Hospital Data Breach
Hospital Data Breach: Advocate Aurora Health & Meta Pixel
On Thursday, October 20, Advocate Aurora Health (AAH), a healthcare system based in Wisconsin and Illinois, notified its patients of a breach that exposed the Personal Health Information (PHI) of 3,000,000 patients. The leak was caused by the improper use of Meta Pixel on AAH’s website, where patients log in and enter medical and personal information. The Meta Pixel is a snippet of JavaScript code that allows organizations to track visitor activity on their website for advertising purposes.
Privacy Concerns Around Meta Pixel
The SensCy cybersecurity team has been monitoring the rise of data breaches in the healthcare industry. While recent trends show hackers shifting focus to small hospitals, clinics and tech companies to siphon off patient data, this incident demonstrates that large healthcare systems remain vulnerable to internal misconfigurations.
The latest breach joins a long list of healthcare data breaches due to Meta Pixel’s misuse. Much like the accidental exposures seen in the Microsoft Data Leak, this situation highlights how third-party integrations can inadvertently compromise sensitive data. Meta Pixel is used by many hospitals in the U.S. and is currently facing class action lawsuits for tracking, exposing, and using healthcare data to target ads.
According to the lawsuit, “neither the hospitals nor Meta informs the patients about the data collection, no user consents are requested, and there is no visible indication of this process.” SensCy believes it is highly likely that more data breaches will accrue in the near future as healthcare providers continue to use third-party tools. To mitigate these risks, organizations must implement 3 actionable steps to increase small-business data protection, specifically auditing website scripts and third-party vendors.
Key Takeaways
- Massive Data Exposure: Advocate Aurora Health (AAH) notified 3 million patients that their Personal Health Information (PHI) was exposed via a tracking tool.
- Root Cause: The breach was not a traditional hack but caused by the improper installation of “Meta Pixel,” a JavaScript tracker, on secure patient portals.
- Compromised Data: Shared information includes IP addresses, appointment schedules, insurance details, and sensitive communications within MyChart.
- Privacy Action: Patients are urged to use “Incognito” mode or browser tracking blockers when accessing healthcare websites to prevent unauthorized data collection.
Breach Response and Mitigation
AAH notified its patients of the data breach and provided a FAQ, a critical component of a transparent Data Breach Response: Essential Guide for Small Business Recovery. They stated the following information might have been exposed via Meta Pixel:
- IP address
- Dates, times, and locations of scheduled appointments
- Proximity to an AAH location
- Medical provider information
- Type of appointment or procedure
- Communications between MyChart users (which may have included first and last names and medical record numbers)
- Insurance information
- Proxy account information
AAH has disabled the Pixel tracker and is implementing new safeguards to prevent similar incidents. SensCy advised patients to use their web browser’s tracker-blocking features or use incognito mode when accessing medical portals.
Frequently Asked Questions (FAQ)
1. What is the Meta Pixel?
The Meta Pixel is a piece of code developed by Facebook (Meta) that website owners place on their sites. It tracks user behavior, such as which pages they visit or buttons they click, to help organizations target advertisements. In this case, it was tracking actions inside a private patient portal.
2. Was this a ransomware attack?
No. Unlike a ransomware attack where criminals lock files and demand payment, this was a data privacy breach. The information was not “stolen” by hackers in the traditional sense; rather, it was automatically sent to Meta (Facebook) due to the way the website was configured.
3. specifically what data was not exposed?
Based on reports, the exposure was tied to appointment and usage data. Full medical histories, diagnosis notes, and Social Security numbers were not explicitly listed as the primary data types scraped by the Pixel, though “communications” within MyChart could theoretically contain sensitive details.
4. How can I stop websites from tracking my health data?
To protect your privacy, avoid logging into medical portals while also logged into Facebook in the same browser. Use “Private” or “Incognito” windows for health-related browsing, and consider installing privacy extensions like uBlock Origin or Privacy Badger to block tracking scripts.

