Blue Shield Shared Patient Health Data Via Google Ads

Blue Shield of California, a U.S. health insurance company, leaked sensitive health information to Google that belong to as many as 4.7 million members.

The data shared may have included medical claim dates and providers such as appointments with specific doctors for ailments ranging from cardiologists or oncologists, Blue Shield shared in a blog post.

Patient names, insurance plan details, city of residence and zip code, gender, family size, and Blue Shield-assigned account identifiers, as well as those responsible for payments were also included. Search queries and results for the "Find a Doctor" tool locator, plan type, and provider details also could have been shared.

The company began notifying members earlier this month after noticing in February that Google Analytics had been configured in a way that allowed certain member data to be shared with Google’s advertising product, Google Ads.

advertisement

advertisement

The breach occurred between April 2021 and January 2024, and it likely included protected health information.

Google also may have used this data to conduct focused ad campaigns back to those individual members, the company said.

Despite all these details, Blue Shield is unable to confirm if any particular member’s information was affected, as a result of the complexity and scope of the disclosures.

“Like other health plans, Blue Shield historically used the third-party vendor service, Google Analytics, to internally track website usage of members who entered certain Blue Shield sites,” the company wrote in the post.

Blue Shield stopped using Google Analytics and Google Ads on its websites in January 2024, and initiated a review of its websites and security protocols to ensure that no other analytics tracking software and information could be found.

The company said there is no evidence of any leaks for other types of personal information, such as Social Security numbers, driver’s license numbers, or banking or credit card information.

1 comment about "Blue Shield Shared Patient Health Data Via Google Ads".
Check to receive email when comments are posted.
  1. L M from agency, April 30, 2025 at 2:47 p.m.

    And the sloppiness goes on, and on. Insurance= financial & data business. Yet they cannot do that correctly. Why would they need to track their own website page usage?  QA & user feedback, yes... but wasting time/money/security on tracking page visits... sounds like a vanity metric for a financial business!
    And they need to hire Data Scientists, not lower level entry clerks.  Breach occurred between April 2021 and January 2024... but not discovered til Feb 2025?  That is far too many YEARS of data sold on dark web and identy theft/financal frauds that the company is not taking active responsibility for.
    The info leaked is PLENTY to create identity theft.  Blue Shield does not have to be... SSN, DL or CC... why? Because the FEDERAL GOVT already leaked those!!!!  In Dec 2020 and then the  2024 National Public Data (NPD) breach, leak occurring from April 2024 onward.
    The Big Tech shiny objects (AI subvariations, metaverse, VR) are cute add ons... but they fail miserable at the MITIGATION of daily damage from enterprise platforms + social platforms.

Next story loading loading..