Data leak

Kaiser Permanente web tracking pixel data disclosure (13.4 million)

πŸ“… 2024-01-01 🏒 Kaiser Permanente member portal and apps
Primary Source β†—

Incident Details

Kaiser Permanente disclosed that tracking technologies (pixels) embedded in its website and mobile apps transmitted member health information to third-party tech companies (Microsoft Bing, Google, X/Twitter). 13,426,869 individuals affected β€” second-largest healthcare breach of 2024. Data shared included names, IP addresses, sign-in status, health encyclopedia search terms (symptoms, drugs, conditions), and navigation behaviour. No SSNs, financial data, or login credentials involved. HHS OCR breach portal notification filed April 2024. $47.5 million settlement reached. Broader HIPAA web-tracking enforcement context: OCR had issued guidance in 2022 prohibiting use of tracking technologies that transmit PHI.

Technical Details

Initial Attack Vector
CWE-359: Exposure of Private Personal Information to an Unauthorized Actor (third-party analytics/advertising tracking pixels embedded in patient-facing portal shared PHI with Google, Microsoft Bing, and X/Twitter)
Vendor / Product
Kaiser Permanente member portal and apps

Timeline

  1. 2024-01-01 Breach occurred
  2. 2024-04-12 Publicly disclosed
  3. 2024-04-25 Customers notified