Telehealth startup Cerebral had a HIPAA-violating data breach

startup is Notoriously bad at keeping our data safe(opens in new tab)Cerebral — a telemedicine startup that gained popularity early in the coronavirus pandemic — shares the personal health information of more than 3.1 million U.S. users with advertisers and social media platforms such as Google, Meta, and TikTok. sharing.

and Disclosure first reported by TechCrunch(opens in new tab), Cerebral said it uses tracking technology provided by third parties such as Google, Meta and TikTok. It’s not uncommon for websites to use this type of tracking technology in advertising. It’s not uncommon for these practices to lead to data breaches and his HIPAA violations.

After reviewing its use of these technologies and data-sharing practices, Cerebral will not disclose certain information to some of these third parties that may be regulated as protected health information under HIPAA. Cerebrum does not allow Google, Meta, and TikTok to collect user information such as name, phone number, email address, date of birth, IP address, mental health self-assessment results, treatment, and other clinical information. You may have provided your personal information in error.

Related item:

Everything You Need to Know About the TikTok Ban in the US

“Upon learning of this issue, Cerebral will immediately disable, reconfigure, and/or remove tracking technology on Cerebral’s platform to prevent such disclosure in the future and to meet all HIPAA requirements. We have stopped or disabled data sharing with subcontractors who cannot.” cerebrum said in disclosure(opens in new tab)Additionally, we have strengthened our information security practices and technical review process to further reduce the risk of sharing such information in the future. “

Company notices to customers are not easy to find.you have to scroll to bottom of website(opens in new tab) It looks like this in small font: here(opens in new tab) For more information on the March 2023 HIPAA breach, see “Social media companies that currently have access to this data should remove it, even though the data resulting from Cerebral’s breach should be subject to the U.S. Health Privacy Act HIPAA.” No need to.

Cerebral was just one of nearly 50 telemedicine startups to share user data with advertising platforms last year, according to a joint study by STAT and The Markup.(opens in new tab).



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *