Connect with us

FACEBOOK

NHS data breach: trusts shared patient details with Facebook without consent | Health

Published

on

NHS trusts are sharing intimate details about patients’ medical conditions, appointments and treatments with Facebook without consent and despite promising never to do so.

An Observer investigation has uncovered a covert tracking tool in the websites of 20 NHS trusts which has for years collected browsing information and shared it with the tech giant in a major breach of privacy.

The data includes granular details of pages viewed, buttons clicked and keywords searched. It is matched to the user’s IP address – an identifier linked to an individual or household – and in many cases details of their Facebook account.

Information extracted by Meta Pixel can be used by Facebook’s parent company, Meta, for its own business purposes – including improving its targeted advertising services.

Records of information sent to the firm by NHS websites reveal it includes data which – when linked to an individual – could reveal personal medical details.

Advertisement

It was collected from patients who visited hundreds of NHS webpages about HIV, self-harm, gender identity services, sexual health, cancer, children’s treatment and more.

It also includes details of when web users clicked buttons to book an appointment, order a repeat prescription, request a referral or to complete an online counselling course. Millions of patients are potentially affected.

This weekend, 17 of the 20 NHS trusts that were using Meta Pixel confirmed they had pulled the tracking tool from their websites.

Eight issued apologies to patients. Multiple trusts said they had originally installed the tracking pixels to monitor recruitment or charity campaigns and were not aware that they were sending patient data to Facebook. The Information Commissioner’s Office (ICO) is investigating.

The Observer can reveal:

In one case, Buckinghamshire Healthcare NHS trust shared when a user viewed a patient handbook for HIV medication. The name of the drug and the NHS trust were sent to the company along with the user’s IP address and details of their Facebook user ID.

Advertisement

Alder Hey Children’s trust in Liverpool, sent Facebook details when users visited webpages for sexual development problems, crisis mental health services and eating disorders. It also shared data when users clicked to order repeat prescriptions.

The Tavistock and Portman NHS foundation trust in London shared data with Facebook when users clicked the information page for its gender identity service, which specialises in working with children who have gender dysphoria. Data was also shared when users viewed the webpage for the Portman Clinic, which “offers specialist help with disturbing sexual behaviours”, and clicked for details on how to be referred to the service.

Surrey and Borders Partnership NHS trust shared data with Facebook when a patient clicked buttons indicating they were under 18, lived in Brighton and wanted to access mental health services.

Other NHS trusts sent detailed receipts to Facebook when users accessed pages for appointment bookings or completed online self-help courses. Barts Health NHS trust, which serves a population of 2.5 million in London, shared data with Facebook when a user clicked to “cancel or change an appointment” or added a visit to a particular hospital to their itinerary.

The Royal Marsden, a specialist cancer centre, sent data on patients requesting referrals, viewing information about private care and browsing pages for particular cancer types.

A page about sexual development disorders on Alder Hey Children’s Hospital’s website, which shared details of the browsing with Facebook via the Meta Pixel.
A page about sexual development disorders on Alder Hey Children’s Hospital’s website, which shared details of the browsing with Facebook via the Meta Pixel.

The findings have caused alarm among privacy experts who said they indicated widespread potential breaches of data protection and patient confidentiality that were “completely unacceptable”.

Information sent to the company is likely to include special category health data, which has extra protection in law and is defined as information “about an individual’s past, current or future health status”, including medical conditions, tests and treatment and “any related data which reveals anything about the state of someone’s health”. Using or sharing it without explicit consent or another lawful basis is illegal.

Advertisement

Once the data reaches Facebook’s servers, it is not possible to track exactly how it is used. The company says it prohibits organisations from sending it sensitive health information and has filters to weed such data out when it is received by mistake.

Professor David Leslie, director of ethics at the Alan Turing Institute, said the transfer of data to third parties by the NHS risked damaging the “delicate relationship of trust” with patients. “Our reasonable expectation when we’re accessing an NHS website is that our data won’t be extracted and shared with third-party commercial entities that could [use it] for targeting ads or linking our personal identities to health conditions,” he said.

Wolfie Christl, a data privacy expert who has investigated the ad tech industry, said: “This should have been stopped by regulators a long time ago. It is irresponsible, even negligent, and it must stop.”

He accused Meta of doing too little to monitor what information it was being sent. “Meta says we don’t permit certain types of data being sent to us but they haven’t spent enough on resources to audit this,” Christl said.

In most cases, the information sent to Facebook during a test by the Observer was transferred automatically upon loading a website – before the user had selected to “accept” or “decline” cookies – and without explicit consent. Only three of the 20 trusts mentioned Facebook or Meta in their privacy policies at all. Several of the trusts had previously promised patients that their information would not be shared or used for marketing.

Collectively, the 20 NHS trusts found using the tracking tool serve a population of more than 22 million people in England, stretching from Devon to the Pennines. Some had been using it for several years.

Advertisement
A screen showing data that was shared by Surrey and Borders partnership
Surrey and Borders partnership trust shared data with Facebook when a patient clicked buttons indicating they were under 18, lived in Brighton and wanted to access mental health services.

One of the trusts that pulled the tracking tool this weekend, Buckinghamshire Healthcare NHS trust, had previously said in its privacy policy that “confidential personal information about your health and care … would never be used for marketing purposes without your explicit consent”.

In a statement, the trust apologised to patients and said the Meta Pixel had been active on its website in error. “It was installed in relation to a recruitment campaign, and we were not aware that Meta was using this information for marketing purposes,” a spokesperson said. “Immediate action has been taken to remove it.”

Alder Hey said it asked visitors to its website for permission to use cookies and said patients’ names and addresses had not been shared. It has removed the tracking tool.

The Royal Marsden said it regularly reviewed its privacy policies but did not say whether it planned to remove the pixel. Barts said it was removing trackers from its website “following the disclosure that they were being used to extract personal information beyond the purpose for which they were originally installed, which was to measure responses to recruitment advertising campaigns.”

Several said they were unaware of how data would be used and apologised to patients for failing to get consent. Aside from the 17 who pulled or are pulling the tool, Hertfordshire Partnership trust and Royal Marsden said they were investigating the issues internally and only the Tavistock and Portman did not respond to requests for comment.

The ICO said it had “noted the findings” and was considering the matter. “People have the right to expect that organisations will handle their information securely and that it will only be used for the purpose they are told,” a spokesperson said.

Revelations about the NHS use of Meta Pixel come after regulators in the US issued warnings over the use of tracking tools there. Last summer, tech website The Markup exposed their use on the websites of healthcare providers. In December, the Biden administration warned that using tracking pixels to collect patient data without consent was a potential federal law violation.

Advertisement

Several leading US hospitals are currently being sued by their patients over their use of the pixels, which are tiny pieces of code that are invisible during normal browsing.

Meta is also facing legal action over accusations of knowingly receiving sensitive health information – including from pages within patient portals – and not taking steps to stop it. The plaintiffs claim Meta violated their medical privacy by intercepting “individually identifiable health information” from its partner websites and “monetising” it.

Jeffrey Koncius, a partner at Kiesel Law in California and one of the attorneys leading the action, said the data transfer by the NHS websites appeared similar to what was happening in the US. “Imagine if a hospital sent a letter to Mark Zuckerberg and said, ‘We want you to know that Jeff Koncius is our patient,’” he said. “That’s exactly what’s happening here. It’s just happening electronically.”

The Liberal Democrat health spokesperson Daisy Cooper described the findings as a “shocking discovery” that raised serious questions about the protection of patient information. “The NHS must investigate how this happened and how widespread this alleged data breach is,” she said.

NHS England said individual trusts were responsible for ensuring they followed data protection laws. “The NHS is looking into this issue and will take further action if necessary,” a spokesperson said.

Meta said it had contacted the trusts to remind them of its policies, which prohibited organisations from sending it health data. “We educate advertisers on properly setting up business tools to prevent this from occurring,” the spokesperson said. They added it was website owner’s responsibility to ensure it complied with data protection laws and had obtained consent before sending data.

The company did not answer questions about the effectiveness of its filters designed to weed out “potentially sensitive data”, or which types of information they would block from hospital websites – or say why it permitted NHS trusts to send it data at all, given the high risk it could reveal details about the web user’s health.

“Like any technology, our filters won’t be able to catch everything all of the time. However, we are constantly improving our mechanisms to make sure we catch as much as we can,” a spokesperson said.

The company offers its business tools to advertisers, saying they can help them use health-based advertising to “grow your business”. In one guide, it says data collected through its business tools can improve users’ Facebook experience by showing them ads they “might be interested in”. “You may see ads for hotel deals if you visit travel websites,” it explains.

Sam Smith, at medConfidential, a data privacy campaign group, said it was never appropriate for the tools to be used to collect health information. “There’s no benefit to NHS trusts in giving this information away. It’s like asking a tobacco company to sponsor a cancer ward,” he said. “NHS England is tacitly approving this by not enforcing anything better.”

Source link

Advertisement
Keep an eye on what we are doing
Be the first to get latest updates and exclusive content straight to your email inbox.
We promise not to spam you. You can unsubscribe at any time.
Invalid email address

FACEBOOK

Facebook Faces Yet Another Outage: Platform Encounters Technical Issues Again

Published

on

By

Facebook Problem Again

Uppdated: It seems that today’s issues with Facebook haven’t affected as many users as the last time. A smaller group of people appears to be impacted this time around, which is a relief compared to the larger incident before. Nevertheless, it’s still frustrating for those affected, and hopefully, the issues will be resolved soon by the Facebook team.

Facebook had another problem today (March 20, 2024). According to Downdetector, a website that shows when other websites are not working, many people had trouble using Facebook.

This isn’t the first time Facebook has had issues. Just a little while ago, there was another problem that stopped people from using the site. Today, when people tried to use Facebook, it didn’t work like it should. People couldn’t see their friends’ posts, and sometimes the website wouldn’t even load.

Downdetector, which watches out for problems on websites, showed that lots of people were having trouble with Facebook. People from all over the world said they couldn’t use the site, and they were not happy about it.

When websites like Facebook have problems, it affects a lot of people. It’s not just about not being able to see posts or chat with friends. It can also impact businesses that use Facebook to reach customers.

Since Facebook owns Messenger and Instagram, the problems with Facebook also meant that people had trouble using these apps. It made the situation even more frustrating for many users, who rely on these apps to stay connected with others.

Advertisement

During this recent problem, one thing is obvious: the internet is always changing, and even big websites like Facebook can have problems. While people wait for Facebook to fix the issue, it shows us how easily things online can go wrong. It’s a good reminder that we should have backup plans for staying connected online, just in case something like this happens again.

Keep an eye on what we are doing
Be the first to get latest updates and exclusive content straight to your email inbox.
We promise not to spam you. You can unsubscribe at any time.
Invalid email address
Continue Reading

FACEBOOK

Christian family goes in hiding after being cleared of blasphemy

Published

on

Christian family goes in hiding after being cleared of blasphemy

LAHORE, Pakistan — A court in Pakistan granted bail to a Christian falsely charged with blasphemy, but he and his family have separated and gone into hiding amid threats to their lives, sources said.

Haroon Shahzad (right) with attorney Aneeqa Maria. | The Voice Society/Morning Star News

Haroon Shahzad, 45, was released from Sargodha District Jail on Nov. 15, said his attorney, Aneeqa Maria. Shahzad was charged with blasphemy on June 30 after posting Bible verses on Facebook that infuriated Muslims, causing dozens of Christian families in Chak 49 Shumaali, near Sargodha in Punjab Province, to flee their homes.

Lahore High Court Judge Ali Baqir Najfi granted bail on Nov. 6, but the decision and his release on Nov. 15 were not made public until now due to security fears for his life, Maria said.

Shahzad told Morning Star News by telephone from an undisclosed location that the false accusation has changed his family’s lives forever.

“My family has been on the run from the time I was implicated in this false charge and arrested by the police under mob pressure,” Shahzad told Morning Star News. “My eldest daughter had just started her second year in college, but it’s been more than four months now that she hasn’t been able to return to her institution. My other children are also unable to resume their education as my family is compelled to change their location after 15-20 days as a security precaution.”

Though he was not tortured during incarceration, he said, the pain of being away from his family and thinking about their well-being and safety gave him countless sleepless nights.

Advertisement



“All of this is due to the fact that the complainant, Imran Ladhar, has widely shared my photo on social media and declared me liable for death for alleged blasphemy,” he said in a choked voice. “As soon as Ladhar heard about my bail, he and his accomplices started gathering people in the village and incited them against me and my family. He’s trying his best to ensure that we are never able to go back to the village.”

Shahzad has met with his family only once since his release on bail, and they are unable to return to their village in the foreseeable future, he said.

“We are not together,” he told Morning Star News. “They are living at a relative’s house while I’m taking refuge elsewhere. I don’t know when this agonizing situation will come to an end.”

The Christian said the complainant, said to be a member of Islamist extremist party Tehreek-e-Labbaik Pakistan and also allegedly connected with banned terrorist group Lashkar-e-Jhangvi, filed the charge because of a grudge. Shahzad said he and his family had obtained valuable government land and allotted it for construction of a church building, and Ladhar and others had filed multiple cases against the allotment and lost all of them after a four-year legal battle.

“Another probable reason for Ladhar’s jealousy could be that we were financially better off than most Christian families of the village,” he said. “I was running a successful paint business in Sargodha city, but that too has shut down due to this case.”

Regarding the social media post, Shahzad said he had no intention of hurting Muslim sentiments by sharing the biblical verse on his Facebook page.

Advertisement



“I posted the verse a week before Eid Al Adha [Feast of the Sacrifice] but I had no idea that it would be used to target me and my family,” he said. “In fact, when I came to know that Ladhar was provoking the villagers against me, I deleted the post and decided to meet the village elders to explain my position.”

The village elders were already influenced by Ladhar and refused to listen to him, Shahzad said.

“I was left with no option but to flee the village when I heard that Ladhar was amassing a mob to attack me,” he said.

Shahzad pleaded with government authorities for justice, saying he should not be punished for sharing a verse from the Bible that in no way constituted blasphemy.

Similar to other cases

Shahzad’s attorney, Maria, told Morning Star News that events in Shahzad’s case were similar to other blasphemy cases filed against Christians.

Advertisement



“Defective investigation, mala fide on the part of the police and complainant, violent protests against the accused persons and threats to them and their families, forcing their displacement from their ancestral areas, have become hallmarks of all blasphemy allegations in Pakistan,” said Maria, head of The Voice Society, a Christian paralegal organization.

She said that the case filed against Shahzad was gross violation of Section 196 of the Criminal Procedure Code (CrPC), which states that police cannot register a case under the Section 295-A blasphemy statute against a private citizen without the approval of the provincial government or federal agencies.

Maria added that Shahzad and his family have continued to suffer even though there was no evidence of blasphemy.

“The social stigma attached with a blasphemy accusation will likely have a long-lasting impact on their lives, whereas his accuser, Imran Ladhar, would not have to face any consequence of his false accusation,” she said.

The judge who granted bail noted that Shahzad was charged with blasphemy under Section 295-A, which is a non-cognizable offense, and Section 298, which is bailable. The judge also noted that police had not submitted the forensic report of Shahzad’s cell phone and said evidence was required to prove that the social media was blasphemous, according to Maria.

Bail was set at 100,000 Pakistani rupees (US $350) and two personal sureties, and the judge ordered police to further investigate, she said.

Advertisement



Shahzad, a paint contractor, on June 29 posted on his Facebook page 1 Cor. 10:18-21 regarding food sacrificed to idols, as Muslims were beginning the four-day festival of Eid al-Adha, which involves slaughtering an animal and sharing the meat.

A Muslim villager took a screenshot of the post, sent it to local social media groups and accused Shahzad of likening Muslims to pagans and disrespecting the Abrahamic tradition of animal sacrifice.

Though Shahzad made no comment in the post, inflammatory or otherwise, the situation became tense after Friday prayers when announcements were made from mosque loudspeakers telling people to gather for a protest, family sources previously told Morning Star News.

Fearing violence as mobs grew in the village, most Christian families fled their homes, leaving everything behind.

In a bid to restore order, the police registered a case against Shahzad under Sections 295-A and 298. Section 295-A relates to “deliberate and malicious acts intended to outrage religious feelings of any class by insulting its religion or religious beliefs” and is punishable with imprisonment of up to 10 years and fine, or both. Section 298 prescribes up to one year in prison and a fine, or both, for hurting religious sentiments.

Pakistan ranked seventh on Open Doors’ 2023 World Watch List of the most difficult places to be a Christian, up from eighth the previous year.

Advertisement



Morning Star News is the only independent news service focusing exclusively on the persecution of Christians. The nonprofit’s mission is to provide complete, reliable, even-handed news in order to empower those in the free world to help persecuted Christians, and to encourage persecuted Christians by informing them that they are not alone in their suffering.

Free Religious Freedom Updates

Join thousands of others to get the FREEDOM POST newsletter for free, sent twice a week from The Christian Post.

Source link

Keep an eye on what we are doing
Be the first to get latest updates and exclusive content straight to your email inbox.
We promise not to spam you. You can unsubscribe at any time.
Invalid email address
Continue Reading

FACEBOOK

Individual + Team Stats: Hornets vs. Timberwolves

Published

on

CHARLOTTE HORNETS MINNESOTA TIMBERWOLVES You can follow us for future coverage by liking us on Facebook & following us on X: Facebook – All Hornets X – …

Source link

Keep an eye on what we are doing
Be the first to get latest updates and exclusive content straight to your email inbox.
We promise not to spam you. You can unsubscribe at any time.
Invalid email address
Continue Reading

Trending

Follow by Email
RSS