[HN Gopher] Blue Shield Data Breach (Google Ads)
       ___________________________________________________________________
        
       Blue Shield Data Breach (Google Ads)
        
       Author : bix6
       Score  : 60 points
       Date   : 2025-04-10 16:09 UTC (6 hours ago)
        
 (HTM) web link (news.blueshieldca.com)
 (TXT) w3m dump (news.blueshieldca.com)
        
       | bix6 wrote:
       | Disappointing behavior to say the least.
       | 
       | "On February 11, 2025, Blue Shield discovered that, between April
       | 2021 and January 2024, Google Analytics was configured in a way
       | that allowed certain member data to be shared with Google's
       | advertising product, Google Ads, that likely included protected
       | health information. Google may have used this data to conduct
       | focused ad campaigns back to those individual members. We want to
       | reassure our members that no bad actor was involved, and, to our
       | knowledge, Google has not used the information for any purpose
       | other than these ads or shared the protected information with
       | anyone."
        
         | accrual wrote:
         | I wonder what, if any, HIPAA fines will apply to Blue Shield if
         | they're found to have inadvertently exposed PHI.
         | 
         | https://www.hipaajournal.com/hipaa-violation-fines/
        
           | chimeracoder wrote:
           | > I wonder what, if any, HIPAA fines will apply to Blue
           | Shield if they're found to have inadvertently exposed PHI.
           | 
           | Well, they _have_ inadvertently exposed PHI - this press
           | release literally admits that they did.
           | 
           | In terms of what fines will apply, well, the annual cap for
           | violations is about $2 million per calendar year, but I doubt
           | they'll have to pay even that.
        
         | 01HNNWZ0MV43FF wrote:
         | "No bad actor was involved"
         | 
         | I see two but whatever
        
           | anon84873628 wrote:
           | I'm sure Google doesn't want customers doing this dumb stuff.
           | So I'd also expect by this point they would be automatically
           | profiling the incoming data to throw up warnings and safe
           | guards. Maybe there is a perverse incentive where doing that
           | only increases their liability in these situations.
        
         | wrs wrote:
         | Putting a third party analytics tool on a page containing PHI
         | is an incredibly dangerous thing to do. It's really surprising
         | the developers could get that through a security review.
        
           | donohoe wrote:
           | What security review?
        
           | stackskipton wrote:
           | As someone who has worked in this field, I'm not. Marketing
           | is generally exempt from massive legal review as they hand
           | wave away "We don't deal with HIPPA data" and developers just
           | wanting marketing to go away, dropped the Javascript block
           | into files that were used for a ton of products including
           | HIPAA containing ones.
           | 
           | EDIT: Most of these places are just feature factories with
           | offshore developers who are very unlikely to raise concerns.
        
             | chimeracoder wrote:
             | > As someone who has worked in this field, I'm not.
             | Marketing is generally exempt from massive legal review as
             | they hand wave away "We don't deal with HIPPA data" and
             | developers just wanting marketing to go away, dropped the
             | Javascript block into files that were used for a ton of
             | products including HIPAA containing ones.
             | 
             | I don't know why you're being downvoted, because this is
             | unfortunately quite accurate. You'd be shocked how often
             | this happens, even for tools they think are totally secure
             | and "HIPAA-compliant".
             | 
             | > EDIT: Most of these places are just feature factories
             | with offshore developers who are very unlikely to raise
             | concerns.
             | 
             | I don't think there's any meaningful difference based on
             | where the developers are located. The developers aren't the
             | ones making the decisions. Usually the issue is that the
             | _higher-ups_ want it, which is why practices can continue
             | even after concerns are raised.
        
               | gausswho wrote:
               | I worked at an org that give Google Tag Manager access to
               | marketing, effectively as means of bypassing engineering
               | to try whatever spyslime of the month they could paste
               | into a box.
        
           | unyttigfjelltol wrote:
           | I would turn that around to be an inference that there was no
           | effective security review....
        
           | AlotOfReading wrote:
           | Kaiser was hit with a class action for exactly the same issue
           | last year: https://news.bloomberglaw.com/litigation/patients-
           | advance-ka...
           | 
           | GoodRx, BetterHelp, and dozens of others have received
           | notices that this is an issue. The federal OCR even published
           | a bulletin about this 3 years ago.
           | 
           | You'd think that any one of these would have triggered
           | internal reviews and discovered this issue for all the
           | others, but that's much too high a bar to expect in
           | healthcare.
        
             | knowitnone wrote:
             | Good. Hope Blue Shield gets the same treatment but they'll
             | just pass the costs to their customers
        
           | ajross wrote:
           | It's only surprising when you phrase it like that. Real bugs
           | are interactions. I mean, sure, if you're asked to review a
           | pull request like "patient_info: Use google to track MRI
           | data", it's a no brainer.
           | 
           | But no doubt the analytics blurb was stuffed into a generic
           | "top_level_page" generator or whatever. And it happens that
           | the PHI wasn't firewalled by design, and pulled it in by
           | default. Or it was firewalled, but then someone forgot and
           | migrated the "patient_info_page" templates to a generic
           | framework, etc...
           | 
           | Security is really, really hard. And one of the worst
           | responses to a mistake like this is to tut-tut about how
           | obvious a mistake and how easy to avoid it was. Believing
           | that secure software is a matter of "not making mistakes"
           | makes you _more_ likely to write such bugs and not less,
           | because you won 't take the time to establish clear
           | boundaries from the start.
        
             | int_19h wrote:
             | Thing is, that's exactly what security and privacy reviews
             | are for.
             | 
             | If there was no review, that's negligence.
             | 
             | If there was a review, one of the first questions that
             | would be asked is, "what kind of tracking or telemetry do
             | you have"? And there are tools that will scan code and flag
             | things like that for you that large companies normally use.
        
       | olyjohn wrote:
       | Are you fucking kidding me? You get interrupted reading this shit
       | by a pop up asking you for your information?
        
         | userbinator wrote:
         | I guess that's what they mean by the "This site requires
         | Javascript in order to function properly" banner I get at the
         | top. The article is readable without JS anyway.
        
       | Ancapistani wrote:
       | The email subject for this notification was "Blue Shield of
       | California Privacy Notification."
       | 
       | It sounds like a fairly minor concern, but I find it quite
       | distasteful that the email subject doesn't indicate that a breach
       | occurred.
        
         | knowitnone wrote:
         | the hope is people delete it because it's just a "privacy
         | notification"
        
         | kmeisthax wrote:
         | Related pet peeve: if the price of something goes down, it's a
         | price drop, but when it goes up, it's a price _change_.
         | 
         | Can we coin a term for this weasel-y headline writing?
        
       | josefritzishere wrote:
       | There should be legal penalties for companies whose negligence
       | leads to data breaches. Consumers really have no recourse here
       | and even CCPA and HIPAA fines are exceedingly rare.
        
         | wormius wrote:
         | I'm sure those affected will get a 3.00 check and the lawyers
         | bringing suit will make a chunk of change. (curious if this
         | will lead to a suit or what the laws are around that (e.g. can
         | this be class action or will only known affected individuals be
         | allowed to seek redress?)
        
       | rdtsc wrote:
       | > Google may have used this data to conduct focused ad campaigns
       | back to those individual members. We want to reassure our members
       | that no bad actor was involved
       | 
       | Well that's a contradiction. I don't know about anyone else, but
       | I don't view Google as a "good actor".
        
         | anon84873628 wrote:
         | This statement is using lots of passive voice to try and
         | deflect and confuse.
         | 
         | Blue Shield configured GA to send data they weren't supposed
         | to. GA may have _automatically_ used that data to do the things
         | GA does. No human at Google would have ever interacted with
         | this data, chosen how it was used, known it was there, or
         | really given a shit (besides the risk of liability and not
         | wanting customers to be dumb and do exactly this).
        
         | mjevans wrote:
         | In this case, the "Bad Actor" was Blue Shield, for designing
         | their system to send PII / PHI to places it should never have
         | gone.
        
           | rdtsc wrote:
           | Of course they voluntarily handed it to Google knowing what
           | Google does. But Google is not a good actor either. Just
           | because "they do this to any data they get their hands on"
           | doesn't make it right.
        
       | neilv wrote:
       | > _between April 2021 and January 2024, Google Analytics was
       | configured in a way that allowed certain member data to be shared
       | with Google's advertising product, Google Ads, that likely
       | included protected health information._
       | 
       | I see so many medical and government sites that _really shouldn
       | 't_ be running third-party trackers. Yet almost every single time
       | I check, they are.
       | 
       | It's negligence/incompetence/reckless, criminally so, in some
       | cases.
       | 
       | Given the inability of almost anyone in our field to build or
       | operate a competently secure system, and the practices that go
       | out of their way to gratuitously make the situation even worse--
       | we really just need to smack our entire field upside the head,
       | repeatedly, until we stop churning out shit while strutting about
       | how smart we are.
       | 
       | "AI" development tools (i.e., making humans stupider, through the
       | power of plagiarism, to churn more BS at a faster rate) isn't
       | going to solve the root problems of grossly misaligned incentives
       | and culture.
        
         | wormius wrote:
         | Gotta love the passive voice used, too.
        
       | neilv wrote:
       | > _We understand receiving a notice such as this can create
       | concern, and we regret that member personal information may have
       | been shared without authorization._
       | 
       | Vague passive voice, FTW.
       | 
       | One way to start to fix the pattern and practice of gross
       | negligence in our field is for Blue Shield CA to get stuck with
       | HIPAA violation fines for each record leaked.
       | 
       | If Blue Shield CA claims they're not competent to know which
       | records were leaked, assume it's all of the records.
        
         | ceejayoz wrote:
         | I've seen this sort of wording called "exonerative tense" when
         | describing police conduct.
        
       | phkahler wrote:
       | This isn't a "data breach" is it? Blue Shield shared data with GA
       | that they were not supposed to right?
        
         | lmkg wrote:
         | It depends on the jurisdiction and law, but a "data breach" is
         | when data is accessed by a party who is not authorized, or who
         | should not be authorized. It's not just hackers. Sending data
         | to the wrong recipient is a form of data breach. Under some
         | definitions, sending data to the intended recipient without
         | appropriate safeguard is a form of data breach.
         | 
         | In this case, health care data covered by HIPAA was sent to a
         | party without a legal contract that extends HIPAA to the
         | receiving party. By law, that's a data breach.
         | 
         | Under some legal definitions, "data breach" includes not just
         | breakdowns of confidentiality, but also of availability and/or
         | integrity. So a company deleting your data by accident would be
         | considered a data breach, even though it's being accessed by
         | _fewer_ parties than intended. This can be important: imagine a
         | bank or credit agency losing some or all of the data about you,
         | this would materially impact your ability to do business in the
         | modern world.
        
         | paxys wrote:
         | Well it is a data breach. Self inflicted, sure, but still a
         | breach.
        
       | Animats wrote:
       | _" Blue Shield severed the connection between Google Analytics
       | and Google Ads on its websites in January 2024."_
       | 
       | They're lying.
       | 
       | Look at the page source for the announcement of the data breach.
       | Use of both Google Tag Manager and Google Analytics.
       | <!-- Google tag (gtag.js) -->           <script
       | type="text/javascript"
       | src="/static/js/jquery.cookie.js"></script>           <script
       | async src="https://www.googletagmanager.com/gtag/js?id=G-KTK4E56V
       | DB"></script>           <script>
       | 
       | ...                     <script>                    (function(i,s
       | ,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){
       | (i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new
       | Date();a=s.createElement(o),                 m=s.getElementsByTag
       | Name(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)
       | })(window,document,'script','//www.google-
       | analytics.com/analytics.js','ga');                  var
       | check_site_id = 347;                  var social_patterns =
       | ['facebook.com/share','twitter.com/share','linkedin.com/share',
       | 'pinterest.com/share','mailto:?subject'];
       | 
       | ...
        
         | gundmc wrote:
         | I'm pretty sure you can use Google analytics without sending
         | the data to Google Ads? I'm not sure why they would lie about
         | correcting the issue.
        
         | darknavi wrote:
         | Their News subdomain stack might be completely different than
         | their patient portals.
        
           | kube-system wrote:
           | They almost certainly are entirely different tech stacks, and
           | likely not even developed by the same organizations. If you
           | poke around in the source a bit you can find clear evidence
           | that the news site is probably developed by a third party PR
           | firm, who wouldn't typically have anything to do with a
           | patient portal.
        
         | Animats wrote:
         | Saved copy of page, in case it is changed:
         | https://archive.is/GB8Ty
        
         | wormius wrote:
         | Went to look at my provider's service portal to see if there
         | was any google analytics. Nothing showed when searching google,
         | but...
         | 
         | "...Settings.WebAnalyticsEnabled = 'False';"
         | 
         | is set - thank goodness my medical provider's doing it right.
         | (at least on this portion, I'm not digging through all the code
         | or whatever)
        
       | userbinator wrote:
       | This is a good reminder to add these to your HOSTS file if you
       | don't already have them blocked (which I have done for over 2
       | decades now):                   0.0.0.0 analytics.google.com
       | 0.0.0.0 google-analytics.com         0.0.0.0 ssl.google-
       | analytics.com         0.0.0.0 www.google-analytics.com
       | 0.0.0.0 www.googletagservices.com
        
         | Scoundreller wrote:
         | You've unlocked a memory:
         | 
         | Back in the day I ran a giant hosts file for the same reason. I
         | guess dumb OSs didn't index HOSTS files well (didn't expect
         | them to be very large?) and it slowed things down noticeably.
         | 
         | Apparently it's still a thing and the workaround doesn't work
         | either:
         | 
         | > This is still relevant with Windows 11; adding a 20MB hosts
         | file (to block every known malicious IP) makes a 24-core i7 /w
         | nvme take 4+ hours to boot. Worse, DNS cache is now system-
         | controlled and cannot be stopped. Do not attempt!
         | 
         | https://serverfault.com/questions/322747/can-a-long-etc-host...
        
           | userbinator wrote:
           | That sounds like the result of an "accidentally quadratic" or
           | worse algorithm. Interesting that they didn't bother to fix
           | it after all these years; perhaps they knew what those with
           | large HOSTS files were using them for, and (especially now
           | with Win11) were against it.
        
       ___________________________________________________________________
       (page generated 2025-04-10 23:01 UTC)