On February 11, 2025, Blue Shield discovered that, between April 2021 and January 2024, Google Analytics was configured in a way that allowed certain member data to be shared with Google’s advertising product, Google Ads, that likely included protected health information. Google may have used this data to conduct focused ad campaigns back to those individual members.

Blue Shield severed the connection between Google Analytics and Google Ads on its websites in January 2024.

What information was involved

  • Insurance plan name, type and group number;
  • city;
  • zip code;
  • gender;
  • family size;
  • Blue Shield assigned identifiers for members’ online accounts;
  • medical claim service date and service provider, patient name, and patient financial responsibility;
  • “Find a Doctor” search criteria and results (location, plan name and type, provider name and type).
  • stankmut@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    1
    ·
    edit-2
    9 hours ago

    The analytics would be for the web development team to see which pages/features are used. Usually a product manager uses that data for setting priorities on what gets worked on.

    • Tronn4@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      6
      ·
      9 hours ago

      SHUSH! 😄 We trying to burn this whole thing to the ground! Don’t come here with all that sense making talk! 🤣 /s