Technology
Blue Shield exposed 4.7M patients’ health data to Google
Healthcare institutions and insurers arguably collect the most sensitive information about you, including IDs, contact details, addresses and medical records. But they often don’t put in the same level of effort to protect that data.
That’s clear from the growing number of healthcare data breaches we’ve seen recently. In most of those cases, a bad actor was involved.
But in the latest news, health insurance giant Blue Shield of California confirmed that it had been sharing private health data of 4.7 million users with Google for three years without even realizing it.
STAY PROTECTED & INFORMED! GET SECURITY ALERTS & EXPERT TECH TIPS — SIGN UP FOR KURT’S THE CYBERGUY REPORT NOW
A person doing a Google search (Kurt “CyberGuy” Knutsson))
What you need to know
Blue Shield of California just admitted to a major data privacy slip that went on for almost three years, from April 2021 to January 2024. It was using Google Analytics to track how people used its member websites. This is totally normal since every business does it. But the tool was accidentally sharing sensitive info with Google Ads because it wasn’t set up properly.
What I find extremely shocking is that it took the company three years to realize it was sharing its user data with Google to run ads. This says a lot about how much these healthcare giants care about protecting your data.
The shared data included a broad array of protected health information (PHI), including names, zip codes, gender, medical claim dates, online account numbers, insurance plan names, group numbers, family data and even search criteria used in its “Find a Doctor” feature.
“Google may have used this data to conduct focused ad campaigns back to those individual members. We want to reassure our members that no bad actor was involved, and, to our knowledge, Google has not used the information for any purpose other than these ads or shared the protected information with anyone,” the company said in a notice on its website.
This incident is not isolated. Over the past few years, healthcare and tech companies have come under scrutiny for similar missteps. The Federal Trade Commission (FTC) and the Department of Health and Human Services (HHS) have already issued warnings about the use of tracking technologies in healthcare, especially those that might expose patient data to third parties without adequate transparency or safeguards.
A Google spokesperson provided the following comment to CyberGuy when asked about the Blue Shield data breach:
“Businesses, not Google, manage the data they collect and must inform users about its collection and use. By default, any data sent to Google Analytics for measurement does not identify individuals, and we have strict policies against collecting private health information (PHI) or advertising based on sensitive information.”
A person working on their laptop (Kurt “CyberGuy” Knutsson)
MALWARE EXPOSES 3.9 BILLION PASSWORDS IN HUGE CYBERSECURITY THREAT
Impact on patients and the industry
Since the data was only shared with Google and not any other party, the overall risk is relatively low, apart from the clear privacy violation. It’s highly unlikely that anyone else will gain access to it, so the chances of the data being misused are slim. Google says it doesn’t allow ads to be served based on sensitive information like health, so there’s a good chance your data wasn’t even used for advertising.
Blue Shield’s case follows a string of similar breaches. Companies like GoodRx, BetterHelp and Kaiser have all faced regulatory and legal consequences for sharing sensitive user data with advertising vendors. Some even settled for millions of dollars. Despite the risks, many healthcare organizations have continued using these tools due to the lack of clear regulatory guardrails, a situation complicated further by a federal court ruling that blocked the Biden administration’s attempts to curb the use of online trackers in healthcare settings.
WHAT IS ARTIFICIAL INTELLIGENCE (AI)?
A person working on a laptop (Kurt “CyberGuy” Knutsson)
HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET
How to protect your health data online
The Blue Shield of California incident is a reminder that even well-known healthcare providers can mishandle sensitive data. While you can’t always control what happens behind the scenes, there are steps you can take to reduce your exposure and safeguard your privacy:
1. Limit what you share on health portals: Avoid entering more personal details than absolutely necessary on insurance or provider websites. Tools like “Find a Doctor” might log your search terms, so keep inputs vague when possible.
2. Use privacy-focused browsers: Browsers like Brave or Firefox offer built-in privacy protections, such as blocking third-party trackers that could expose health-related browsing activity.
3. Turn off ad personalization: Visit Google’s Ad Settings and disable ad personalization. This won’t stop tracking, but it can reduce how your data is used for targeting.
4. Opt out of tracking where possible: Many healthcare sites use cookies and tracking tools. Choose “reject all” or the strictest privacy settings in cookie banners. If a tracking opt-out tool is available, use it.
5. Read privacy policies (yes, really): Look for language like “third-party sharing,” “advertising,” or “analytics.” If a healthcare provider mentions tools like Google Analytics or Meta Pixel, that’s a cue to proceed cautiously.
6. Monitor your accounts and credit: Keep an eye out for unusual insurance claims or medical charges. Set up credit alerts or monitoring services if your provider offers them, especially after a breach.
7. Ask questions: Call or email your healthcare provider or insurer. Ask what tracking tools they use and how they protect your data. The more consumers push for transparency, the more pressure there is to improve standards.
Bonus privacy steps (For extra peace of mind)
If you want to go beyond the basics, here are some additional steps that can help reduce your digital footprint and catch misuse early:
Use a personal data removal service: While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap — and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you. Check out my top picks for data removal services here.
Consider identity theft protection services: If you’re concerned about fraud or medical identity theft, you’ll want to consider using identity theft protection services. Identity theft companies can monitor personal information like your Social Security number, phone number and email address and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.
Use strong antivirus software: To guard against malware or phishing attacks that could compromise access to your online health accounts, be sure to use strong antivirus software. The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.
Kurt’s key takeaway
It baffles me how careless most companies are when it comes to protecting user data. Blue Shield “mistakenly” shared your data with Google, which then used it to show personalized ads. It took the company three years to realize this. While most cyber incidents involve an attacker, this breach didn’t need one. We need accountability in data practices, especially when human error or tech oversight can cause damage at scale.
How comfortable are you knowing that your health data might be used to target ads? Let us know by writing us at Cyberguy.com/Contact
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter
Ask Kurt a question or let us know what stories you’d like us to cover
Follow Kurt on his social channels
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
It’s amazing how good Alienware’s $350 OLED monitor is
I’ve recommended several OLED gaming monitors to readers over the years, and I’ve finally taken my own advice to buy one. Alienware’s new 27-inch 1440p QD-OLED has all the features that I want and a low $350 price that was too tempting to ignore.
The AW2726DM model has five things that make it stand out for the price: a 1440p QD-OLED screen with lush contrast, a fast 240Hz refresh rate, a semi-glossy screen coating to enhance details, a low-profile design without flashy RGB LEDs, and a great warranty (three years with coverage for burn-in).
I’ve been using Alienware’s new monitor for a couple days, and I’ve already spent hours with it playing Marathon. It was my first opportunity to see Bungie’s new first-person extraction shooter in its full HDR glory, and I can never go back. Switching on HDR wasn’t automatic, though it already looked so much better than my IPS panel without being activated.
Enabling it transformed how Marathon looked for the better, but made everything else about the OS look pretty washed-out. It’s a Windows issue, not an Alienware issue. It’s easy to enable HDR every time I launch a game and disable it afterward with the Windows + Alt + B keyboard shortcut, but unfortunately triggers HDR for all connected displays. This includes my IPS monitor that imbues everything with a terrible gray hue when HDR is on. So, using the system settings is the best way to adjust HDR for just the QD-OLED.
I landed on this QD-OLED after having spent a ton of time researching pricier models. The unanimous takeaway from reviewers was that LG’s Tandem RGB WOLED panels are some of the brightest out there, but also tend to exhibit lousy gray uniformity in dark scenes. QD-OLED monitors, on the other hand, offer slightly better contrast than WOLED and don’t suffer from those same uniformity issues. However, blacks sometimes appear as dark purple in bright rooms on QD-OLED panels, meaning they’re ideal for rooms that don’t have a bunch of light bouncing around.
There’s no perfect choice, and honestly I got tired of doing research, so I jumped in with the cheapest OLED. I’m glad that I did. Shopping for an OLED gaming monitor can be hard, but it can also be this easy. AOC makes a model that’s discounted to $339.99 at the time of publishing, and its specs are comparable.
As expected, the AW2726DM isn’t a cutting-edge monitor. Its QD-OLED panel isn’t as fast or as bright as some other pricier options, and it doesn’t have USB ports for connecting accessories. Considering its low price, it’s easy for me to overlook those omissions. I’d have a much harder time accepting them in a pricier display.
The fact that I mostly use my computer for text-based work at The Verge is what prevented me from upgrading to an OLED monitor. My 1440p IPS monitor is bright, it’s good at showing text clearly, and it has a fast refresh rate for gaming. Alienware’s QD-OLED is less bright, and some might be bothered by how text looks (I have to really squint to see the slight fringing from this QD-OLED’s subpixel layout). But I have a life outside of work, which includes playing a lot of PC games. That’s the slice of myself I bought this monitor for, and I’m so happy I did.
Photography by Cameron Faulkner / The Verge
Technology
Michael and Susan Dell surpass $1 billion in donations backing AI-driven hospital project
NEWYou can now listen to Fox News articles!
Billionaire Michael Dell and his wife, Susan Dell, have become the first donors to give more than $1 billion to the University of Texas at Austin, funding a massive new medical research campus and hospital system powered by artificial intelligence.
The couple’s latest investment includes a $750 million gift to help build the UT Dell Medical Center, a planned “AI-native” hospital expected to open in 2030 as part of a more than 300-acre advanced research campus.
University officials said the project will integrate research, clinical care and advanced computing to improve early disease detection, personalize treatment and expand access to care in the rapidly growing Austin region.
The Dells’ support builds on decades of contributions to UT, including funding for its medical school, scholarships and research programs.
EXCLUSIVE: REPUBLICANS IN KEY RED STATE LAUNCH CAMPAIGN TO ELECT ‘TRUE’ CONSERVATIVES AHEAD OF TRUMP RETURN
Michael Dell and Susan Dell attend the Breakthrough Prize ceremony as they become the first to donate more than $1 billion to the University of Texas at Austin. ( Craig T Fruchtman/WireImage)
“By bringing together medicine, science and computing in one campus designed for the AI era, UT can create more opportunity, deliver better outcomes, and build a stronger future for communities across Texas and beyond,” Michael Dell and Susan Dell said.
The gift ranks among the largest in the history of higher education, alongside major contributions like Phil Knight’s $2 billion pledge to Oregon Health & Science University and Michael Bloomberg’s $1.8 billion donation to Johns Hopkins University.
The new UT Dell Medical Center will be developed in collaboration with MD Anderson Cancer Center, integrating cancer care into a system designed to connect prevention, diagnosis and treatment.
AI IS RUNNING THE CLASSROOM AT THIS TEXAS SCHOOL, AND STUDENTS SAY ‘IT’S AWESOME’
The University of Texas at Austin campus at sunset. (iStock)
“We will deliver better outcomes for patients by providing research-driven cancer care that is precise, compassionate and hope-filled,” Peter WT Pisters, president of UT MD Anderson, said.
Officials said the facility will be built from the ground up to incorporate AI, rather than retrofitting older infrastructure — an approach they say could transform how hospitals operate.
Independent experts have cautioned that AI in health care can introduce risks if not carefully validated. A widely cited study published in the journal Science by researchers at the University of California, Berkeley and the University of Chicago found that a commonly used healthcare algorithm underestimated the needs of Black patients due to biased training data, highlighting broader concerns about equity in AI-driven systems.
The project also includes funding for undergraduate scholarships, student housing and the Texas Advanced Computing Center, where officials are developing one of the nation’s most powerful academic supercomputers.
TURNING POINT USA BACKS TRUMP ACCOUNTS PROGRAM WITH ‘DOLLAR-FOR-DOLLAR MATCH’ FOR ELIGIBLE EMPLOYEE NEWBORNS
Artificial intelligence technology is expected to play a key role in diagnosis and patient care at the planned UT Dell Medical Center. (iStock)
Texas Gov. Greg Abbott said the investment will help position the state as a national leader in healthcare innovation.
“Texas already dominates in technology, energy and business, and now we will further cement our leadership in health care innovation as well,” Abbott said.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
The university said it plans to break ground on the medical center later this year and has launched a broader campaign to raise $10 billion over the next decade.
The Associated Press contributed to this report.
Technology
SpaceX cuts a deal to maybe buy Cursor for $60 billion
SpaceX and Cursor are now working closely together to create the world’s best coding and knowledge work AI.
The combination of Cursor’s leading product and distribution to expert software engineers with SpaceX’s million H100 equivalent Colossus training supercomputer will allow us to build the world’s most useful models.
Cursor has also given SpaceX the right to acquire Cursor later this year for $60 billion or pay $10 billion for our work together.
-
Business4 minutes agoOil Prices Rise as Investors Weigh Cease-Fire Extension
-
Science10 minutes agoPace of N.I.H. Funding Slows Further in Trump’s Second Year
-
Health15 minutes agoAging in Place: How Technology Might Help You Grow Old at Home
-
Culture28 minutes agoBook Review: ‘Israel: What Went Wrong?,’ by Omer Bartov
-
Lifestyle34 minutes agoStreet Style Look of the Week: Airy Beachy Clothes
-
Education40 minutes agoÉcole des Sables, Africa’s Premier Dance School, Faces a Precarious Future
-
Technology46 minutes agoIt’s amazing how good Alienware’s $350 OLED monitor is
-
World52 minutes agoIran reportedly fires on three ships in Strait of Hormuz