Breach report
HealthcareKaiser Permanente
Kaiser's website tracking tools may have compromised data on 13 million customers
Kaiser Permanente told regulators that tracking code on its websites and apps had sent data about 13.4 million people, including health encyclopedia searches, to Google, Microsoft Bing and X.
Reported by The Record
Records exposed
13.4M
13.4 million members and patients
Scale vs. largest on file
- When
- 2024
- How they got in
- Third-party tracking pixels and code sharing data with advertisers
- Sector
- Healthcare
In April 2024, Kaiser Permanente, the California-based integrated health system and insurer, reported to the U.S. Department of Health and Human Services that personal information on about 13.4 million current and former members and patients may have been shared with outside technology companies. Unlike most healthcare breaches, no hacker was involved. The exposure came from tracking technologies that Kaiser itself had installed on its websites and mobile apps.
The code, commonly used to measure traffic and target advertising, transmitted information about how people used Kaiser's online services to third parties that Kaiser named as Google, Microsoft Bing and X, formerly Twitter. The data could include IP addresses, names, whether a user was signed in, how they navigated the site and app, and the terms they searched in Kaiser's online health encyclopedia. Kaiser said Social Security numbers, financial account details and credentials were not involved, and it said it had no evidence the information had been misused. Kaiser operates in eight states and the District of Columbia, and the notice covered people who used its public websites and mobile apps.
Kaiser said it had removed the trackers after an internal investigation and began mailing notices in May 2024. The disclosure came as regulators were cracking down on pixel tracking in healthcare: the HHS Office for Civil Rights had issued guidance warning hospitals and insurers that such tools can violate HIPAA, and the Federal Trade Commission had taken action against digital health companies over similar practices. Hospital groups challenged parts of the HHS guidance in court and won a partial ruling in 2024.
The consumer litigation proved costly. Class actions accused Kaiser of sharing health-related browsing data without consent, and in late 2025 a federal judge in California granted preliminary approval to a settlement of at least $46 million. Kaiser denied wrongdoing but agreed to settle.
The case is one of the largest examples of a breach created by routine marketing technology rather than criminal intrusion. It shows that for health organizations, sending even seemingly innocuous web analytics to advertisers can reveal sensitive facts, such as what conditions a patient is researching, and that regulators and courts increasingly treat that flow of data as a reportable privacy failure.