On February 11, 2025, Blue Shield discovered that, between April 2021 and January 2024, Google Analytics was configured in a way that allowed certain member data to be shared with Google’s advertising product, Google Ads, that likely included protected health information. Google may have used this data to conduct focused ad campaigns back to those individual members.

Blue Shield severed the connection between Google Analytics and Google Ads on its websites in January 2024.

What information was involved

  • Insurance plan name, type and group number;
  • city;
  • zip code;
  • gender;
  • family size;
  • Blue Shield assigned identifiers for members’ online accounts;
  • medical claim service date and service provider, patient name, and patient financial responsibility;
  • “Find a Doctor” search criteria and results (location, plan name and type, provider name and type).
  • Tronn4@lemmy.world
    link
    fedilink
    English
    arrow-up
    45
    ·
    2 天前

    What are these supposed benefits they speak of? Allowing Google access for what end?

    • stankmut@lemmy.world
      link
      fedilink
      English
      arrow-up
      18
      ·
      edit-2
      2 天前

      The analytics would be for the web development team to see which pages/features are used. Usually a product manager uses that data for setting priorities on what gets worked on.

        • Cousin Mose@lemmy.hogru.ch
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 天前

          As a web developer that blocks all this shit, that’s the line I always use. I would just use first-party analytics from the same domain the website is hosted from. The added bonus is that people like me wouldn’t even be able to block it without blocking the entire website (at least with DNS).

      • Tronn4@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 天前

        SHUSH! 😄 We trying to burn this whole thing to the ground! Don’t come here with all that sense making talk! 🤣 /s

    • chaospatterns@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 天前

      Google Analytics gives you insights on what pages people visit, how long they spend, what kind of browsers and devices they use. That can give them data on what pages are important to customers and what screen sizes to support

      I’d rather they self host this data vs use Google Analytics, but there are benefits.

      • NotMyOldRedditName@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 天前

        It goes further than that. They can track how people interact with the page, order of buttons pressed, if or when they abort a workflow etc. You can go as deep down the rabbit hole of analytics and optimizations as you want.

    • real_squids@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      10
      ·
      edit-2
      2 天前

      “Better” ads most likely, aka more personalized.

      edit:

      Google may have used this data to conduct focused ad campaigns back to those individual members.

      That’s their exact language

      • stankmut@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        2 天前

        Allowing Google to run an ad campaign targeting their members wasn’t the benefit Blue Cross was talking about, that’s a side effect from them not turning off the data sharing option in the Google analytics settings.

        The analytics data is used for prioritizing development work. If a tool they have on the website relies on a library that isn’t compatible with a new version of React, for instance, do they know how many people use it? Having analytics allows you to decide what’s worth spending the development time to maintain.