• Academics at the University of Pennsylvania analyzed a nationally representative sample of 100 non-federal acute care hospitals – essentially traditional hospitals with emergency departments – and their findings were that 96 percent of their websites transmitted user data to third parties.
  • Not all sites had privacy policies and of those that did, only 56% disclosed specific third parties receiving data.
  • Google and Meta (through Facebook Pixel) were on nearly every site and received the most data. Adobe, Verizon, Oracle, Microsoft, Amazon also received data.
  • Common data shared included IP addresses, browser info, pages visited, referring site.
  • Sharing data poses privacy risks for visitors and legal/regulatory risks for hospitals if policies don’t comply with laws.
  • A class action lawsuit against Mass General Brigham and Dana-Farber resulted in an $18.4M settlement over sharing patient data.
  • Researcher calls for hospitals to collaborate with computer science departments to design more private websites. Also recommends privacy tools to block third party tracking.

But in the meantime, and in lieu of any federal data privacy law in the US, protecting personal information falls to the individual. And for that, Friedman recommends browser-based tools Ghostery and Privacy Badger, which identify and block transfers to third-party domains. “It impacts your browsing experience almost none,” he explained. “It’s free. And you will be shocked at how much tracking is actually happening, and how much data is actually flowing to third parties.”

Note: Although Friedman recommends Ghostery and Privacy Badger, uBlock Origin is generally considered a better privacy-enhancing browser extension. Additionally, there exist multiple approaches for adblocking and tracker blocking beyond the browser extension model.

  • @[email protected]
    link
    fedilink
    English
    38 months ago

    This is called “enumerating badness” and the findings here are both probably not that meaningful and based on a lot of assumptions.

    I am curious to see what data is being transmitted, but not a lot is actually revealed by this

    • @[email protected]
      link
      fedilink
      English
      28 months ago

      “Common data shared included IP addresses, browser info, pages visited, referring site.”

      • wagesj45
        link
        fedilink
        18 months ago

        So enough to cross reference with a bazillion other data-brokers online and absolutely pinpoint most people.