20 US State Health Exchanges Send Sensitive User Data to Meta and TikTok via Trackers
Nearly 20 US state health insurance exchanges have been transmitting sensitive user data — including race and citizenship status — to Meta, TikTok, and Google through standard advertising tracker and pixel implementations on exchange websites, without users' knowledge, according to Bloomberg. The data is classified as protected health information under HIPAA guidelines. The leakage occurs through analytics and ad attribution tooling added to government-operated web properties.
Why It Matters
High-severity privacy breach involving federally protected health data at the state government level signals systemic failure of PII governance in government web infrastructure — creating significant HIPAA compliance exposure and potential federal enforcement action across 20 state agencies.