Just in the last week, Onsite Mammography, Kelly & Associates Insurance Group, Behavioral Health Resources, Hamilton Health Care System, Central Texas Pediatric Orthopedics and Medical Express Ambulance Service have all reported data breaches resulting from cyberattacks. The sensitive healthcare information of millions in the U.S. has been leaked through data breaches that multiple insurance companies, clinics, hospitals and more reported over the last week. The information shared with Google includes insurance plan name; group number; zip code; gender; family information; online account numbers; medical claim service dates; names; “Find a Doctor” search criteria and results; and more. In breach notification letters and in a notice on its website, the insurer said that from April 2021 to January 2024, it used Google Analytics to internally track website usage of members who entered certain Blue Shield sites. But last year, the federal government backed off new regulations it had issued to limit hospitals’ deployment of web-tracking tools after a federal court ruled that the Biden administration’s efforts to restrict the use of online trackers by hospitals and other health providers were illegal. The attack on Onsite Mammography, announced on Monday, impacted 357,265 people and included names, Social Security numbers, medical records and other health information. Companies like Kaiser, BetterHelp, GoodRx, Premom and Flurry have faced massive penalties for either harvesting sensitive healthcare data or sharing it with third-party vendors like Google. Other healthcare organizations have flooded state regulators with notices of data leaks exposing hundreds of thousands of individuals’ information. The Federal Trade Commission (FTC) and HHS previously sent a joint letter to about 130 hospital systems and telehealth providers warning of security risks posed by tracking technologies such as the Meta/Facebook Pixel and Google Analytics. We want to reassure our members that no bad actor was involved, and, to our knowledge, Google has not used the information for any purpose other than these ads or shared the protected information with anyone,” the company said.
This Cyber News was published on therecord.media. Publication date: Wed, 23 Apr 2025 18:40:25 +0000