Facebook (Meta) Healthcare and Tax Payer Breaches

Facebook (Meta) Healthcare and Tax Payer Breaches

Over the past year, news outlets have been buzzing about Facebook, now called “Meta”, collecting vast amounts of data from healthcare organizations and tax return companies.  Some of these companies are announcing breaches as a result of this data collection.

Why are Companies Sending Sensitive Data to Facebook?

Let’s be clear – Companies are not trying to send their sensitive information to Facebook.  Companies are NOT going to Facebook.com and uploading their customer information.  Instead, Facebook is collecting this information via web tracker software that they offer to companies for free to monitor website visitor behavior.  Companies invest a lot of resources in their websites to ensure their customers get the best value and can easily navigate their offerings.  In order to see how customers interact with their websites, companies install web trackers to monitor button clicks, visitor statistics, navigation errors, and more.  Most websites have a method of logging user behavior using trackers that are generally hidden from the website visitor.  A couple of the many website trackers include Facebook’s Meta Pixel and Google Analytics.  Companies are using it to track basic website visitor information and often times they do not realize that Facebook may be collecting sensitive information.

What is Meta Pixel?

Meta Pixel is Facebook’s web tracker software.  Facebook’s Meta Pixel is popular, easy to use, and it’s free.   Any company can download the code, install it on their website, and instantly see information about website visitors.  Companies can log into a dashboard showing daily website visitor statistics.

Is a Vulnerability in the Meta Pixel Software Causing the “Breach”?

There is no known vulnerability in the Meta Pixel software that is causing the breaches.  Instead, companies are announcing breaches because Facebook is not supposed to receive sensitive information.  Since Meta Pixel is collecting more information than intended, and Facebook was not authorized to have access to this information, companies are listed it as a breach or a privacy violation.

What Companies are Affected?

The Markup news outlet wrote an investigative report about a number of hospitals that had the Meta Pixel code on their website and their patient protected portals (Feathers, Fondrie-Teitler, Waller, & Mattu, 2022).  Some of the affected hospitals immediately removed the Meta pixel software when they realized that it could collect more information than intended.  The Markup released another report showing how tax filing websites were sending sensitive tax payer information to Facebook by the same Meta Pixel software (Fondrie-Teitler, Waller, & Lecher, 2022).  While the healthcare and financial industries are in the news for these issues, the website tracker breaches surely affect many industries as the Facebook Meta Pixel code is installed on millions of websites.

How is Meta using the Data?

It is unclear how Meta is using the collected data.  Facebook itself may not know what it does with this data according to a Vice report based on a leaked internal Facebook memo (Franceschi-Bicchierai, 2022).  In the leaked memo, a Facebook engineer stated “We do not have an adequate level of control and explainability [sic] over how our systems use data”.

Number of Individuals Affected

According to the 2023 Velocity Healthcare Breach Report, in the healthcare industry alone, over 6,000,000 medical records were affected in 2022.  The affected tax filing companies have millions of customers.  The number of affected individuals is most likely much higher and continues to grow as more companies announce that they had the Meta Pixel software on their websites.

What Can Companies do to Prevent this in the Future?

Companies should thoroughly investigate all web trackers to determine how data is utilized before placing the code in production environments.  Many companies have methods to perform security evaluations on new third-parties as they go through the procurements system, but this scrutiny is not usually applied to free software such as Meta Pixel or Google Analytics.  Companies should ensure that any code changes go through a Software Development Lifecycle (SDLC) that includes a security analysis.

How can Stern Security Help?

Our cybersecurity services team has extensive experience analyzing web trackers and the data that they send outside a customer environment.  Additionally, Stern Security’s Velocity application can be used to get your third-party risk management program in order and evaluate vendor solutions for cybersecurity and privacy problems.

Works Cited

Feathers, T., Fondrie-Teitler, S., Waller, A., & Mattu, S. (2022, July 19). Facebook Is Receiving Sensitive Medical Information from Hospital Websites. Retrieved from The Markup: https://themarkup.org/pixel-hunt/2022/06/16/facebook-is-receiving-sensitive-medical-information-from-hospital-websites

Fondrie-Teitler, S., Waller, A., & Lecher, C. (2022, November 28). The Markup. Retrieved from Tax Filing Websites Have Been Sending Users’ Financial Information to Facebook: https://themarkup.org/pixel-hunt/2022/11/22/tax-filing-websites-have-been-sending-users-financial-information-to-facebook

Franceschi-Bicchierai, L. (2022, April 26). Facebook Doesn’t Know What It Does With Your Data, Or Where It Goes: Leaked Document. Retrieved from Vice: https://www.vice.com/en/article/akvmke/facebook-doesnt-know-what-it-does-with-your-data-or-where-it-goes

2023 Velocity Healthcare Data Breach Report

2023 Velocity Healthcare Data Breach Report

In its second annual Velocity healthcare data breach report, Stern Security has critically analyzed over 5,000 data breaches since the Department of Health and Human Services (HHS) began tracking the information in 2009. Stern Security utilized data from their HealthcareBreaches.com website as well as published information from HHS to create this comprehensive study. Stern Security augmented the HHS data by investigating each breach in 2022 to fully understand the cause of the incident.

This report shows critical insights into healthcare breach trends over the past 13 years. It covers everything from the number of breaches attributed to ransomware to the number attributed to third-parties (business associates). This year, Stern Security has added a new breach categorization – the number of breaches due to analytics software including Meta (Facebook) Pixel. Once again, a new breach record was established with more healthcare breaches occurring in 2022 than any previous year. This report puts forth a detailed analysis.

Mailing List

If you enjoyed our 2023 Velocity Healthcare Breach Report and would like to join our mailing list to stay informed, please complete the form below.

2022 Velocity Healthcare Data Breach Report

2022 Velocity Healthcare Data Breach Report

In its first annual healthcare data breach report, Stern Security has critically analyzed over 4,000 data breaches since the Department of Health and Human Services began tracking the information in 2009. Stern Security utilized data from their HealthcareBreaches.com website as well as published information from Health and Human Services to create this comprehensive report.

This report shows thought-provoking insights into healthcare breach trends over the past 12 years. It covers everything from the number of breaches attributed to ransomware to third-party (business associate) breaches. More healthcare breaches occurred in 2021 than any other year and this report illustrates the detailed analysis.

If you enjoyed the report and want to stay in the loop, please join our mailing list:

Breached Healthcare Records Surpass U.S. Population

Breached Healthcare Records Surpass U.S. Population

Healthcare breaches have recently reached a grim milestone. As of June 10th, 2022, the number of Protected Health Information (PHI) records breached has reached 341,995,928.  To put in prospective, this number surpasses the United States population which is at 332,759,097 (United States Census Bureau, 2022). 

As the graphs show on HealthcareBreaches.com, this startling loss of data is almost entirely due to hacking.

It must be noted that these numbers only include reported healthcare breaches containing 500 or more PHI records.  Healthcare breaches under 500 records are not listed publicly.  To view additional trends, please visit our healthcare executive data breach dashboard at https://www.healthcarebreaches.com/ and utilize the control panel on the left side to fine-tune your area of interest.

Works Cited

United States Census Bureau. (2022, June 10). U.S. and World Population Clock. Retrieved from United States Census Bureau: https://www.census.gov/popclock/

Hacking Finally Tops Healthcare Breach Causes

Hacking Finally Tops Healthcare Breach Causes

Hacking Finally Tops Healthcare Breach Causes

One would think that most data breaches were caused by hacking as those are the breaches that are always mentioned in the news. However, up until the end of 2019, Theft was still the top cause of breaches in healthcare according to data compiled from the U.S. Department of Health and Human Services (HHS) Office for Civil Rights.

Utilizing the Healthcare Breach Executive Dashboard at https://www.healthcarebreaches.com, we could see the breach trends changing. While breaches due to Theft were increasing at a slow pace, Hacking/IT Incident breaches were steadily climbing at a rapid pace. It was only a matter of time before Hacking topped the charts.

Why is the rate of breaches due to theft slowing down? One possible explanation is encryption. Most breaches due to Theft occur from stolen laptops, USB Drives, desktops, etc. that contain Protected Health Information (PHI). Thefts still frequently, however, organizations are getting better at encrypting drives. If a stolen drive is encrypted, it is not reported as a breach.

Even though Hacking only recently past Theft as the top source of healthcare breaches, there has been no competition for the source of the number of records lost. Hacking has far surpassed all other breach categories for the top cause of patient records compromised.

If breaches from Theft could be slowed down, perhaps Hacking can as well. Organizations must do all they can do increase security posture and reduce risk. Continue checking HealthcareBreaches.com for more trend updates.