{"id":336222,"date":"2025-12-08T03:30:34","date_gmt":"2025-12-08T03:30:34","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/336222\/"},"modified":"2025-12-08T03:30:34","modified_gmt":"2025-12-08T03:30:34","slug":"kaiser-permanente-to-pay-46m-for-patient-data-breach","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/336222\/","title":{"rendered":"Kaiser Permanente to Pay $46M for Patient Data Breach"},"content":{"rendered":"<p>The health system is settling a class action lawsuit after finding that data-tracking technology used on its websites and apps could have shared data with companies like Microsoft and Google.<\/p>\n<p><a href=\"https:\/\/healthy.kaiserpermanente.org\/brand\/el?promo_id=201&amp;WT.mc_id=201&amp;WT.seg_1=Google-zzzELzzz_CNS-c--e-kaiser%20permanente-Cj0KCQiA_8TJBhDNARIsAPX5qxSszovWPsfebJDJ1NxZfuRdQ762zVLFXQVGF9rbGppydO3IY-UKDEUaAvvUEALw_wcB&amp;cid=ca-oth|re-mas|ch-ps|pl-go|ta-demo|au-64|bo-conv|&amp;ad_id=Cj0KCQiA_8TJBhDNARIsAPX5qxSszovWPsfebJDJ1NxZfuRdQ762zVLFXQVGF9rbGppydO3IY-UKDEUaAvvUEALw_wcB&amp;psd=kc-|mt-e|kn-kaiser%20permanente|ki-kwd-28786830|ci-22937880936|ski-28786830|sci-22937880936|adv-8287244582&amp;gclsrc=aw.ds&amp;gad_source=1&amp;gad_campaignid=22937880936&amp;gbraid=0AAAAA9mVzvBGqPhcnZHHYRKLR7DAxLRrG&amp;gclid=Cj0KCQiA_8TJBhDNARIsAPX5qxSszovWPsfebJDJ1NxZfuRdQ762zVLFXQVGF9rbGppydO3IY-UKDEUaAvvUEALw_wcB\" target=\"_blank\" rel=\"nofollow noopener\">Kaiser Permanente<\/a> is paying a hefty price for gathering patient access data on its websites and apps.<\/p>\n<p>The Oakland-based health system will pay at least $46 million and as much as $47.5 million to settle a class action lawsuit filed by several patients who said their information was caught up in KP\u2019s consumer-tracking programs, which can share data with Microsoft, Google, X (Twitter) and Adobe.<\/p>\n<p>The practice is common with consumer-facing companies who want to know who\u2019s accessing their sites and why, and it\u2019s becoming more sophisticated as the technology evolves to enable companies to personalize those access points based on a user\u2019s preferences. <a href=\"https:\/\/www.healthaffairs.org\/doi\/abs\/10.1377\/hlthaff.2022.01205\" target=\"_blank\" rel=\"nofollow noopener\">According to a 2023 study published in Health Affairs<\/a>, almost every health system surveyed \u2013 99% &#8212; uses data tracking tools.<\/p>\n<p>In healthcare, however, those user preferences may include personal health information, putting patient privacy at risk and leaving hospitals liable to legal action under <a href=\"https:\/\/www.hhs.gov\/hipaa\/index.html\" target=\"_blank\" rel=\"nofollow noopener\">HIPAA<\/a>.<\/p>\n<p>The Health Insurance Portability and Accountability Act (HIPAA) doesn\u2019t specifically permit data transfers like this, so healthcare organizations either need to secure patient consent or a business associate agreement with the third-party vendors that receive that data. \u00a0<\/p>\n<p>KP isn\u2019t the first health system to face charges over this. In 2023, <a href=\"https:\/\/www.hipaajournal.com\/new-york-presbyterian-pixel-settlement\/\" target=\"_blank\" rel=\"nofollow noopener\">New York Presbyterian Hospital settled a complaint<\/a> filed by the New York Attorney General and paid a $300,000 fine for exposing patient data through its use of data tracking technologies.<\/p>\n<p>Federal regulators tried to get a handle on this a few years ago. In 2022, the Health and Human Services Department\u2019s (HHS) Office of Civil Rights <a href=\"https:\/\/www.healthleadersmedia.com\/technology\/hhs-drops-plan-restrict-hospital-use-data-tracking-tech\" target=\"_blank\" rel=\"nofollow noopener\">issued guidance that would have prohibited organizations covered by HIPAA<\/a> from using \u201ctracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors or any other violations of HIPAA Rules.\u201d<\/p>\n<p>The American Hospital Association and several other groups\u00a0<a href=\"https:\/\/www.healthleadersmedia.com\/technology\/aha-sues-feds-over-hospital-use-data-tracking-technologies\" target=\"_blank\" rel=\"nofollow noopener\">filed suit against HHS in late 2023<\/a>, charging that the federal agency exceeded its statutory authority in preventing healthcare providers from collecting the IP addresses of people visiting public-facing websites. Last year, a federal district court in the Northern District of Texas ruled that the federal order \u201cwas\u00a0promulgated in clear excess of HHS\u2019s authority under HIPAA,\u201d\u00a0and HHS opted to drop the proposed rule.<\/p>\n<p>As it stands now, healthcare organizations can use data tracking technology \u2013 but not on any sites that require a log-in, such as a patient portal or app.<\/p>\n<p><a href=\"https:\/\/healthy.kaiserpermanente.org\/alerts\/p3\/privacy-matter\" target=\"_blank\" rel=\"nofollow noopener\">KP disclosed the data breach in May 2024<\/a>, announcing that as many as 13.4 million members had been affected. The organization said user information was put in a position to be accessed by third-party tracking companies through the KP website and mobile apps.<\/p>\n<p>\u201cOn October 25, 2023, Kaiser Permanente determined that certain online technologies (commonly known as cookies or pixels) installed on our websites and mobile applications may have transmitted personal information to our third-party vendors Google, Microsoft Bing, and X (Twitter) when members and patients accessed our websites or mobile applications,\u201d the organization said. \u201cThese technologies are sometimes used by organizations to understand how consumers interact with websites and mobile applications. We apologize that this incident occurred.\u201d<\/p>\n<p>\u201cThe information that may have been involved was limited to: IP address, name, information that could indicate you were signed into a Kaiser Permanente account or service, information showing how you interacted with and navigated through our website or mobile applications, and search terms used in the health encyclopedia,\u201d KP continued. \u201cDetailed information concerning Kaiser Permanente account credentials (username and password), Social Security numbers, financial account information and credit card numbers were not included in the information involved.\u201d<\/p>\n<p>KP said it removed the tracking technologies from its websites and took additional measures to safeguard those sites.<\/p>\n<p>KP officials denied the allegations in the lawsuit \u2013 namely, that protected health information was mishandled by the health system and that executives put that information at risk \u2013 but decided that settling the case with no admission of wrongdoing would be better than continuing to a trial.<\/p>\n<p><a href=\"https:\/\/www.hipaajournal.com\/kaiser-permanente-website-tracker-breach-affects-13-4-million-individuals\/\" target=\"_blank\" rel=\"nofollow noopener\">According to the HIPAA Journal<\/a>, lawsuits filed by patients named the Kaiser Foundation Health Plan, Kaiser Foundation Hospitals, and Kaiser Foundation Health Plan of Washington as defendants.<\/p>\n<p>The suits, which were consolidated into one lawsuit by the United States District Court in San Francisco, charged KP with violating the federal Electronic Communications Privacy Act, as well as negligence, common law invasion of privacy (intrusion upon seclusion), breach of implied contract, breach of express contract, and violations of many state laws, including the California Confidentiality of Medical Information Act, District of Columbia Consumer Protection Procedures Act, Maryland Wiretapping and Electronic Surveillance Act, Virginia Insurance Information and Privacy Protection Act, Washington Health Care Information Act, and many other state laws.<\/p>\n<p>According to the HIPAA Journal, the OCR and Federal Trade Commission (FTC) issued more than 130 warning letters to healthcare organizations in 2024 over potential HIPAA violations related to data tracking, and settled complaints with five companies: Cerebral, Monument, BetterHelp, GoodRx and Easy Healthcare (Premom).<\/p>\n","protected":false},"excerpt":{"rendered":"The health system is settling a class action lawsuit after finding that data-tracking technology used on its websites&hellip;\n","protected":false},"author":2,"featured_media":336223,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[59],"tags":[169689,2788,5401,39019,2420,97,252,253,3038,10791,22074,2932,6655,72985,10307,514,9107,7270,8620,74],"class_list":["post-336222","post","type-post","status-publish","format-standard","has-post-thumbnail","category-health-care","tag-back-end","tag-data","tag-data-breach","tag-digital-health","tag-government","tag-health","tag-health-care","tag-healthcare","tag-healthcare-access","tag-hhs","tag-hit","tag-lawsuit","tag-legal","tag-patient-experience","tag-patient-safety","tag-privacy","tag-regulation","tag-security","tag-strategy","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/336222","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=336222"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/336222\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/336223"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=336222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=336222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=336222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}