State healthcare websites have been sharing sensitive personal information including location data, race, and immigration status with Meta, TikTok, and other major tech companies. Privacy experts say current laws fail to protect users.
Multiple state healthcare sites are transmitting personal data to large technology platforms, raising significant privacy concerns. The shared information includes location history, racial demographics, and immigration status—details typically considered sensitive health-related information.
The data flows occur through tracking tools and analytics embedded on state health websites. These tools, commonly used for measuring web traffic and user behavior, often send information to third-party companies including Meta and TikTok.
States affected include those running their own healthcare marketplaces and enrollment systems. The practice appears widespread but largely undisclosed to users accessing these sites for health insurance information and enrollment.
Current Privacy Gaps
Existing privacy regulations like HIPAA do not adequately cover these data-sharing practices. HIPAA protects health information held directly by healthcare providers and insurers, but does not extend to state websites or the third-party tracking tools they employ.
State privacy laws vary significantly in scope and enforcement. Many states lack specific regulations governing how personal information can be shared with tech platforms, leaving gaps in protection even where privacy laws exist.
Industry Practice
The integration of tracking and analytics tools on government health sites reflects broader industry practice. Many public websites use similar tools to monitor user engagement and traffic patterns.
However, the sensitivity of health-related data—combined with the involvement of major social media platforms with significant advertising capabilities—distinguishes this situation from standard website analytics.
Path Forward
The issue highlights growing tension between government digital services and data privacy. Privacy advocates are calling for stronger regulations to restrict data sharing from health websites and greater transparency about tracking practices on government platforms.
Some proposals include requiring explicit user consent before data sharing, limiting what types of information can be transmitted to third parties, and extending privacy protections to government health websites specifically.
The U.S. Cybersecurity and Infrastructure Security Agency has issued a mandate requiring all federal agencies to patch an actively exploited remote code execution vulnerability in Citrix NetScaler appliances by Saturday.
A new Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service attacks and root-level privilege escalation.
The FBI has dismantled proxy tools used by Chinese hackers in a widespread campaign against NASA, the Federal Reserve, the US Senate, and the Justice Department. The operation marks a significant coordinated response to months of intrusions into critical US infrastructure.
Snowflake is phasing out password authentication for legacy service accounts, requiring organizations to adopt passwordless methods. The real challenge: identifying which accounts exist, who manages them, and what access they hold.