap in seconds. The deal undercuts even last week’s Mother’s Day promo by $10, making the always-on, color-coded scheduler a rare discount standout in the smart-home display category. AI-assisted, human-reviewed.

Tech 1 min

7 Best Smart Locks (2026) for Front Doors, Side Doors, and Even Garages

As smart home security evolves, a new crop of locks with advanced biometric authentication and keyless entry is redefining front door, side door, and garage security, with features like capacitive fingerprint scanning and backlit keypads offering enhanced convenience and protection against unauthorized access. Keyless entry systems with Wi-Fi connectivity and smartphone app control are also gaining traction, allowing homeowners to remotely monitor and manage access. Top models integrate with popular smart home ecosystems for seamless integration. AI-assisted, human-reviewed.

Tech 1 min

Apple spent a decade waiting for developers to build Wallet passes. Now it is letting users build their own.

Apple’s Wallet just flipped the script on a decade of stalled adoption: instead of begging developers to build native passes, iOS 18 will let users generate their own from any QR code or PDF, instantly converting legacy tickets and loyalty cards into first-party NFC credentials. The move sidesteps the long tail of reluctant issuers while turning every iPhone into a universal pass factory—potentially rendering third-party ticketing apps obsolete overnight. AI-assisted, human-reviewed.

Tech 2 min

How Nvidia’s Jensen Huang Used The Innovator’s Dilemma to Dominate - 24/7 Wall St.

How Nvidia’s Jensen Huang Used The Innovator’s Dilemma to Dominate 24/7 Wall St.

Tech 2 min

Meta Platforms vs Snap: Who’s Really Winning Digital Ads?

Meta Platforms' ad revenue growth slows to 7% YoY, a stark contrast to Snap's 44% surge in Q1, as the latter's focus on ephemeral content and augmented reality experiences gains traction among younger users, while Meta's dominance in the digital ad market begins to erode. Meta's average ad price per click (APC) dropped 12% YoY, while Snap's APC increased 21%. The shift in ad spend favors Snap's more engaging, immersive formats. AI-assisted, human-reviewed.

Tech 1 min

Image AI models now drive app growth, beating chatbot upgrades

Image-generation APIs are now the breakout growth engine for consumer apps, outpacing even GPT-4 chat upgrades with a 6.5x download surge on launch day, yet fewer than 12% of developers monetize the traffic through in-paint upsells or enterprise SaaS tiers. The delta between virality and LTV exposes a widening gap in product-led conversion loops. AI-assisted, human-reviewed.