Blog, Reflectiz Blog
ECRI Warns Healthcare Providers About Third-Party Tags Like Meta Pixel | Reflectiz
ECRI Warns Healthcare Providers About Third-Party Tags Like Meta Pixel
**This article is originally published by our partner, Reflectiz. Click here to view the original article.

Data breach in the healthcare industry has become very common. Healthcare organizations seem to struggle with visibility and control over their third-party analytics tools like Meta pixel.
Meta pixel is a small piece of code placed on a business’ website to measure the effectiveness of advertising. However, working behind the scenes, the data that Meta pixel collects has come under severe scrutiny. Patient-safety-focused nonprofit ECRI has alerted healthcare organizations and hospitals to reduce the threat.
Who has been impacted by this Meta pixel data breach?
Unlike other cyberattacks that often rely on cybercriminals launching a targeted threat against a business or a supply chain partner, the risks of third-party tags are much broader.
A great representation of this is a study completed by The Markup, which tested the websites of the top 100 hospitals in the United States. In 33% of cases, Meta pixel was found to be sending a packet of data to Facebook whenever a doctor’s appointment was scheduled online, data that included the user’s IP address. The Markup found that Facebook was being given sensitive information inside this data packet, including the search terms related to the specific reason behind making the appointment and even the doctor’s name.
Inside seven disparate password-protected patient portals, Meta pixel was also found to send Personal Healthcare Information (PHI), including the names of patients’ medications and their upcoming medical appointments. According to The Markup, regulators, data security experts, and privacy advocates have all agreed that these hospitals may have violated HIPAA due to the actions of the Meta pixel.
How are healthcare organizations held responsible?
Hospitals are already seeing the fallout from loose controls over third-party analytics tools like Meta pixel. Two class action lawsuits have recently been filed on behalf of those who had PHI disclosed without their consent due to Meta pixel. Advocate Aurora Health has said the PHI of up to 3 million patients might have been told to Facebook, and WakeMed Health and Hospitals confirmed around 495,000 patients had been impacted via the MyChart patient portal.
The reputational damage of this kind of breach has high risks, especially as we’re dealing with the healthcare sector. For example, exposed patient data could be used to tailor advertisements to specific Facebook users based on their healthcare records. It’s highly plausible that users could be encouraged to pursue less appropriate care or even buy unproven treatments over the web.
Of course, even if healthcare organizations do not know of the PHI breach, they could still be held responsible under HIPAA and face steep fines and legal action. Providers must understand their responsibilities to visualize and govern the third-party scripts and apps under their website roofs.
Chad Waters, the senior cybersecurity engineer at ECRI, commented, “It is important to understand that many of these tools are free because their revenue model is dependent on building profiles of Internet users… Hospitals should review usage policies and be cautious about where these tools are deployed.”
What can healthcare organizations do?
Hospitals and those who handle sensitive healthcare information have only one choice. They can’t remove all third-party analytics trackers and tags from their websites. It would make it impossible for them to benefit from essential digital interactions such as online appointment management, digital patient portals, and valuable information about user activities.
Instead, they need visibility and control over third-party scripts, apps, and tags that access patient information.
Here’s where Reflectiz comes in, providing an airtight solution for this growing problem and enabling the safe use of third-party apps.
Executed remotely with no installation required, Reflectiz provides a thorough inventory of all third and fourth-party applications on your website, allowing you to see:
- Who are your digital vendors? Perhaps some are unnecessary or legacy apps that should have been removed or altered.
- What are they doing? If any have access to PHI, so you can recognize the context of the risk level of each application, tag, or script.
- Where is the data being sent? Immediately be aware if any sensitive information is being sent to an unauthorized source without user consent.
Securing Your Online Presence
Keep your online businesses safe by mitigating security and privacy risks resulting from next generation third-party threats on your website, without adding a single line of code.
Free Reflectiz Information Kit
Get first-hand information and use cases to discover how Reflectiz can protect your website from advanced third party based attacks
Get Web Asset Free Assessment
Request a free non-intrusive security assessment of your website, and get a report with an overview of client-side security risks.






