[HN Gopher] Blue Shield Data Breach (Google Ads)
___________________________________________________________________
Blue Shield Data Breach (Google Ads)
Author : bix6
Score : 60 points
Date : 2025-04-10 16:09 UTC (6 hours ago)
(HTM) web link (news.blueshieldca.com)
(TXT) w3m dump (news.blueshieldca.com)
| bix6 wrote:
| Disappointing behavior to say the least.
|
| "On February 11, 2025, Blue Shield discovered that, between April
| 2021 and January 2024, Google Analytics was configured in a way
| that allowed certain member data to be shared with Google's
| advertising product, Google Ads, that likely included protected
| health information. Google may have used this data to conduct
| focused ad campaigns back to those individual members. We want to
| reassure our members that no bad actor was involved, and, to our
| knowledge, Google has not used the information for any purpose
| other than these ads or shared the protected information with
| anyone."
| accrual wrote:
| I wonder what, if any, HIPAA fines will apply to Blue Shield if
| they're found to have inadvertently exposed PHI.
|
| https://www.hipaajournal.com/hipaa-violation-fines/
| chimeracoder wrote:
| > I wonder what, if any, HIPAA fines will apply to Blue
| Shield if they're found to have inadvertently exposed PHI.
|
| Well, they _have_ inadvertently exposed PHI - this press
| release literally admits that they did.
|
| In terms of what fines will apply, well, the annual cap for
| violations is about $2 million per calendar year, but I doubt
| they'll have to pay even that.
| 01HNNWZ0MV43FF wrote:
| "No bad actor was involved"
|
| I see two but whatever
| anon84873628 wrote:
| I'm sure Google doesn't want customers doing this dumb stuff.
| So I'd also expect by this point they would be automatically
| profiling the incoming data to throw up warnings and safe
| guards. Maybe there is a perverse incentive where doing that
| only increases their liability in these situations.
| wrs wrote:
| Putting a third party analytics tool on a page containing PHI
| is an incredibly dangerous thing to do. It's really surprising
| the developers could get that through a security review.
| donohoe wrote:
| What security review?
| stackskipton wrote:
| As someone who has worked in this field, I'm not. Marketing
| is generally exempt from massive legal review as they hand
| wave away "We don't deal with HIPPA data" and developers just
| wanting marketing to go away, dropped the Javascript block
| into files that were used for a ton of products including
| HIPAA containing ones.
|
| EDIT: Most of these places are just feature factories with
| offshore developers who are very unlikely to raise concerns.
| chimeracoder wrote:
| > As someone who has worked in this field, I'm not.
| Marketing is generally exempt from massive legal review as
| they hand wave away "We don't deal with HIPPA data" and
| developers just wanting marketing to go away, dropped the
| Javascript block into files that were used for a ton of
| products including HIPAA containing ones.
|
| I don't know why you're being downvoted, because this is
| unfortunately quite accurate. You'd be shocked how often
| this happens, even for tools they think are totally secure
| and "HIPAA-compliant".
|
| > EDIT: Most of these places are just feature factories
| with offshore developers who are very unlikely to raise
| concerns.
|
| I don't think there's any meaningful difference based on
| where the developers are located. The developers aren't the
| ones making the decisions. Usually the issue is that the
| _higher-ups_ want it, which is why practices can continue
| even after concerns are raised.
| gausswho wrote:
| I worked at an org that give Google Tag Manager access to
| marketing, effectively as means of bypassing engineering
| to try whatever spyslime of the month they could paste
| into a box.
| unyttigfjelltol wrote:
| I would turn that around to be an inference that there was no
| effective security review....
| AlotOfReading wrote:
| Kaiser was hit with a class action for exactly the same issue
| last year: https://news.bloomberglaw.com/litigation/patients-
| advance-ka...
|
| GoodRx, BetterHelp, and dozens of others have received
| notices that this is an issue. The federal OCR even published
| a bulletin about this 3 years ago.
|
| You'd think that any one of these would have triggered
| internal reviews and discovered this issue for all the
| others, but that's much too high a bar to expect in
| healthcare.
| knowitnone wrote:
| Good. Hope Blue Shield gets the same treatment but they'll
| just pass the costs to their customers
| ajross wrote:
| It's only surprising when you phrase it like that. Real bugs
| are interactions. I mean, sure, if you're asked to review a
| pull request like "patient_info: Use google to track MRI
| data", it's a no brainer.
|
| But no doubt the analytics blurb was stuffed into a generic
| "top_level_page" generator or whatever. And it happens that
| the PHI wasn't firewalled by design, and pulled it in by
| default. Or it was firewalled, but then someone forgot and
| migrated the "patient_info_page" templates to a generic
| framework, etc...
|
| Security is really, really hard. And one of the worst
| responses to a mistake like this is to tut-tut about how
| obvious a mistake and how easy to avoid it was. Believing
| that secure software is a matter of "not making mistakes"
| makes you _more_ likely to write such bugs and not less,
| because you won 't take the time to establish clear
| boundaries from the start.
| int_19h wrote:
| Thing is, that's exactly what security and privacy reviews
| are for.
|
| If there was no review, that's negligence.
|
| If there was a review, one of the first questions that
| would be asked is, "what kind of tracking or telemetry do
| you have"? And there are tools that will scan code and flag
| things like that for you that large companies normally use.
| olyjohn wrote:
| Are you fucking kidding me? You get interrupted reading this shit
| by a pop up asking you for your information?
| userbinator wrote:
| I guess that's what they mean by the "This site requires
| Javascript in order to function properly" banner I get at the
| top. The article is readable without JS anyway.
| Ancapistani wrote:
| The email subject for this notification was "Blue Shield of
| California Privacy Notification."
|
| It sounds like a fairly minor concern, but I find it quite
| distasteful that the email subject doesn't indicate that a breach
| occurred.
| knowitnone wrote:
| the hope is people delete it because it's just a "privacy
| notification"
| kmeisthax wrote:
| Related pet peeve: if the price of something goes down, it's a
| price drop, but when it goes up, it's a price _change_.
|
| Can we coin a term for this weasel-y headline writing?
| josefritzishere wrote:
| There should be legal penalties for companies whose negligence
| leads to data breaches. Consumers really have no recourse here
| and even CCPA and HIPAA fines are exceedingly rare.
| wormius wrote:
| I'm sure those affected will get a 3.00 check and the lawyers
| bringing suit will make a chunk of change. (curious if this
| will lead to a suit or what the laws are around that (e.g. can
| this be class action or will only known affected individuals be
| allowed to seek redress?)
| rdtsc wrote:
| > Google may have used this data to conduct focused ad campaigns
| back to those individual members. We want to reassure our members
| that no bad actor was involved
|
| Well that's a contradiction. I don't know about anyone else, but
| I don't view Google as a "good actor".
| anon84873628 wrote:
| This statement is using lots of passive voice to try and
| deflect and confuse.
|
| Blue Shield configured GA to send data they weren't supposed
| to. GA may have _automatically_ used that data to do the things
| GA does. No human at Google would have ever interacted with
| this data, chosen how it was used, known it was there, or
| really given a shit (besides the risk of liability and not
| wanting customers to be dumb and do exactly this).
| mjevans wrote:
| In this case, the "Bad Actor" was Blue Shield, for designing
| their system to send PII / PHI to places it should never have
| gone.
| rdtsc wrote:
| Of course they voluntarily handed it to Google knowing what
| Google does. But Google is not a good actor either. Just
| because "they do this to any data they get their hands on"
| doesn't make it right.
| neilv wrote:
| > _between April 2021 and January 2024, Google Analytics was
| configured in a way that allowed certain member data to be shared
| with Google's advertising product, Google Ads, that likely
| included protected health information._
|
| I see so many medical and government sites that _really shouldn
| 't_ be running third-party trackers. Yet almost every single time
| I check, they are.
|
| It's negligence/incompetence/reckless, criminally so, in some
| cases.
|
| Given the inability of almost anyone in our field to build or
| operate a competently secure system, and the practices that go
| out of their way to gratuitously make the situation even worse--
| we really just need to smack our entire field upside the head,
| repeatedly, until we stop churning out shit while strutting about
| how smart we are.
|
| "AI" development tools (i.e., making humans stupider, through the
| power of plagiarism, to churn more BS at a faster rate) isn't
| going to solve the root problems of grossly misaligned incentives
| and culture.
| wormius wrote:
| Gotta love the passive voice used, too.
| neilv wrote:
| > _We understand receiving a notice such as this can create
| concern, and we regret that member personal information may have
| been shared without authorization._
|
| Vague passive voice, FTW.
|
| One way to start to fix the pattern and practice of gross
| negligence in our field is for Blue Shield CA to get stuck with
| HIPAA violation fines for each record leaked.
|
| If Blue Shield CA claims they're not competent to know which
| records were leaked, assume it's all of the records.
| ceejayoz wrote:
| I've seen this sort of wording called "exonerative tense" when
| describing police conduct.
| phkahler wrote:
| This isn't a "data breach" is it? Blue Shield shared data with GA
| that they were not supposed to right?
| lmkg wrote:
| It depends on the jurisdiction and law, but a "data breach" is
| when data is accessed by a party who is not authorized, or who
| should not be authorized. It's not just hackers. Sending data
| to the wrong recipient is a form of data breach. Under some
| definitions, sending data to the intended recipient without
| appropriate safeguard is a form of data breach.
|
| In this case, health care data covered by HIPAA was sent to a
| party without a legal contract that extends HIPAA to the
| receiving party. By law, that's a data breach.
|
| Under some legal definitions, "data breach" includes not just
| breakdowns of confidentiality, but also of availability and/or
| integrity. So a company deleting your data by accident would be
| considered a data breach, even though it's being accessed by
| _fewer_ parties than intended. This can be important: imagine a
| bank or credit agency losing some or all of the data about you,
| this would materially impact your ability to do business in the
| modern world.
| paxys wrote:
| Well it is a data breach. Self inflicted, sure, but still a
| breach.
| Animats wrote:
| _" Blue Shield severed the connection between Google Analytics
| and Google Ads on its websites in January 2024."_
|
| They're lying.
|
| Look at the page source for the announcement of the data breach.
| Use of both Google Tag Manager and Google Analytics.
| <!-- Google tag (gtag.js) --> <script
| type="text/javascript"
| src="/static/js/jquery.cookie.js"></script> <script
| async src="https://www.googletagmanager.com/gtag/js?id=G-KTK4E56V
| DB"></script> <script>
|
| ... <script> (function(i,s
| ,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){
| (i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new
| Date();a=s.createElement(o), m=s.getElementsByTag
| Name(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)
| })(window,document,'script','//www.google-
| analytics.com/analytics.js','ga'); var
| check_site_id = 347; var social_patterns =
| ['facebook.com/share','twitter.com/share','linkedin.com/share',
| 'pinterest.com/share','mailto:?subject'];
|
| ...
| gundmc wrote:
| I'm pretty sure you can use Google analytics without sending
| the data to Google Ads? I'm not sure why they would lie about
| correcting the issue.
| darknavi wrote:
| Their News subdomain stack might be completely different than
| their patient portals.
| kube-system wrote:
| They almost certainly are entirely different tech stacks, and
| likely not even developed by the same organizations. If you
| poke around in the source a bit you can find clear evidence
| that the news site is probably developed by a third party PR
| firm, who wouldn't typically have anything to do with a
| patient portal.
| Animats wrote:
| Saved copy of page, in case it is changed:
| https://archive.is/GB8Ty
| wormius wrote:
| Went to look at my provider's service portal to see if there
| was any google analytics. Nothing showed when searching google,
| but...
|
| "...Settings.WebAnalyticsEnabled = 'False';"
|
| is set - thank goodness my medical provider's doing it right.
| (at least on this portion, I'm not digging through all the code
| or whatever)
| userbinator wrote:
| This is a good reminder to add these to your HOSTS file if you
| don't already have them blocked (which I have done for over 2
| decades now): 0.0.0.0 analytics.google.com
| 0.0.0.0 google-analytics.com 0.0.0.0 ssl.google-
| analytics.com 0.0.0.0 www.google-analytics.com
| 0.0.0.0 www.googletagservices.com
| Scoundreller wrote:
| You've unlocked a memory:
|
| Back in the day I ran a giant hosts file for the same reason. I
| guess dumb OSs didn't index HOSTS files well (didn't expect
| them to be very large?) and it slowed things down noticeably.
|
| Apparently it's still a thing and the workaround doesn't work
| either:
|
| > This is still relevant with Windows 11; adding a 20MB hosts
| file (to block every known malicious IP) makes a 24-core i7 /w
| nvme take 4+ hours to boot. Worse, DNS cache is now system-
| controlled and cannot be stopped. Do not attempt!
|
| https://serverfault.com/questions/322747/can-a-long-etc-host...
| userbinator wrote:
| That sounds like the result of an "accidentally quadratic" or
| worse algorithm. Interesting that they didn't bother to fix
| it after all these years; perhaps they knew what those with
| large HOSTS files were using them for, and (especially now
| with Win11) were against it.
___________________________________________________________________
(page generated 2025-04-10 23:01 UTC)