University of Illinois at Urbana-Champaign
Privacy concerns of web tracking on healthcare websites
Abstract
dc:descriptionIn the United States, Protected Health Information (PHI) is protected under the Health Insurance Portability and Accountability Act (HIPAA). This act limits the disclosure of PHI without the patient's consent or knowledge. However, as medical care becomes web-integrated, many providers have chosen to use third-party web trackers for measurement and marketing purposes, and ensuring PHI is not unintentionally or maliciously leaked becomes difficult. This paper investigates health information leakage in online medical records, focusing on 459 online patient portals and 4 telehealth websites. We find that 14 percent of patient portals had Google Analytics, which includes HTTP cookies that could be used to identify users. Besides, 5 portals and 4 telehealth websites contained JavaScript-based trackers that leaked PHI, including lab results, to third parties. We notified healthcare providers of the PHI breaches and found only 15.7 percent took action to correct leaks. After notifying Epic, the healthcare portal vendor of patient portals in our study, of the PHI leaks, we received a prompt response and observed extensive mitigation across providers.
Degree
thesis:*- Name thesis:degree_name
- M.S.
- Level thesis:degree_level
- Thesis
- Discipline thesis:degree_discipline
- Electrical & Computer Engr
- Grantor
- University of Illinois at Urbana-Champaign
- Year dc:date
- 2022
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Huo, Mingjia
- Contributors dc:contributor
-
- Levchenko, Kirill
Subjects
dc:subject × 3Rights
dc:rights- Statement dc:rights
-
- Copyright 2022 Mingjia Huo
- Language dc:language
- en, eng
Identifiers
dc:identifier.*- Handle dc:identifier
- https://hdl.handle.net/2142/117825