🚨 4.7 million health records leaked — not by hackers, but by a misconfigured analytics tool.
Blue Shield of California has disclosed a major data leak caused by a Google Analytics misconfiguration that exposed protected health information (PHI) to Google’s advertising platforms over a 33-month period.
The incident, now listed on the U.S. Department of Health and Human Services breach portal, impacted nearly 80% of the nonprofit health plan’s members across California.
What happened:
- Google Analytics was incorrectly set up on Blue Shield websites
- This allowed sensitive member data to be shared with Google Ads
- The information may have been used to run personalized ad campaigns targeting individual users
Exposed data includes:
- Insurance plan names, group numbers, and Blue Shield identifiers
- Patient names, medical claim dates, providers, and financial responsibility
- “Find a Doctor” search terms and results
- City, zip code, gender, and family size
No Social Security numbers or payment data were leaked, but the nature of the exposed PHI still raises serious concerns around patient profiling and targeted advertising.
Blue Shield has not offered identity theft protection or confirmed if affected users will receive direct notifications.
This is the second major incident in under a year. In 2024, nearly one million members were impacted by a ransomware attack via software vendor Connexure.
At @Efani, we believe data privacy lapses aren’t just technical failures — they’re trust failures. And when it comes to healthcare, every misstep can affect lives, not just log files.
#CyberSecurity #BlueShield #DataBreach