Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Blue Shield of California shared the private health data of millions with Google for years
TechCrunch ^ | 4/23/25 | Zach Whittaker

Posted on 04/27/2025 3:04:02 PM PDT by CFW

Health insurance giant Blue Shield of California is notifying millions of people of a data breach. The company confirmed on Wednesday that it had been sharing patients’ private health information with tech and advertising giant Google since 2021.

The insurer said that the data sharing stopped in January 2024, but it only learned this February that the years-long collection contained patients’ personal and sensitive health information.

Blue Shield said it used Google Analytics to track how its customers used its websites, but a misconfiguration had allowed for personal and health information to be collected as well, such as the search terms that patients used on its website to find healthcare providers.

The insurance giant said Google “may have used this data to conduct focused ad campaigns back to those individual members.”

Blue Shield said the collected data also included insurance plan names, types, and group numbers, along with personal information such as patients’ city, zip code, gender, and family size. Details of Blue Shield-assigned member account numbers, claim service dates and service providers, patient names, and patients’ financial responsibility were also shared.

(Excerpt) Read more at techcrunch.com ...


TOPICS: Constitution/Conservatism; Culture/Society; US: California
KEYWORDS: bluecross; breach; california; data; hipaa; privacy
That's quite a breach!

So Blue Shield of California spent almost three years accidentally handing over sensitive health info - names, medical claims, family data, and even doctor searches - to Google without telling anyone.

They were trying to track website clicks, but thanks to sloppy settings, Google Ads got a backstage pass to patient privacy from April 2021 to January 2024.

1 posted on 04/27/2025 3:04:02 PM PDT by CFW
[ Post Reply | Private Reply | View Replies]

To: CFW

This is what happens when your tech team are all DEI hires.


2 posted on 04/27/2025 3:04:57 PM PDT by CFW
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW
The insurance giant said Google “may have used this data to conduct focused ad campaigns back to those individual members.”

And, of course, Google never came back to Blue Shield and said, "Hey, you might be giving us too much information, here."

3 posted on 04/27/2025 3:12:53 PM PDT by Mr. Jeeves ([CTRL]-[GALT]-[DELETE])
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW
The insurer said that the data sharing stopped in January 2024, but it only learned this February that the years-long collection contained patients’ personal and sensitive health information.

Would they like to pull my other leg? I tied bells on it to give a festive touch.

4 posted on 04/27/2025 3:19:33 PM PDT by Harmless Teddy Bear ( Not my circus. Not my monkeys. But I can pick out the clowns at 100 yards.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW
but thanks to sloppy settings

I'm not convinced of that part.

5 posted on 04/27/2025 3:28:55 PM PDT by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW

Why this is a surprise to anybody is what’s amazing.


6 posted on 04/27/2025 3:32:29 PM PDT by Lizavetta
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW

Aren’t Hippa violations prosecutable crimes?


7 posted on 04/27/2025 3:40:36 PM PDT by Seruzawa ("The Political left is the Garden of Eden of incompetence" - Marx the Smarter (Groucho))
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW

Get your online health password, we will protect your health data, of course.


8 posted on 04/27/2025 3:45:03 PM PDT by If You Want It Fixed - Fix It
[ Post Reply | Private Reply | To 2 | View Replies]

To: Mr. Jeeves
Yeah, this is sick and pathetic on both sides.

A rookie coder could strip away identifying data at the origin, and only send forward anonymous data that only Blue Shield could re-attach to the patients.

On the Blue Shield side, even a rookie coder could identify what was passing to them and tell them strip the patient data.

9 posted on 04/27/2025 4:06:16 PM PDT by T.B. Yoits
[ Post Reply | Private Reply | To 3 | View Replies]

To: CFW

Or Indian.


10 posted on 04/27/2025 4:08:53 PM PDT by grey_whiskers (The opinions are solely those of the author and are subject to change without notice.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: CFW

It’s just “confusion”

When that word is used as an excuse, you should see how I nuke people.

Incompetence, greed, failure, fraud, stupidity is not…. Confusion or a coincidence.


11 posted on 04/27/2025 4:10:21 PM PDT by Professional ( )
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW

Just send me my million dollars and all will be forgiven.


12 posted on 04/27/2025 4:16:27 PM PDT by Enterprise ( These people have no honor, no belief, no poetry, no art, no humor, no patriotism.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW
It's not an "accident", it's ignorance.

The personal information should have been stripped out from the dataset and replaced with anonymous unique identifiers that could be later synced back up to the patient information after getting run through Google Analytics.

It should be one of the very first steps in the process.

13 posted on 04/27/2025 4:58:06 PM PDT by T.B. Yoits
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW

But DOGE is the problem.


14 posted on 04/27/2025 5:39:42 PM PDT by E. Pluribus Unum (Democrats are the Party of anger, hate and violence.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW

“So Blue Shield of California spent almost three years accidentally handing over sensitive health info...”

Doesn’t sound like much of a ‘shield’.

Anyway, will Blue Shield now re-imburse people for the money they received from Google for this sensitive information?

I kind of doubt it.


15 posted on 04/27/2025 5:40:40 PM PDT by BobL
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW

Don’t think for one second that Google didn’t know they were collecting illegal information… not for one single second


16 posted on 04/27/2025 5:41:27 PM PDT by HamiltonJay
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW

It’s just a whoopsie do do! Accidents happen. Someone was preoccupied and hit the wrong key, sending the data of millions to Googleland. Then they simply forgot about it and went to lunch. This sounds perfectly reasonable and legitimate.


17 posted on 04/27/2025 6:22:09 PM PDT by dragnet2 (Diversion and evasion are tools of deceit)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW
The insurer said that the data sharing stopped in January 2024, but it only learned this February that the years-long collection contained patients’ personal and sensitive health information.

3 year data stream and they didn't know what information the data contained? LOL....Who was getting paid?

18 posted on 04/27/2025 6:34:06 PM PDT by dragnet2 (Diversion and evasion are tools of deceit)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CFW

Blue Shield of California sold........................?

Sounds more like it most use the hack issue for it


19 posted on 04/28/2025 7:23:11 AM PDT by Vaduz
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson