Cerebral tells 3.1 million people tracking pixels leaked their health data
- Organization
- Cerebral
- Exploit
- Human Error
- Industry
- Telehealth
Telehealth company Cerebral notified 3,179,835 people in March 2023 that protected health information had been disclosed to third-party advertising and analytics platforms through tracking technology embedded in its website and apps.
Cerebral said the tracking pixels and similar tools, supplied by companies including Google, Meta and TikTok, had been in place since October 12, 2019. The company disabled, reconfigured or removed them after concluding that it had shared data without obtaining the assurances HIPAA requires from such recipients. The disclosures ran through January 3, 2023, the date on which Cerebral said it discovered that the tracking technologies had transferred protected health information to third parties.
The information involved varied with how much of the service a person used. Anyone who created an account could have had a full name, phone number, email address, date of birth, IP address, Cerebral client ID and demographic details transmitted. People who completed the platform's mental health self-assessment also had their responses and associated health information disclosed, and subscribers had treatment details, appointment dates, insurance information and pharmacy or co-pay data involved.
Cerebral said Social Security numbers, credit card numbers and bank account details were not affected. The company recommended that users reset their passwords, offered complimentary credit monitoring, and said it had changed its data transmission practices after federal guidance clarified what counts as protected health information in this context.