Skip to main content
Blog
Blog

Kaiser Permanente Data Leak: A Case of Miscommunication and Inadequate Disclosure

On April 29th, healthcare giant Kaiser Permanente disclosed a data leak impacting 13.4 million current and former insurance members. The incident was rooted in improperly managed 3rd party scripts. The Incident Kaiser Permanente used tracking codes to monitor how its members navigated through its website and mobile applications. Some of these pages contained sensitive healthcare data, leading to the 3rd party scripts inadvertently transmitted information to third-party vendors they weren't

May 25, 2024 4 min read
Kaiser Permanente Data Leak: A Case of Miscommunication and Inadequate Disclosure cover image
Table of Contents

TL;DR: Kaiser Permanente 13.4M HIPAA tracker leak

  • No hack, still leaked: No hijack. No malicious actor. Kaiser Permanente still leaked 13.4 million member records because marketing installed trackers engineering never scoped, and both teams thought the other one owned the risk.
  • Trackers on HIPAA pages: The leaked pixels exfiltrated names, IPs, visited URLs, login state and health-encyclopedia search terms across pages HIPAA covers. cside can restrict a script to a page-level scope and flag when it fires anywhere it should not.
  • Scope or remove: If any tracker on your site can load on a page containing PHI, PII or payment data, scope it today. If you cannot scope it, remove it before your next audit letter is a breach letter.

Short on time? See cside's in-browser Magecart and skimmer blocking. It covers everything below in one deployment.

On April 29th, healthcare giant Kaiser Permanente disclosed a data leak impacting 13.4 million current and former insurance members. The incident was rooted in improperly managed 3rd party scripts.

Kaiser Permanente's legal notice about the data leak

The incident

Kaiser Permanente used tracking codes to monitor how its members navigated through its website and mobile applications. Some of these pages contained sensitive healthcare data, leading to the 3rd party scripts inadvertently transmitted information to third-party vendors they weren't supposed to have.

While the breach wasn't a result of a script hijack, it shows a common gap in how the healthcare industry, and companies elsewhere, handle third-party scripts.

The incident also points to a broader issue: engineering teams are often asked, ad-hoc, to implement 3rd party scripts chosen by marketing, data or legal teams. This can lead to engineers implementing the script, lacking context and deploying scripts site-wide. It works, but it now touches data it shouldn't.

Proper tooling likely wasn't in place to spot or prevent this issue.

The risks

The core issue was a lack of understanding and proper disclosure of the tracking code being used, not malicious intent. The shared data included names, IP addresses, visited pages, user login status, and search terms used in Kaiser's online health encyclopedia. Although such tracking scripts are very common, in the healthcare industry, they must comply with privacy regulations like the Health Insurance Portability and Accountability Act (HIPAA) and others.

The risks of inadequate disclosure

Healthcare providers handle sensitive information, and any data leak can have serious repercussions. Even though the data shared by Kaiser might not be classified as electronically protected health information (ePHI), the breach could still result in penalties and most certainly damage to the company's reputation. The incident indicates many companies with strong safety and compliance teams, still suffer from mismanaging third-party scripts. An issue we see all too often.

A practical solution

To address such issues, companies can implement robust Content Security Policies (CSPs) to manage third-party scripts on sensitive pages. While this solution causes some downsides like noisy console logs, it effectively mitigates the risk of unauthorized data sharing.

Ideally, instead of deploying scripts globally, one would use conditional rendering. Defining the pages scripts should load on.

Using cside, you can also manage your third-party scripts more cleanly, seeing which scripts run on specific pages and stopping malicious code before it renders.

cside

cside can flag any sightings of scripts on pages that contain sensitive information, using fine-grained, autogenerated rules to prevent delivery without noisy console logs on those pages.

To address third-party script security, our solution analyzes scripts before they reach the user's browser. By proxying scripts and using AI to detect malicious intent, cside ensures that potential threats are neutralized before they can cause harm. This proactive approach, combined with historical context analysis, allows for effective monitoring and response to third-party script breaches.

We naturally also monitor all scripts, meaning with us in place, this issue could've been prevented.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead