Kaiser Permanente Data Breach Affects Millions
US health conglomerate Kaiser advised that personal data from millions of its current and past members has been inadvertently shared with third-party advertisers.
A Kaiser representative said “certain online technologies,” previously installed on its websites and mobile applications, “may have transmitted personal information to third-party vendors.” Those third-party vendors included Google, Microsoft, and X.
The exposed data includes the member’s names, IP addresses, and how members “interacted with and navigated through the website and mobile applications,” as well as “search terms used” when interacting with the health encyclopedia.
Since the breach, Kaiser has updated its code to remove the tracking software on its website and mobile apps.
Kaiser sent a notification to the US government on April 12 to advise that the security leak affected 13.4 million residents. The Health and Human Services (HHS) Department requires all entities covered by the Health Insurance Portability and Accountability Act (HIPAA) to report all health-related data breaches. According to the HHS website, this breach represents the largest health-related data breach in 2024.
Kaiser said it will be contacting all the members, past and present, to notify them of their compromised personal information. As of the date of the notification, Kaiser advised that it was not aware of any misuse of the exposed personal data.
Kaiser is not the only healthcare organization impacted by the use of online tracking, which is code embedded in web pages and mobile apps that allow companies to collect data about users’ online activity. Telehealth companies Cerebral, Monument, and Tempest have also ceased using this type of code to avoid sharing customer data.
Oakland-based Kaiser International Health Group Inc. is one of the leading US health care providers that caters to individual, family, and group accounts, with a specific focus on the care of individuals during their retirement years. At the end of 2023, Kaiser reportedly had 12.5 million active users.