Meta’s Latest Privacy Scandal Includes Hospitals Sending Patient Data

You can’t see them, but Meta’s trackers are embedded in millions of websites all over the internet, collecting data about where you go and what you do and sending it back to Meta. A recent investigation shows that those trackers are on sites that even the most cynical among us might expect to be off-limits: those belonging to hospitals, including patient portals that are supposed to be protected by health privacy laws.

This week, the Markup, a nonprofit news outlet that covers technology’s harms, has been publishing the latest findings of its investigation into Meta’s Pixels, which are pieces of code developers can embed on websites to track their visitors. So far, those stories reveal how websites owned by the government, pregnancy counseling centers, and hospitals are sending data to Meta through Pixels, much of which would be considered sensitive to the users who unwittingly provided it.

It’s easy and understandable to blame Meta for this, given the company’s much-deserved, less-than-stellar reputation on user privacy. In Pixel and other trackers, Meta has played an instrumental role in building the privacy-free, data-leaking online world we must navigate today. The company supplies a tracking system designed to suck up user data from millions of sites and spin it into advertising gold, and it knows very well that there are many cases where the tool was implemented poorly at best and abused at worst.

But this may also be a rare case of a Meta-related privacy scandal that isn’t entirely Meta’s fault, partly because Meta has done its best to place that blame elsewhere. Or, as security researcher Zach Edwards put it: “Facebook wants to have their data cake and not eat the violations, too.” Businesses choose to put Meta’s trackers on their websites and apps, and they choose again which data about their visitors to send up to the social media giant.

There’s simply no good excuse, in this day and age, for developers that use Meta’s business tools not to understand how they work or what user data is being sent through them. At the very least, developers shouldn’t put them on health appointment scheduling pages or inside patient portals, which users have every reason to expect not to be secretly sending their data to nosy third parties because they’re often explicitly told by those sites that they aren’t. Meta created a monster, but those websites are feeding it.

How Pixel makes tracking too easy

Meta makes Pixel available, free of charge, to businesses to embed in their sites. Pixel collects and sends site visitor data to Meta, and Meta can match this to a user’s profile on Facebook or Instagram, giving it that much more insight into that user. (There are also cases where Meta collects data about people who don’t even have Meta accounts.) Some data, like a visitor’s IP address, is collected by Meta automatically. But developers can also set Pixel up to track what it calls “events”: various actions users take on the site.

That may include links they click on or responses in forms they fill out, and it helps businesses better understand users or focus on specific behaviors or actions. All this data can then be used to target ads at those people, or to create what’s known as “lookalike audiences.” This involves a business asking Meta to send ads to people who Meta believes are similar to its existing customers. The more data Meta gets from businesses through those trackers, the better it should be able to target ads.

Meta may also use that data to improve its own products and services. Businesses may use Pixel data for analytics to improve their products and services as well. Businesses (or the third-party vendors they contract to build out their sites or run advertising campaigns) have a lot of control over what data about their customers Meta gets. The Markup discovered that, on some of the sites in its report, hospital website appointment pages were sending Meta the name of someone making an appointment, the date and time of the appointment, and which doctor the patient is seeing.

If that’s happening, that’s because someone on the hospital’s end set Pixel up to do that. Either the hospital didn’t do its due diligence to protect that data or it didn’t consider it to be data worth protecting. Or perhaps it assumed that Meta’s tools would stop the company from collecting or using any sensitive data that was sent to it. In its most recent hospital investigation, the Markup found that a third of the hospitals it looked at from a list of the top 100 hospitals in the country had a Pixel on appointment scheduling pages, and seven health systems had Pixels in their patient portals. Several of the websites removed Pixel after being contacted by the Markup.

How can a hospital justify any of this? The only hospital that gave the Markup a detailed response, Houston Methodist, claimed that it didn’t believe it was sending protected health information to Meta. The Markup found that the hospital’s site told Meta when someone clicked “schedule appointment,” which doctor they scheduled the appointment for, and even that the doctor was found by searching “home abortion.”

But Houston Methodist said scheduling an appointment didn’t mean the appointment was ever confirmed, nor that the person who scheduled the appointment was the person that appointment was actually for. Houston Methodist might think it isn’t violating patient privacy, but its patients may well feel differently. But they’d also have no way of knowing this was happening in the first place without using special tools or having a certain level of technical knowledge. Houston Methodist has since removed the Pixel.

Another health system the Markup looked at, Novant Health, said in a statement that the Pixel was placed by a third-party vendor for a campaign to get more people to sign up for its patient portal system, and was only used to see how many people signed up. But the Markup found far more data than what was being sent to Meta, including medications that users listed and their sexual orientations. That third-party vendor appears to have made some mistakes here, but Novant’s the one that has a duty to its patients to keep their information private on websites that promise to do so. Not the third-party vendor, and not Meta.

This is not to let Meta off the hook. Again, it created the Pixel tracking system, and while it has rules and tools that are supposed to prevent certain types of sensitive information — like health conditions — from being sent to it, the Markup’s reports are evidence that those measures aren’t enough.

Meta told Recode in a statement that “our system is designed to filter out potentially sensitive data it detects.” But the Markup found those filters lacking when it came to data from at least one crisis pregnancy center’s website. Meta didn’t respond to Recode’s questions about what it does if it finds that a business is violating its rules. Edwards, the security researcher, was even less charitable about how much blame Meta should get here. “It’s 100 percent Facebook’s fault, in my opinion,” he said.

Meta also didn’t respond to questions from Recode asking what it does to ensure businesses are following its policies, or what it does with the sensitive information businesses aren’t supposed to send it. As it stands, it looks as though Meta is making and distributing a tracking tool that can materially benefit Meta. But if that tool is exploited or used incorrectly, someone else is responsible. The only people who pay the price for that, it seems, are the site visitors whose privacy is unknowingly invaded.

What you can do to avoid Pixel

There are a few things you can do to protect yourself here. Browsers like Safari, Firefox, and Brave offer tracker blockers. Todd Feathers, one of the reporters on the Markup’s hospital story, told Recode they used Chrome browsers with no privacy extensions for their tests. Speaking of privacy extensions, you can get those, too. VPNs and Apple’s paid private relay service can obscure your IP address from the sites you visit.

Finally, Meta has controls that limit tracking and ad targeting off of its platforms. The company claims that turning off “data about your activity from partners” or “off-Facebook activity” will stop it from using data collected by Pixel from being used to target ads to you. This means placing some trust in Meta that its privacy tools do what it claims they do.

And there’s always, of course, asking your lawmaker to push for privacy laws that would make some of these practices explicitly illegal, or forcing companies to inform and get user consent before collecting and sending their data to anyone else. A few new federal privacy bills or draft bills have been introduced as recently as this week. The interest is there among some members of Congress, but not in enough of them to come close to passing anything yet.

Source: Meta’s latest privacy scandal includes hospitals sending patient data – Vox

More contents:

Mozilla slams a big Safari privacy feature, calling it ‘a poor trade-off’

Didi makes privacy fixes to ousted apps in run-up to restoring them – SCMP

14:40 Wed, 15 JunFirefox Browsers Internet
20:19 Thu, 16 JunFacebook Meta Internet
16:39 Sat, 18 JunData Protection
14:07 Fri, 10 Jun

More Remote Working Apps:

https://quintexcapital.com/?ref=arminham     Quintex Capital

https://www.genesis-mining.com/a/2535466   Genesis Mining

 http://www.bevtraders.com/?ref=arminham   BevTraders

https://www.litefinance.com/?uid=929237543  LiteTrading

https://jvz8.com/c/202927/369164  prime stocks

  https://jvz3.com/c/202927/361015  content gorilla

  https://jvz8.com/c/202927/366443  stock rush  

 https://jvz1.com/c/202927/373449  forrk   

https://jvz3.com/c/202927/194909  keysearch  

 https://jvz4.com/c/202927/296191  gluten free   

https://jvz1.com/c/202927/286851  diet fitness diabetes  

https://jvz8.com/c/202927/213027  writing job  

 https://jvz6.com/c/202927/108695  postradamus

https://jvz1.com/c/202927/372094  stoodaio

 https://jvz4.com/c/202927/358049  profile mate  

 https://jvz6.com/c/202927/279944  senuke  

 https://jvz8.com/c/202927/54245   asin   

https://jvz8.com/c/202927/370227  appimize

 https://jvz8.com/c/202927/376524  super backdrop

 https://jvz6.com/c/202927/302715  audiencetoolkit

 https://jvz1.com/c/202927/375487  4brandcommercial

https://jvz2.com/c/202927/375358  talkingfaces

 https://jvz6.com/c/202927/375706  socifeed

 https://jvz2.com/c/202927/184902  gaming jobs

 https://jvz6.com/c/202927/88118   backlinkindexer

 https://jvz1.com/c/202927/376361  powrsuite  

https://jvz3.com/c/202927/370472  tubeserp  

https://jvz4.com/c/202927/343405  PR Rage  

https://jvz6.com/c/202927/371547  design beast  

https://jvz3.com/c/202927/376879  commission smasher

 https://jvz2.com/c/202927/376925  MT4Code System

https://jvz6.com/c/202927/375959  viral dash

https://jvz1.com/c/202927/376527  coursova

 https://jvz4.com/c/202927/144349  fanpage

https://jvz1.com/c/202927/376877  forex expert  

https://jvz6.com/c/202927/374258  appointomatic

https://jvz2.com/c/202927/377003  woocommerce

https://jvz6.com/c/202927/377005  domainname

 https://jvz8.com/c/202927/376842  maxslides

https://jvz8.com/c/202927/376381  ada leadz

https://jvz2.com/c/202927/333637  eyeslick

https://jvz1.com/c/202927/376986  creaitecontentcreator

https://jvz4.com/c/202927/376095  vidcentric

https://jvz1.com/c/202927/374965  studioninja

https://jvz6.com/c/202927/374934  marketingblocks

https://jvz3.com/c/202927/372682  clipsreel  

https://jvz2.com/c/202927/372916  VideoEnginePro

https://jvz1.com/c/202927/144577  BarclaysForexExpert

https://jvz8.com/c/202927/370806  Clientfinda

https://jvz3.com/c/202927/375550  Talkingfaces

https://jvz1.com/c/202927/370769  IMSyndicator

https://jvz6.com/c/202927/283867  SqribbleEbook

https://jvz8.com/c/202927/376524  superbackdrop

https://jvz8.com/c/202927/376849  VirtualReel

https://jvz2.com/c/202927/369837  MarketPresso

https://jvz1.com/c/202927/342854  voiceBuddy

https://jvz6.com/c/202927/377211  tubeTargeter

https://jvz6.com/c/202927/377557  InstantWebsiteBundle

https://jvz6.com/c/202927/368736  soronity

https://jvz2.com/c/202927/337292  DFY Suite 3.0 Agency+ information

https://jvz8.com/c/202927/291061  VideoRobot Enterprise

https://jvz8.com/c/202927/327447  Klippyo Kreators

https://jvz8.com/c/202927/324615  ChatterPal Commercial

https://jvz8.com/c/202927/299907  WP GDPR Fix Elite Unltd Sites

https://jvz8.com/c/202927/328172  EngagerMate

https://jvz3.com/c/202927/342585  VidSnatcher Commercial

https://jvz3.com/c/202927/292919  myMailIt

https://jvz3.com/c/202927/320972  Storymate Luxury Edition

https://jvz2.com/c/202927/320466  iTraffic X – Platinum Edition

https://jvz2.com/c/202927/330783  Content Gorilla One-time

https://jvz2.com/c/202927/301402  Push Button Traffic 3.0 – Brand New

https://jvz2.com/c/202927/321987  SociCake Commercial https://jvz2.com/c/202927/289944  The Internet Marketing

 https://jvz2.com/c/202927/297271  Designa Suite License

https://jvz2.com/c/202927/310335  XFUNNELS FE Commercial 

https://jvz2.com/c/202927/291955  ShopABot

https://jvz2.com/c/202927/312692  Inboxr

https://jvz2.com/c/202927/343635  MediaCloudPro 2.0 – Agency

 https://jvz2.com/c/202927/353558  MyTrafficJacker 2.0 Pro+

https://jvz2.com/c/202927/365061  AIWA Commercial

https://jvz2.com/c/202927/357201  Toon Video Maker Premium

https://jvz2.com/c/202927/351754  Steven Alvey’s Signature Series

https://jvz2.com/c/202927/344541  Fade To Black

https://jvz2.com/c/202927/290487  Adsense Machine

https://jvz2.com/c/202927/315596  Diddly Pay’s DLCM DFY Club

https://jvz2.com/c/202927/355249  CourseReel Professional

https://jvz2.com/c/202927/309649  SociJam System

https://jvz2.com/c/202927/263380  360Apps Certification

 https://jvz2.com/c/202927/359468  LocalAgencyBox

https://jvz2.com/c/202927/377557  Instant Website Bundle

https://jvz2.com/c/202927/377194  GMB Magic Content

https://jvz2.com/c/202927/376962  PlayerNeos VR

https://jvz8.com/c/202927/381812/  BrandElevate Bundle information

https://jvz4.com/c/202927/381807/ BrandElevate Ultimate

https://jvz2.com/c/202927/381556/ WowBackgraounds Plus

https://jvz4.com/c/202927/381689/  Your3DPal Ultimate

https://jvz2.com/c/202927/380877/  BigAudio Club Fast Pass

https://jvz3.com/c/202927/379998/ Podcast Masterclass

https://jvz3.com/c/202927/366537/  VideoGameSuite Exclusive

https://jvz8.com/c/202927/381148/ AffiliateMatic

https://jvzoo.com/c/202927/381179  YTSuite Advanced

https://jvz1.com/c/202927/381749/  Xinemax 2.0 Commercial

https://jvzoo.com/c/202927/382455  Living An Intentional Life

https://jvzoo.com/c/202927/381812  BrandElevate Bundle

https://jvzoo.com/c/202927/381935 Ezy MultiStores

https://jvz2.com/c/202927/381194/  DFY Suite 4.0 Agency

https://jvzoo.com/c/202927/381761  ReVideo

https://jvz4.com/c/202927/381976/  AppOwls Bundle

https://jvz8.com/c/202927/381950/  TrafficForU

https://jvz3.com/c/202927/381615/  WOW Backgrounds 2.0

https://jvz4.com/c/202927/381560   ALL-in-One HD Stock Bundle

https://jvz6.com/c/202927/382326/   Viddeyo Bundle

https://jvz8.com/c/202927/381617/  The Forex Joustar

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: