{"id":3494,"date":"2025-04-24T10:05:48","date_gmt":"2025-04-24T10:05:48","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/04\/24\/blue-shield-leaked-health-info-of-4-7m-patients-with-google-ads\/"},"modified":"2025-04-24T10:05:48","modified_gmt":"2025-04-24T10:05:48","slug":"blue-shield-leaked-health-info-of-4-7m-patients-with-google-ads","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/04\/24\/blue-shield-leaked-health-info-of-4-7m-patients-with-google-ads\/","title":{"rendered":"Blue Shield Leaked Health Info of 4.7M patients with Google Ads"},"content":{"rendered":"<p>    Blue Shield Leaked Health Info of 4.7M patients with Google Ads<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Blue Shield of California has disclosed a significant data breach affecting 4.7 million members, representing the majority of its nearly 6 million customers.\u00a0<\/p>\n<p>The health insurance provider revealed that protected health information (PHI) was inadvertently shared with Google\u2019s advertising platforms over a nearly three-year period due to a misconfiguration of Google Analytics on the company\u2019s websites.<\/p>\n<p>This breach, spanning from April 2021 to January 2024, is among the largest healthcare data incidents of 2025.<\/p>\n<p>The <a href=\"https:\/\/news.blueshieldca.com\/notice-of-data-breach\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">company discovered<\/a> the privacy violation on February 11, 2025, when an internal review identified that Google Analytics had been improperly configured to share sensitive member data with Google Ads, potentially enabling targeted advertising campaigns directed at affected individuals.<\/p>\n<p>\u201cOn February 11, 2025, Blue Shield discovered that, between April 2021 and January 2024, Google Analytics was configured in a way that allowed certain member data to be shared with Google\u2019s advertising product, Google Ads, that likely included protected health information,\u201d the company stated in its notification.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Blue Shield Data Exposure<\/strong><\/h2>\n<p>The data potentially exposed includes:<\/p>\n<ul class=\"wp-block-list\">\n<li>Insurance plan name, type, and group number<\/li>\n<li>City, zip code, gender, and family size<\/li>\n<li>Blue Shield-assigned identifiers for online accounts<\/li>\n<li>Medical claim service dates and providers<\/li>\n<li>Patient names and financial responsibility<\/li>\n<li>\u201cFind a Doctor\u201d search criteria and results (location, plan, provider)<\/li>\n<\/ul>\n<p>Blue Shield emphasized that no Social Security numbers, driver\u2019s license numbers, or banking and credit card information were compromised in the breach.\u00a0<\/p>\n<p>The company also stated that \u201cno bad actor was involved\u201d and that Google has not shared the protected information with other parties.<\/p>\n<p>This incident raises serious concerns about HIPAA compliance in relation to online tracking technologies.<\/p>\n<p>Under HIPAA regulations, health organizations must implement robust safeguards for PHI and secure Business Associate Agreements (BAAs) with vendors handling such data.\u00a0<\/p>\n<p>Google explicitly states that Google Analytics is not <a href=\"https:\/\/cybersecuritynews.com\/best-vpn-for-hipaa\/\" target=\"_blank\" rel=\"noreferrer noopener\">HIPAA-compliant<\/a> and does not offer a BAA, making its use on pages handling PHI inherently risky.<\/p>\n<p>Security experts attribute such breaches to technical misconfigurations and inadequate visibility into data collection practices.\u00a0<\/p>\n<p>\u201cMany healthcare companies are caught unaware of potential data privacy problems because they either don\u2019t fully know what their analytics tools are collecting, or they don\u2019t know how to set up Google Analytics correctly,\u201d noted Ian Cohen, CEO of Lokker.<\/p>\n<p>Blue Shield severed the connection between Google Analytics and Google Ads in January 2024 and has initiated a comprehensive review of its websites and security protocols.\u00a0<\/p>\n<p>The company recommends that affected members remain vigilant by monitoring account statements and credit reports for suspicious activity.<\/p>\n<p>This marks Blue Shield\u2019s second significant IT incident in under a year. In 2024, the <a href=\"https:\/\/cybersecuritynews.com\/blacksuit-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener\">BlackSuit ransomware<\/a> group stole nearly one million health plan members\u2019 data following an attack on Connexure, Blue Shield\u2019s software solutions provider.<\/p>\n<p>According to the U.S. Department of Health\u2019s Office of Civil Rights, this breach is currently recognized as the most significant healthcare-related data breach of 2025.\u00a0<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Malware Trends Report Based on 15000 SOC Teams Incidents, Q1 2025 out!-&gt;\u00a0<a href=\"https:\/\/any.run\/cybersecurity-blog\/malware-trends-q1-2025\/?utm_source=cyber-threat-intel_linkedin&amp;utm_medium=post&amp;utm_campaign=q1&amp;utm_content=blog&amp;utm_term=150425\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get Your Free Copy<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/blue-shield-leaked-health-info\/\">Blue Shield Leaked Health Info of 4.7M patients with Google Ads<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/blue-shield-leaked-health-info\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Blue Shield Leaked Health Info of 4.7M patients with Google Ads Blue Shield of California has disclosed a significant data breach affecting 4.7 million members, representing the majority of its nearly 6 million customers.\u00a0 The health insurance provider revealed that protected health information (PHI) was inadvertently shared with Google\u2019s advertising platforms over a nearly three-year [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,946],"tags":[130],"class_list":["post-3494","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-beach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3494"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3494"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3494\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3494"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3494"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3494"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}