{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/117825"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/117825","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Privacy concerns of web tracking on healthcare websites","abstract":"Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-04-12 without embargo terms","abstract_html":"Submission original under an indefinite embargo labeled &#x27;Open Access&#x27;. The submission was exported from vireo on 2023-04-12 without embargo terms","abstract_has_math":false,"creators":["Huo, Mingjia"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Levchenko, Kirill"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2022,"date_issued":"2022-12","date_published":"2022-12","updated_at":"2026-07-22T22:24:56Z","subjects":["Web Tracking","Web Privacy","Protected Health Information"],"languages":["en","eng"],"rights":["Copyright 2022 Mingjia Huo"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/117825","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Levchenko, Kirill"]},{"key":"dc:creator","label":"Author","values":["Huo, Mingjia"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2022-12","2022-12-05"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Web Tracking","Web Privacy","Protected Health Information"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2022 Mingjia Huo"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/117825"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-04-12 without embargo terms","The student, Mingjia Huo, accepted the attached license on 2022-12-02 at 09:17.","The student, Mingjia Huo, submitted this Thesis for approval on 2022-12-02 at 09:18.","This Thesis was approved for publication on 2022-12-05 at 14:39.","DSpace SAF Submission Ingestion Package generated from Vireo submission #18735 on 2023-04-12 at 07:37:08","In the United States, Protected Health Information (PHI) is protected under the Health Insurance Portability and Accountability Act (HIPAA). This act limits the disclosure of PHI without the patient's consent or knowledge. However, as medical care becomes web-integrated, many providers have chosen to use third-party web trackers for measurement and marketing purposes, and ensuring PHI is not unintentionally or maliciously leaked becomes difficult. This paper investigates health information leakage in online medical records, focusing on 459 online patient portals and 4 telehealth websites. We find that 14 percent of patient portals had Google Analytics, which includes HTTP cookies that could be used to identify users. Besides, 5 portals and 4 telehealth websites contained JavaScript-based trackers that leaked PHI, including lab results, to third parties. We notified healthcare providers of the PHI breaches and found only 15.7 percent took action to correct leaks. After notifying Epic, the healthcare portal vendor of patient portals in our study, of the PHI leaks, we received a prompt response and observed extensive mitigation across providers."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Privacy concerns of web tracking on healthcare websites"]}]}],"canonical_facts":{"dc:contributor":["Levchenko, Kirill"],"dc:creator":["Huo, Mingjia"],"dc:date":["2022-12","2022-12-05"],"dc:description":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-04-12 without embargo terms","The student, Mingjia Huo, accepted the attached license on 2022-12-02 at 09:17.","The student, Mingjia Huo, submitted this Thesis for approval on 2022-12-02 at 09:18.","This Thesis was approved for publication on 2022-12-05 at 14:39.","DSpace SAF Submission Ingestion Package generated from Vireo submission #18735 on 2023-04-12 at 07:37:08","In the United States, Protected Health Information (PHI) is protected under the Health Insurance Portability and Accountability Act (HIPAA). This act limits the disclosure of PHI without the patient's consent or knowledge. However, as medical care becomes web-integrated, many providers have chosen to use third-party web trackers for measurement and marketing purposes, and ensuring PHI is not unintentionally or maliciously leaked becomes difficult. This paper investigates health information leakage in online medical records, focusing on 459 online patient portals and 4 telehealth websites. We find that 14 percent of patient portals had Google Analytics, which includes HTTP cookies that could be used to identify users. Besides, 5 portals and 4 telehealth websites contained JavaScript-based trackers that leaked PHI, including lab results, to third parties. We notified healthcare providers of the PHI breaches and found only 15.7 percent took action to correct leaks. After notifying Epic, the healthcare portal vendor of patient portals in our study, of the PHI leaks, we received a prompt response and observed extensive mitigation across providers."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/117825"],"dc:language":["en","eng"],"dc:rights":["Copyright 2022 Mingjia Huo"],"dc:subject":["Web Tracking","Web Privacy","Protected Health Information"],"dc:title":["Privacy concerns of web tracking on healthcare websites"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:56Z"}