Forgotten Dairies

Hospitals Turned Patient Trust Into Advertising Data -By Fransiscus Nanga Roka

Congress should also establish a federal private right of action, joint liability for healthcare providers and technology vendors, quick breach notification and mandate deletion of data obtained unlawfully while providing damages without forcing patients to prove downstream identity theft.

Published

on

A hospital website needs to be a digital clinic, not an advertisement sink hole.

But are the proposed class actions uncovered the allegation about tracking technologies like Google Analytics, advertising cookies, Sdk and Meta Pixel allegedly tracked patients across healthcare websites and apps. These may register page views, button clicks, appointment activity, search queries, device identifiers and other information that can help determine why a person is seeking treatment.

This wasn’t a hacker penetrating the firewall of a hospital. Even more disturbing, the allegation that some healthcare organizations actually deployed the surveillance infrastructure themselves.

In Doe v. Google LLC, filed on May 12, 2023 in federal court in California, a pseudonymous plaintiff alleged that the automated tracking tools Google provides to assist web and app development quietly captured and shared a wealth of sensitive information collected from healthcare websites and apps. One of the incidents described in the complaint involved a California resident who had looked up Planned Parenthood on the web. The information transmitted was reported to have included the IP address of the user, their approximate location, which facility they had selected and pages stating why they wanted care. California s privacy and medical-confidentiality law are also the basis of the proposed nationwide class. These are, of course, allegations against Google supposedly not a ruling of liability yet. ClassAction. org

Who may be affected? Patients and visitors on hospital portals, appointment pages, symptom checkers, methodist-wellbeing.com reproductive-wellbeing sites and medical apps.

Advertisement

What may have been transmitted? Identity + what they are treating, appointment information or browsing activity

What is the place of the alleged monitoring? In digital spaces validating and seeming like secret medicinal care.

Why was it collected? The complaints included unauthorized tracking data, analytics, advertising and commercial profiling.

How did it happen? When users had interacted with the service, small snippets of code from third parties would be sent to transmit data automatically, more often than not before a user was meaningfully informed (or agreed) of the disclosure.

The scandal is about more than dodgy cybersecurity: it shows a deeper ethical failure. If healthcare institutions requested that patients lajf trust them, they may have let advertising architecture spy on their fears. A search for cancer is not consumer choice An appointment with an abortion provider is not a unit of margin. A psychiatric inquiry is not an advertising sign. It materializes the medical professional’s contract of confidentiality with patients and transforms it into unprocessed information for surveillance capitalism.

Advertisement

But legal accountability remains fragmented. HIPAA, Only applies to Covered Entity and Business Associate disclosures of PHI According to HHS, tracking technologies on authenticated patient pages usually have access to PHI, and the marketing disclosures typically need HIPAA-compliant authorization. It even cautions that such unauthorized disclosure can lead to discrimination, stigma, identity theft and physical harm. HHS

Nevertheless, not every visit to a public health webpage by any person is automatically protected by HIPAA. 2024 The federal court vacated guidance issued by HHS that made the combination of an IP address and a visit to an unauthenticated health-related webpage necessarily HIPAA triggering. It is this gap that leaves patients relying on state privacy statutes, consumer-and wiretap claims and fact-specific proof of identifiability.

That patchwork rewards strategic ambiguity. Hospitals may blame vendors. Thus, some vendors may report that they were only given technical data. Health-care providers will say that technology companies set the tools up, known as “configuring,” if they argue otherwise. Fragmentation makes money for everyone, and patients pay the price to prove it happened.

Third-party advertising trackers on patient-facing healthcare platforms should be presumed harmful, and regulators ought to take steps to protect against their use. Hospitals should execute public inventories of trackers, eliminate unnecessary pixels, separate analytics from advertising and obtain explicit opt-in consent before transmitting any identifiable health data.

Congress should also establish a federal private right of action, joint liability for healthcare providers and technology vendors, quick breach notification and mandate deletion of data obtained unlawfully while providing damages without forcing patients to prove downstream identity theft.

Advertisement

The uncompromising principle, is that health information generated in the course of seeking care must never become an ad commodity. This is not a mere failure of privacy in a healthcare system that monetizes vulnerability. It has let the patient down before treatment starts.

Fransiscus Nanga Roka

Faculty of Law University 17 August 1945 Surabaya and Managing Partner Lw Firm Victorious Indonesia

Leave a Reply

Your email address will not be published. Required fields are marked *

Exit mobile version