Hospital Websites Too Often Share User Data with Third Parties: Study

User privacy can be compromised by sharing website information with external organizations.

By Jeff Wardon, Jr., Assistant Editor


Healthcare cybersecurity has been in the spotlight for some time now, and a relatively new security could compromise digital privacy: third-party tracking on hospital websites. Using this tactic, attackers could gain access to user information healthcare organizations share with third-party organizations. 

A recent JAMA Network study analyzed the privacy policies of hospital websites to understand the way they handle user information and third-party tracking. They looked at a sample of nonfederal, acute care hospitals to examine whether their websites used tracking technologies transferring data to third parties and if they had accessible privacy policies disclosing this.  

The study, from November 2023 to January 2024, assessed policy length, readability and content, focusing on details that include user information collected, potential uses, third-party recipients and user rights regarding tracking and information collection. 

Related: Tracking and Analytics Tool Compromised Patient Data

Key findings included: 

  • 96 percent of hospital websites shared user information with third parties, 
  • 71 percent of websites included a publicly accessible privacy policy, 
  • Of 71 privacy policies, 40 — 56.3 percent — disclosed specific third-party companies receiving user information. 

A “substantial number of hospital websites did not present users with adequate information about the privacy implications of website use, either because they lacked a privacy policy or had a privacy policy that contained limited content about third-party recipients of user information,” according to the study. 

Jeff Wardon, Jr. Is the assistant editor for the facilities market. 



April 17, 2024


Topic Area: Information Technology


Recent Posts

Case Study: How NYU Langone Rebuilt for Resilience After Superstorm Sandy

Although the damage was severe, it provided a valuable opportunity for NYU Langone to assess structural vulnerabilities and increase facility resilience.


Frederick Health Hospital Faces 5 Lawsuits Following Ransomware Attack

The lawsuits accuse FHH of inadequate cybersecurity, poor breach notification and failing to protect patients from identity theft risks.


Arkansas Methodist Medical Center and Baptist Memorial Health Care to Merge

They have signed a non-binding letter of intent to complete a shared mission agreement to merge the two organizations.


Ground Broken on Intermountain Saratoga Springs Multi-Specialty Clinic

The clinic is scheduled to open and start seeing patients in the fall of 2026.


Electrical Fire Tests Resilience of Massachusetts Hospital

Signature Healthcare Brockton Hospital used opportunity to renovate key systems and components and expand facility operations.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.