TechCrunch News 04月23日 22:01
Blue Shield of California shared the private health data of millions with Google for years
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

蓝盾加州(Blue Shield of California)向470万用户发出通知,披露了该公司的数据泄露事件。自2021年以来,蓝盾加州一直在与科技巨头谷歌共享患者的私人健康信息。尽管数据共享已于2024年1月停止,但蓝盾加州直到今年2月才得知,多年来的数据收集包含了患者的个人和敏感健康信息。此次泄露涉及搜索词、保险计划名称、个人信息等,甚至包括患者的财务责任信息。蓝盾加州表示,谷歌可能利用这些数据进行定向广告宣传。此事件是2025年迄今为止最大的医疗保健相关数据泄露事件。

🚨 蓝盾加州与谷歌的数据共享始于2021年,涉及患者的个人和敏感健康信息,包括搜索词、保险计划、个人信息等。

🔍 蓝盾加州使用谷歌分析追踪用户网站使用情况,但配置错误导致个人健康信息被收集,并可能被谷歌用于定向广告。

❗ 数据泄露影响了470万用户,涉及会员账户号码、索赔服务日期、服务提供商、患者姓名和财务责任等敏感信息。

⚠️ 蓝盾加州是最新一家因使用在线追踪技术而受影响的医疗保健公司,此前凯撒和多家初创公司也曾发生类似的数据泄露事件。

📊 此事件是2025年迄今为止最大的医疗保健相关数据泄露事件,凸显了医疗数据安全面临的严峻挑战。

Health insurance giant Blue Shield of California is notifying millions of people of a data breach. The company confirmed on Wednesday that it had been sharing patients’ private health information with tech and advertising giant Google since 2021.

The insurer said that the data sharing stopped in January 2024, but it only learned this February that the years-long collection contained patients’ personal and sensitive health information.

Blue Shield said it used Google Analytics to track how its customers used its websites, but a misconfiguration had allowed for personal and health information to be collected as well, such as the search terms that patients used on its website to find healthcare providers.

The insurance giant said Google “may have used this data to conduct focused ad campaigns back to those individual members.” 

Blue Shield said the collected data also included insurance plan names, types and group numbers, along with personal information such as patients’ city, zip code, gender and family size. Details of Blue Shield-assigned member account numbers, claim service dates and service providers, patient names and patients’ financial responsibility were also shared. 

Per a legally required disclosure with the U.S. government’s health department, Blue Shield of California said it is notifying 4.7 million individuals affected by the breach. The breach is thought to affect the majority of its customers; Blue Shield had 4.5 million members as of 2022.

It’s not immediately clear if Blue Shield asked Google to delete the data, or if Google has complied. Spokespeople for Blue Shield and Google did not immediately respond to requests for comment. 

Blue Shield is the latest healthcare company to be caught out by the use of online tracking technologies. Online trackers are small snippets of code, often provided by tech giants, designed to collect information about a customers’ browsing activity by being embedded in mobile apps and websites. Tech and social media companies are usually the sources of these trackers, as they rely on the data for advertising and to drive the majority of their revenues.

Last year, U.S. health insurance giant Kaiser notified more than 13 million people that it had been sharing patients’ data with advertisers including Google, Microsoft and X, after embedding tracking code on its website. 

Several other emerging healthcare companies, including mental health startup Cerebral and alcohol recovery startups Monument and Tempest, have disclosed past breaches involving the sharing of patients’ personal and health information with advertising firms. 

The breach at Blue Shield of California currently stands as the largest healthcare-related data breach of 2025 so far, per the U.S. health department’s Office of Civil Rights.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

蓝盾加州 数据泄露 谷歌 隐私 医疗保健
相关文章