ReportWire

Tag: health care information

  • Mental health startup exposes the personal data of more than 3 million people | CNN Politics

    Mental health startup exposes the personal data of more than 3 million people | CNN Politics

    [ad_1]


    Washington
    CNN
     — 

    A mental health startup exposed the personal data of as many as 3.1 million people online. In some cases, possibly sensitive information on mental health treatment was leaked, according to a company statement and a Department of Health and Human services filing.

    Cerebral, a California-based firm that connects people suffering from anxiety and depression with mental health professionals via video calls, said it discovered the “inadvertent” data exposure more than three years after it started using “pixels” – a common method that companies and advertisers use to track user behavior for marketing purposes.

    The company determined in January that tracking pixels had been sharing client and user data to “third-party platforms” and “subcontractors” that it didn’t name, according to a privacy notice near the bottom of its website.

    Cerebral said it was unaware of any misuse of the protected health information that was disclosed. But privacy advocates have for years warned that such data troves can be used to aggressively market products at consumers and infringe on their privacy.

    Some of the data potentially exposed in the Cerebral breach includes answers to online “self-assessments” about mental health that Cerebral asks prospective clients to fill out. That can include questions on whether someone is experiencing panic attacks, abusing alcohol or has a personality disorder, CNN’s review of the online assessments found.

    Cerebral said in a statement to CNN on Friday that it was “committed to correcting historical errors and leading the industry in privacy standards moving forward.”

    Cerebral notified the Department of Health and Human Services (HHS), which said in a filing this month that the breach affects over 3.1 million users. The department investigates potential violations of the Health Insurance Portability and Accountability Act (HIPAA), a law that requires medical providers to safeguard patient data.

    Rachel Seeger, a spokesperson for the HHS Office for Civil Rights, said the office typically “does not comment on open or potential investigations.”

    Cerebral said in its public statement that it had disabled the tracking pixels on its platforms and stopped sharing data with subcontractors “not able to meet all HIPAA [Health Insurance Portability and Accountability Act] requirements.”

    “It is important to note that Cerebral never impermissibly transmitted clinician generated notes or clinician communications,” the company told CNN.

    Cerebral spokesperson Chris Savarese did not respond to emailed questions about which and how many platforms and contractors to which the company disclosed the client health information.

    Some analysts argue that the broader market for data tracking tools is out of control. A group of conservative Catholics has spent millions of dollars to buy mobile data that identified priests who used gay dating and hookup apps, the Washington Post reported this week.

    Andrea Downing, who has done extensive research on pixel tracking and privacy, said patients are often unaware of how much personal data health care startups collect and potentially transmit to other parties.

    “What is in the fine print or the details of how data is being shared for advertising is not apparent to us when we’re going through the trauma of a diagnosis and seeking knowledge,” said Downing, who is co-founder of Light Collective, a digital rights nonprofit.

    “The only thing that is incentivizing change right now is the threat of liability,” Downing told CNN.

    [ad_2]

    Source link

  • Fertility app fined $200,000 for leaking customer’s health data | CNN Business

    Fertility app fined $200,000 for leaking customer’s health data | CNN Business

    [ad_1]



    CNN
     — 

    The company behind a popular fertility app has agreed to pay $200,000 in federal and state fines after authorities alleged that it had shared users’ personal health information for years without their consent, including to Google and to two companies based in China.

    The app, known as Premom, will also be banned from sharing personal health information for advertising purposes and must ensure that the data it shared without users’ consent is deleted from third-party systems, according to the Federal Trade Commission, along with the attorneys general of Connecticut, the District of Columbia and Oregon.

    Wednesday’s proposed settlement targeting Premom highlights how regulators have stepped up their scrutiny of fertility trackers and health information in the wake of the US Supreme Court’s decision last year striking down federal protections for abortion.

    The sharing of personal data allegedly affected Premom’s hundreds of thousands of users from at least 2018 until 2020, and violated a federal regulation known as the Health Breach Notification Rule, according to an FTC complaint against Easy Healthcare, Premom’s parent company.

    Premom didn’t immediately respond to a request for comment.

    As part of the alleged violation, Premom collected and shared personally identifiable health information with Google and with a third-party marketing firm in violation of Premom’s own privacy policy, which had promised to share only “non-identifiable data” with others, according to the complaint.

    In addition, Premom allegedly shared location information and device identifiers — such as WiFi network names and hardware IDs — with two China-based data analytics companies, known as Jiguang and Umeng, according to the complaint. That information, the FTC alleged, “could be used to identify Premom’s users and disclose to third parties that these users were utilizing a fertility app,” according to an FTC complaint filed against Easy Healthcare, Premom’s parent company.

    Since the Supreme Court’s decision in Dobbs v. Jackson, a wave of anti-abortion legislation has raised the prospect that fertility apps, search engines and other technology platforms could be forced to hand over user data in potential prosecutions of abortion-seekers.

    “Now more than ever, with reproductive rights under attack across the country, it is essential that the privacy of healthcare decisions is vigorously protected,” said DC Attorney General Brian Schwalb in a statement. “My office will continue to make sure companies protect consumers’ personal information to protect against unlawful encroachment on access to effective reproductive healthcare.”

    Samuel Levine, director of the FTC’s consumer protection bureau, said the agency “will not tolerate health privacy abuses.”

    “Premom broke its promises and compromised consumers’ privacy,” Levine said in a statement. “We will vigorously enforce the Health Breach Notification Rule to defend consumer’s health data from exploitation.”

    [ad_2]

    Source link