respect teamwork conversation scale security like value security-breach question delivery-truck dog accident folder slippery wheelchair Lifted Logic Web Design in Kansas City clock location phone play chevron-down chevron-left chevron-right chevron-up facebook checkbox checkbox-checked radio radio-selected instagram google plus pinterest twitter youtube send linkedin computer phone-call play-button quote-end quote-start pin call-answer envelope clock fax-machine right-arrow left-arrow mail-envelope-outlined

1.3 million patients notified of Novant data breach

Health care breaches are becoming more common.  McShane & Brady is committed to holding those responsible accountable for their actions.  If you have received notification of a breach, please call our office at 816-888-8010 or fill out our online questionnaire for a 100% free case evaluation.

From the Winston Salem Journal August 14th, 2022:

Certain Novant Health Inc. patients are being notified that their protected health information may have improperly disclosed through a tracking tool linked to Facebook as part of a marketing campaign that began in May 2020.

Novant did not disclose Friday how many patients were affected by the pixel tracking, but said it has mailed 1.3 million notification letters.

Novant said the tracking involved the use of a Facebook-related pixel, which was “configured incorrectly and may have allowed certain private information to be transmitted to (Facebook parent company) Meta from the Novant Health website and MyChart portal.”

The patient information disclosure involves:  Patient’s demographic information, such as email address, phone number, computer IP address and contact information entered into emergency contacts or advanced care planning,  patient’s demographic information, such as email address, phone number, computer IP address and contact information entered into emergency contacts or advanced care planning.

Novant said the disclosure did not affect patients’ Social Security numbers or other financial information “unless it was typed into a free text box by the user.”

Novant said among patients receiving the notification letter will be patients of independent physicians and facilities who use MyChart.

The system said the letter is part of an outreach effort — “to be as transparent as possible” — about the disclosure. “The letter sent to each patient will specifically state whether such financial information may have been involved.”

Novant said patients at New Hanover Regional Medical Center in the Wilmington market were not affected by the disclosure cited in the statement.

Novant and Atrium Health were among 33 major healthcare systems nationwide identified in a June 16 report by The Markup as having certain patient information tracked and made available to Facebook.

The Markup is a nonprofit investigative media outlet that specializes in mining technology data for its reports.

The Markup began its report by saying that “a tracking tool, known as Meta Pixel, was installed on many hospitals’ websites and has been collecting patients’ sensitive health information — including details about their medical conditions, prescriptions and doctor’s appointments — and sending it to Facebook.

The tracker sends Facebook “a packet of data whenever a person clicked a button to schedule a doctor’s appointment.” The data is connected to an IP address, “creating an intimate receipt of the appointment request for Facebook,” the group said.

Novant was among seven systems using Pixel in their patients’ password-protected portals, the report said.

Ashton Miller, Novant’s director of media relations, said June 16 that the entire Novant system was affected by the tracking tool. Miller said Novant removed the tracker after being contacted by The Markup, which the group confirmed in its report.

Background

Novant said the disclosure issue emerged from a promotional campaign it began in May 2020 “to connect more patients to the Novant Health MyChart patient portal with the goal of improving access to care through virtual visits and provide increased accessibility to counter the limitations of in-person care.”

Facebook’s involvement was in the form of Novant advertisements on the website, along with the tracking pixel placed on Novant’s website “to help understand the success of those efforts on Facebook.”

Novant said that once it became aware that the pixel had the capability to transmit unintended information to Meta, it was disabled and removed. The system began an investigation “to learn whether, and to what extent, information was transmitted.”

“Based on its investigation, Novant Health is unaware of any improper use or attempted use of any patient information by Meta or any other third party,” Novant said.

Novant said it “has also implemented more structure, governance and policies around the use of pixels and is taking actions to ensure this does not happen again.”