All Eyes On Me: Inside Third Party Trackers' Exfiltration of PHI from Healthcare Providers' Online Systems
All Eyes On Me: Inside Third Party Trackers' Exfiltration of PHI from Healthcare Providers' Online Systems
复制标题
所有人都在关注我:第三方追踪者从医疗保健提供商的在线系统中泄露 PHI 的内部情况
DOI:
10.1145/3559613.3563190
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Levchenko, Kirill
中科院分区:
文献类型:
--
作者:
Huo, Mingjia;Bland, Maxwell;Levchenko, Kirill
In the United States, sensitive health information is protected under the Health Insurance Portability and Accountability Act (HIPAA). This act limits the disclosure of Protected Health Information (PHI) without the patient's consent or knowledge. However, as medical care becomes web-integrated, many providers have chosen to use third-party web trackers for measurement and marketing purposes. This presents a security concern: third-party JavaScript requested by an online healthcare system can read the website's contents, and ensuring PHI is not unintentionally or maliciously leaked becomes difficult. In this paper, we investigate health information breaches in online medical records, focusing on 459 online patient portals and 4 telehealth websites. We find 14% of patient portals include Google Analytics, which reveals (at a minimum) the fact that the user visited the health provider website, while 5 portals and 4 telehealth websites contained JavaScript-based services disclosing PHI, including medications and lab results, to third parties. The most significant PHI breaches were on behalf of Google and Facebook trackers. In the latter case, an estimated 4.5 million site visitors per month were potentially exposed to leaks of personal information (names, phone numbers) and medical information (test results, medications). We notified healthcare providers of the PHI breaches and found only 15.7% took action to correct leaks. Healthcare operators lacked the technical expertise to identify PHI breaches caused by third-party trackers. After notifying Epic, a healthcare portal vendor, of the PHI leaks, we received a prompt response and observed extensive mitigation across providers, suggesting vendor notification is an effective intervention against PHI disclosures.
登录
查看更多内容
DOI:
--
发表时间:
2019
期刊:
Network and Distributed System Security Symposium
影响因子:
--
作者:
Luis Vargas;Logan Blue;Vanessa Frost;Christopher Patton;Nolen Scaife;Kevin R. B. Butler;Patrick Traynor
通讯作者:
Patrick Traynor
DOI:
--
发表时间:
2006
期刊:
Asia-Pacific Computer Systems Architecture Conference
影响因子:
--
作者:
D. Baker
通讯作者:
D. Baker
DOI:
--
发表时间:
2021
期刊:
WPES@CCS
影响因子:
--
作者:
Vera Wesselkamp;Imane Fouad;C. Santos;Yanis Boussad;Nataliia Bielova;A. Legout
通讯作者:
A. Legout
DOI:
--
发表时间:
2011
期刊:
Conference on Computer and Communications Security
影响因子:
--
作者:
D. Garg;Limin Jia;Anupam Datta
通讯作者:
Anupam Datta
DOI:
10.1007/978-3-319-15509-8_21
发表时间:
2015
期刊:
2012 IEEE Symposium on Security and Privacy
影响因子:
--
作者:
Tai;Huy Hang;M. Faloutsos;P. Efstathopoulos
通讯作者:
P. Efstathopoulos