Telehealth company Cerebral has reportedly shared private patient data with Google, Meta, and TikTok, according to recent news reports.
The company, which provides online therapy and medication management services, shared information on 3.1 million patients, including their names, dates of birth, and medical histories. The data was shared with the tech companies for advertising purposes.
Cerebral's disclosure at the bottom of their website states that the exposed information may include:
The sharing of private patient data with third-party companies raises serious concerns about patient privacy and the security of medical information.
While sharing data can help companies target ads more effectively, it also risks patient confidentiality and harms patients' trust in the healthcare system. Companies that collect sensitive medical information are expected to be transparent about how that information is being used and to protect patients' privacy rights.
Cerebral's actions have also drawn criticism from privacy advocates, who argue that patient data should be treated as confidential and protected under the Health Insurance Portability and Accountability Act (HIPAA).
Andrea Downing, who has done extensive research on pixel tracking and privacy, said patients are often unaware of how much personal data healthcare startups collect and potentially transmit to other parties.
While Cerebral has stated that it did not violate HIPAA regulations, some experts have raised concerns that the company may have violated patients' privacy rights by sharing their data without explicit consent.
Sharing private patient data with third-party companies is a growing concern in the healthcare industry. Regulators are likely to look closely at companies that engage in these practices.
Patients should know the risks of sharing their medical information with online healthcare providers. They should take steps to protect their privacy, such as reading privacy policies and asking providers how their data will be used.
While companies like Cerebral can provide valuable telehealth services, they must keep patient data confidential and protected from unauthorized access. Patients should be able to trust that their medical information will be used only for legitimate purposes and that their privacy rights will be respected.
As the healthcare industry continues to evolve, it is important for all involved to ensure patient privacy is maintained and that the benefits of technology are balanced against potential risks.
Related: How to send HIPAA compliant emails