“On February 11, 2025, Blue Shield discovered that, between April 2021 and January 2024, Google Analytics was configured in a way that allowed certain member data to be shared with Google’s advertising product, Google Ads, that likely included protected health information,” the company stated in its notification. The company discovered the privacy violation on February 11, 2025, when an internal review identified that Google Analytics had been improperly configured to share sensitive member data with Google Ads, potentially enabling targeted advertising campaigns directed at affected individuals. The health insurance provider revealed that protected health information (PHI) was inadvertently shared with Google’s advertising platforms over a nearly three-year period due to a misconfiguration of Google Analytics on the company’s websites. “Many healthcare companies are caught unaware of potential data privacy problems because they either don’t fully know what their analytics tools are collecting, or they don’t know how to set up Google Analytics correctly,” noted Ian Cohen, CEO of Lokker.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 24 Apr 2025 07:40:11 +0000