Blue Shield of California sent member health data to Google Ads by misconfiguration
- Organization
- Blue Shield of California
- Exploit
- Misconfiguration
- Industry
- Healthcare
Blue Shield of California disclosed on 9 April 2025 that a misconfigured web analytics setup had passed protected health information to Google's advertising platform for close to three years.
The insurer said Google Analytics had been installed on some of its websites in a way that allowed member data to flow into Google Ads between April 2021 and January 2024. Blue Shield said it discovered the problem on 11 February 2025 and had already severed the connection between the two Google products in January 2024, with no further sharing after that point.
The incident was posted to the US Department of Health and Human Services breach portal as affecting roughly 4.7 million people. The information involved included names, gender, city and ZIP code, family size, insurance plan name, type and group number, Blue Shield account identifiers, medical claim service dates and providers, patient financial responsibility, and the search criteria and results members entered into the plan's Find a Doctor tool. Blue Shield said Social Security numbers, driver's licence numbers, credit card numbers and banking information were not involved.
The company said no attacker was involved and that, to its knowledge, Google had not used the data for anything beyond targeted advertising or passed it to anyone else. It said it reviewed its websites and security protocols after the discovery. Reporting at the time noted this was the insurer's second large incident in under a year, following a 2024 vendor ransomware attack affecting close to a million members.