UK markets closed
  • FTSE 100

    +8.52 (+0.11%)
  • FTSE 250

    -248.86 (-1.24%)
  • AIM

    -4.39 (-0.47%)

    -0.0048 (-0.41%)

    -0.0117 (-0.98%)

    -1,732.97 (-8.74%)
  • CMC Crypto 200

    -33.25 (-6.14%)
  • S&P 500

    -62.27 (-1.45%)
  • DOW

    -356.30 (-1.05%)

    +0.03 (+0.03%)

    -9.70 (-0.55%)
  • NIKKEI 225

    -11.77 (-0.04%)

    +9.12 (+0.05%)
  • DAX

    -152.89 (-1.12%)
  • CAC 40

    -61.57 (-0.94%)

Meta gathered people’s private medical data to show them ads on Facebook, lawsuit alleges

  • Oops!
    Something went wrong.
    Please try again later.
·2-min read
In this article:
  • Oops!
    Something went wrong.
    Please try again later.
 (Getty Images)
(Getty Images)

Meta is being sued for collecting data from US hospitals without users’ knowledge, two new lawsuits allege.

The claims focus on the Meta Pixel, which sends Facebook data whenever they click a button.

A recent report from The Markup found that the pixel was used on 33 of the top 100 hospitals in America. The data that is sent to Facebook includes an IP address, meaning that the user or their household could be identified.

At seven of these 33 hospitals, the pixel was installed on password-protected patient portals – sharing information including the names of patients’ medications, descriptions of their allergic reactions, and details about their upcoming doctor’s appointments. Some hospitals removed the pixels after The Markup’s report.

One lawsuit alleges that medical information was sent to Facebook via the pixel from the University of California San Francisco and Dignity Health patient portals, which resulted in her seeing adverts for her heart and knee conditions – some of which had no scientific support.

United States medical privacy law states that healthcare organisations need the patient’s consent to share identifiable information to outside groups, with the lawsuits alleging that Meta is knowingly not enforcing these policies.

Meta did not respond to The Independent’s request for comment before time of publication and did not answer questions sent by The Markup.

Instead, a spokesperson paraphrased the company’s sensitive health data policy: “If Meta’s signals filtering systems detect that a business is sending potentially sensitive health data from their app or website through their use of Meta Business Tools, which in some cases can happen in error, that potentially sensitive data will be removed before it can be stored in our ads systems”.

“I am deeply troubled by what [the hospitals] are doing with the capture of their data and the sharing of it,” said David Holtzman, a health privacy consultant who previously served as a senior privacy adviser in the US Department of Health and Human Services’ Office for Civil Rights, which enforces HIPAA, told The Markup.

“I cannot say [sharing this data] is for certain a HIPAA violation. It is quite likely a HIPAA violation.”

The lawsuits have not yet been certified as class actions, which a judge will need to do before they cand develop, but if they do, they could bring damages on behalf of all users whose medical providers have used the pixel.

Our goal is to create a safe and engaging place for users to connect over interests and passions. In order to improve our community experience, we are temporarily suspending article commenting