State insurance exchanges in the US leaked citizenship and race data

Colleagues, I want to draw attention to a cybersecurity incident: Bloomberg found that state health insurance exchange sites in about 20 states were transmitting applicants’ data to advertising platforms.
- Found: citizenship, race and other fields could have been shared with Google, Meta, LinkedIn, Snap and TikTok.
- Examples: New York transmitted information about relatives (including data on incarcerated persons). D.C. shared emails and phone numbers; a TikTok pixel attempted to overwrite the “race” field but masking was incomplete.
- Response: D.C. paused the TikTok pixel, Virginia removed the Meta pixel.
Why it matters: misconfigured pixels on government sites can cause mass leakage of sensitive data.
What immediate steps should governments and IT teams take?
#cybersecurity #privacy #health #advertising


Latest comments
No comments yet.