EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2024-kaiser-permanente-data-breach
101/430

File EL-0330HighResolvedData Breach / Third-Party Tracking / Privacy Violation

Kaiser Permanente Data Breach

Also filed as Kaiser Permanente Online Tracking Breach

Kaiser Permanente disclosed that third-party tracking pixels (Google, Microsoft Bing, Meta) embedded in its websites and mobile apps were transmitting patient data to tech companies without authorization, affecting 13.4 million individuals.

  • #healthcare
  • #pii
  • #medical-records
  • #online-tracking
  • #hipaa-violation
  • #third-party
  • #privacy
Notoriety8/10
Event
1 Apr 2024
Disclosed
26 Apr 2024
Target
Kaiser Permanente
Actor
Third-Party Tracking Vendors (Google, Microsoft Bing, Meta/X)
Scale
13.4M people
Status
Resolved

01Summary

In April 2024, Kaiser Permanente began notifying 13.4 million patients that their health data had been improperly shared with third-party advertisers through tracking pixels. The pixels embedded in Kaiser's websites and patient portal transmitted search terms, button clicks, provider names, and appointment details to Google, Microsoft, and Meta. This violated HIPAA privacy rules as patients had not consented to this data sharing. The breach resulted from Kaiser's implementation of online analytics tools that were not adequately configured to protect health information.

02Background

Kaiser Permanente is one of the largest healthcare providers in the United States, serving over 12 million members across 8 states and Washington DC.

03Key revelations

  1. 01Widespread use of tracking pixels on healthcare websites transmits PHI to advertisers
  2. 02Major healthcare provider lacked adequate privacy controls on third-party analytics
  3. 03HIPAA compliance gaps in digital analytics implementation

04Technical analysis

Kaiser's websites and patient portal contained JavaScript tracking pixels from Google Analytics, Microsoft Bing Ads, and Meta Pixel. These pixels captured URL parameters, search queries, button click text, and page titles which frequently contained health-related information such as medication names, appointment types, and provider names.

05Threat actor

This incident was not caused by a malicious hacking group but by the corporate practices of third-party advertising and analytics companies (Google, Meta, Microsoft) collecting health data through embedded tracking technologies without adequate healthcare privacy safeguards.

Aliases

  • Online Tracking Pixels

Attribution sources

  • Kaiser Permanente breach notification
  • HIPAA Journal
  • Class-action filings

06Victims and impact

Patient health information was transmitted to third-party advertising platforms for analytics and ad targeting. While no direct financial fraud occurred, the HIPAA violations exposed Kaiser to major regulatory fines and class-action litigation.

Evidence of breach

Kaiser conducted an internal investigation following reports about healthcare tracking pixel usage, confirming that protected health information was transmitted to third parties.

Countries affected

  • United States

07Data exposed

Data types

  • Patient Names
  • Search Terms
  • Button Click Text
  • Provider Names
  • Appointment Dates
  • Health Conditions (via search terms)
  • IP Addresses

08Financial damage

Kaiser faced potential HIPAA fines up to $1.5M+ and class-action settlement costs.

09Timeline

  1. 2024-01-01Tracking pixels transmitting data (estimated timeframe)
  2. 2024-04-12Kaiser identifies tracking pixel issue during internal review
  3. 2024-04-26Kaiser begins notifying 13.4M affected individuals
  4. 2024-04-26Class-action lawsuits filed
  5. 2024-06-01Kaiser completes remediation and pixel removal

10Reaction and fallout

Public reaction

Significant concern about healthcare privacy in the digital age. Many patients expressed anger that their most sensitive health information was shared without consent.

Political impact

Reinforced calls for stronger HIPAA enforcement and restrictions on third-party tracking in healthcare settings.

11Legal

Multiple class-action lawsuits filed. HHS Office for Civil Rights opened investigation into HIPAA violations.

Civil lawsuits

  • Multiple class-action lawsuits for HIPAA violations and privacy breach

12Aftermath

Policy changes

  • Kaiser removed tracking pixels from patient-facing portals

Regulatory changes

  • HHS issued updated guidance on third-party tracking technologies in healthcare

Security improvements

  • Removal of third-party analytics from patient portals
  • Enhanced privacy review processes for website technologies

13Significance and legacy

Significance

The Kaiser breach represented one of the largest health data privacy violations in US history and highlighted the systemic risk of third-party tracking pixels on healthcare websites.

Legacy

Led to industry-wide reassessment of tracking pixel usage in healthcare and contributed to HHS issuing clearer guidance on HIPAA compliance for web analytics.

14Disclosure and media

Authentication
Kaiser Permanente official breach notification to HHS

Publishing organisations

  • HIPAA Journal
  • Kaiser Health News
  • Reuters
  • The Verge

15Related files

Related events

  • 2024-change-healthcare-attack

16Field notes

  1. 01The tracking pixels were originally implemented for legitimate analytics purposes but were not configured to filter out health information.
  2. 02This was one of several major healthcare tracking pixel incidents in 2024 that led to HHS issuing new guidance.

17Resolution

Kaiser removed or reconfigured tracking pixels across all patient-facing digital properties and implemented enhanced privacy controls.

18Sources

Official documents

  • Kaiser Permanente breach notification letter
  • HHS OCR investigation filing

References

  1. [1]HIPAA Journal
  2. [2]HHS OCR
  3. [3]Kaiser Permanente official notifications
Fact sheetEL-0330

Dates

Event
1 Apr 2024
Started
1 Jan 2024
Ended
15 Apr 2024
Duration
106 days
Discovered
12 Apr 2024
Disclosed
26 Apr 2024
Resolved
1 Jun 2024
Ongoing
No

Target

Organisation
Kaiser Foundation Health Plan, Inc.
Type
Healthcare Provider
Sector
Healthcare
Country
United States

Actor

Name
Third-Party Tracking Vendors (Google, Microsoft Bing, Meta/X)
Type
Corporate Entity
Nationality
United States
Motivation
Collection of user data for advertising and analytics
Attribution
Confirmed
Status
Active
Arrested
No
Convicted
No

Data

People
13,400,000
Sensitivity
Highly Sensitive
Published
No
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.