On February 11, 2025, Blue Shield discovered that, between April 2021 and January 2024, Google Analytics was configured in a way that allowed certain member data to be shared with Google’s advertising product, Google Ads, that likely included protected health information. Google may have used this data to conduct focused ad campaigns back to those individual members.

Blue Shield severed the connection between Google Analytics and Google Ads on its websites in January 2024.

What information was involved

  • Insurance plan name, type and group number;
  • city;
  • zip code;
  • gender;
  • family size;
  • Blue Shield assigned identifiers for members’ online accounts;
  • medical claim service date and service provider, patient name, and patient financial responsibility;
  • “Find a Doctor” search criteria and results (location, plan name and type, provider name and type).
    • DominusOfMegadeus
      link
      fedilink
      English
      193 months ago

      In theory there would be large fines for every violation, of which there would be millions in this case

      • sunzu2
        link
        fedilink
        53 months ago

        These people kill low quality domestic slaves for sports and profit…

        They are above the law and selling your data is a nice revenue stream

        What you gonna do about it? Switch your insurance?

    • @unconfirmedsourcesDOTgov@lemmy.sdf.org
      link
      fedilink
      English
      4
      edit-2
      3 months ago

      Arguably the only potential PHI is the association between provider names and individuals, but with the current clown show running HHS, I’m not going to hold my breath and wait for accountability here.

    • stankmut
      link
      fedilink
      English
      17
      edit-2
      3 months ago

      The analytics would be for the web development team to see which pages/features are used. Usually a product manager uses that data for setting priorities on what gets worked on.

        • Cousin Mose
          link
          fedilink
          English
          23 months ago

          As a web developer that blocks all this shit, that’s the line I always use. I would just use first-party analytics from the same domain the website is hosted from. The added bonus is that people like me wouldn’t even be able to block it without blocking the entire website (at least with DNS).

      • @Tronn4@lemmy.world
        link
        fedilink
        English
        -53 months ago

        SHUSH! 😄 We trying to burn this whole thing to the ground! Don’t come here with all that sense making talk! 🤣 /s

        • Cousin Mose
          link
          fedilink
          English
          23 months ago

          But you can do all that without selling out your users to third parties.

    • @real_squids@sopuli.xyz
      link
      fedilink
      English
      9
      edit-2
      3 months ago

      “Better” ads most likely, aka more personalized.

      edit:

      Google may have used this data to conduct focused ad campaigns back to those individual members.

      That’s their exact language

      • stankmut
        link
        fedilink
        English
        4
        edit-2
        3 months ago

        Allowing Google to run an ad campaign targeting their members wasn’t the benefit Blue Cross was talking about, that’s a side effect from them not turning off the data sharing option in the Google analytics settings.

        The analytics data is used for prioritizing development work. If a tool they have on the website relies on a library that isn’t compatible with a new version of React, for instance, do they know how many people use it? Having analytics allows you to decide what’s worth spending the development time to maintain.

    • @chaospatterns@lemmy.world
      link
      fedilink
      English
      73 months ago

      Google Analytics gives you insights on what pages people visit, how long they spend, what kind of browsers and devices they use. That can give them data on what pages are important to customers and what screen sizes to support

      I’d rather they self host this data vs use Google Analytics, but there are benefits.

      • @NotMyOldRedditName@lemmy.world
        link
        fedilink
        English
        63 months ago

        It goes further than that. They can track how people interact with the page, order of buttons pressed, if or when they abort a workflow etc. You can go as deep down the rabbit hole of analytics and optimizations as you want.

    • SharkEatingBreakfast
      link
      fedilink
      English
      43 months ago

      Dear Blue Shield members: what improvements in “”“services”“” from Blue Shield have you seen?

  • Phoenixz
    link
    fedilink
    English
    303 months ago

    Jail those involved.

    I’m serious, jail them. This is again corpos making millions from us plebs and then they’ll get a fine that is a fraction of what they made and since they don’t pay taxes anyway, it’s still nothing.

    Jail them

    Find out who was in charge and either that person can show evidence that it was someone else without their knowledge or YOU JAIL THEM. Both at Google and at that torture company blue shield

    Jail them! Jail them now. Jail them for years, at least.

  • @pelespirit@sh.itjust.works
    link
    fedilink
    English
    163 months ago

    I saw an ad for Amazon telehealth a couple of weeks ago. I’m not digging the times we’re in. I also hope we don’t look back on this time with nostalgia.

      • Lka1988
        link
        fedilink
        English
        23 months ago

        “Yes, the planet got destroyed. But for a beautiful moment in time we created a lot of value for shareholders”

  • @takeda@lemm.ee
    link
    fedilink
    English
    113 months ago

    This is why you always block ads and trackers. It never pays to worry about revenue of “poor sites”

  • Cousin Mose
    link
    fedilink
    English
    33 months ago

    This is why I’m such a cunt about blocking this stuff at the DNS and/or IP level. Google Analytics is essentially everywhere including IRS web pages with your Social Security number in the DOM.

  • sunzu2
    link
    fedilink
    13 months ago

    But HIPaA 🤡

    Love seeing normies cite some law without understanding how the regime actually operates on practice.

    Useful fucking idiots