Kaiser Permanente website trackers exposed data on 13.4 million members

Organization
Kaiser Foundation Health Plan (Kaiser Permanente)
Exploit
Misconfiguration
Industry
Healthcare

Kaiser Foundation Health Plan, which operates as Kaiser Permanente, notified about 13.4 million current and former members and patients that online tracking technologies on its websites and mobile applications had transmitted their information to third parties. The health system reported the incident to the US Department of Health and Human Services and the California Attorney General's Office on 12 April 2024, and the disclosure was reported publicly later that month.

Kaiser said the tracking code, installed previously on its digital properties, may have passed data to Google, Microsoft Bing and X, formerly Twitter, when members and patients used the sites or apps. The information involved included names, IP addresses, indicators of whether a person was signed in to an account, how they navigated the sites, and search terms entered into Kaiser's health encyclopedia.

The organisation said usernames, passwords, Social Security numbers and payment card or financial account details were not involved. It stated it had no awareness of any misuse of member or patient information and said it was notifying people out of an abundance of caution.

Kaiser removed the tracking technologies from its websites and applications and said it had put additional safeguards in place. HHS logged the event on its breach portal as an unauthorised access or disclosure affecting 13.4 million people. Security researchers noted at the time that data captured by advertising trackers is routinely passed on within the wider ad ecosystem regardless of which vendor receives it first.

Sources