- Academics at the University of Pennsylvania analyzed a nationally representative sample of 100 non-federal acute care hospitals – essentially traditional hospitals with emergency departments – and their findings were that 96 percent of their websites transmitted user data to third parties.
- Not all sites had privacy policies and of those that did, only 56% disclosed specific third parties receiving data.
- Google and Meta (through Facebook Pixel) were on nearly every site and received the most data. Adobe, Verizon, Oracle, Microsoft, Amazon also received data.
- Common data shared included IP addresses, browser info, pages visited, referring site.
- Sharing data poses privacy risks for visitors and legal/regulatory risks for hospitals if policies don’t comply with laws.
- A class action lawsuit against Mass General Brigham and Dana-Farber resulted in an $18.4M settlement over sharing patient data.
- Researcher calls for hospitals to collaborate with computer science departments to design more private websites. Also recommends privacy tools to block third party tracking.
But in the meantime, and in lieu of any federal data privacy law in the US, protecting personal information falls to the individual. And for that, Friedman recommends browser-based tools Ghostery and Privacy Badger, which identify and block transfers to third-party domains. “It impacts your browsing experience almost none,” he explained. “It’s free. And you will be shocked at how much tracking is actually happening, and how much data is actually flowing to third parties.”
Note: Although Friedman recommends Ghostery and Privacy Badger, uBlock Origin is generally considered a better privacy-enhancing browser extension. Additionally, there exist multiple approaches for adblocking and tracker blocking beyond the browser extension model.
I remember years ago my friends told me Ghostery did some shady business. Sadly it is difficult to find any useful information about this, between the lots of ads and pop ups (Where have all the blog posts gone ?), but here is something : https://en.wikipedia.org/wiki/Ghostery#Criticism
This is called “enumerating badness” and the findings here are both probably not that meaningful and based on a lot of assumptions.
I am curious to see what data is being transmitted, but not a lot is actually revealed by this
I’m not a programmer so I could be wrong… Aren’t using the direct medical apps on your phone (Epic, FollowMyHealth, etc) safer than the web?
Or are they selling that data too?At first, I found this funny. Then I realized how scary, sad, etc. the reality is.
Companies typically prefer users to use a native app for two reasons. First, the software is sometimes easier to build. Second, they are capable of scraping a vastly larger and more valuable set of data from the user.
Browsers can hit many differs sites, many of which are dangerous. Thus, web browsers have to be as secure as possible to protect users from malicious sites. This includes Facebook, TikTok, every medical site you’ve ever logged into, etc.
I know a lot about software. Personally, I view every installed app as a means of attacking my privacy. If you have the choice and your experience isn’t diminished, use a web browser instead of a native app.
Edit:
Something else to note. The larger companies are almost always much worse. Take a look at Facebook on the Apple Store: https://apps.apple.com/us/app/facebook/id284882215
Go down to App Privacy and View Details. It’s absolutely terrible how much data they collect. Unethical at a minimum. Now compare to Voyager for Lemmy: https://apps.apple.com/us/app/voyager-for-lemmy/id6451429762
“Data Not Collected”
That is definitely some scary shit, thank you. That also piggybacks onto another thought I had, my partner insists on google chrome for everything. (He is a pc and android user). I stay away from google anything and would think because he SAYS he cares about what’s collected, and he admits he isn’t a techie, but then doesn’t want to hear it from me when I say use something Mozilla based and ublock. But nothing is safe anymore. I do use voyager. :)
I ditched chrome (chromium + google propriety spyware) some years ago in favor of Brave browser (chromium + Brave stuff). It was a decent user experience but Brave also does some shady stuff, which you can google easily if interested.
Last year, google poisoned chromium with DRM stuff. They rolled back the changes after a few months but the damage was already done. I, and many others, jumped ship to Firefox and other non-chromium based browsers. Firefox isn’t perfect, but it’s an excellent browser. I’m sticking with it for the foreseeable future. And absolutely use uBlock Origin. Between that and proton VPN features, I don’t see ads anymore. It’s fantastic.
Welcome to for-profit healthcare.
Doesn’t this violate HIPAA, or does HIPAA not cover this?
Reading this while in an urgent care lmao
I bet they made you use a website or app to check in. And that website wasn’t created by the Urgent Care. So everything you entered isn’t protected by HIPPA.
They did and probably 😔