Desk live·
ForensicPost
Breaches/Healthcare/File 22-1020

Advocate Aurora Told 3 Million Patients Tracking Pixels Sent Data to Meta and Google

Advocate Aurora Health told three million patients — its entire patient base — that tracking pixels on its portal, app and scheduling pages had transmitted their information to third-party analytics vendors. Nobody attacked anything.

Constructed geometry · not a chart of case data
JurisdictionUSAMilwaukee, Wisconsinthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetAdvocate Aurora Health
ActorUnattributed
D. Kennedy12 min readConfidence: high3 sources reviewed

In October 2022 Advocate Aurora Health notified patients that tracking technologies installed on its websites, its LiveWell app, its MyChart patient portal and some scheduling widgets had transmitted patient information to third-party analytics vendors. Reporting identifies the technologies as including Meta Pixel and Google Analytics, and the stated purpose as better understanding patient needs and preferences.

A filing with the US Department of Health and Human Services indicated up to three million people could be affected — the organisation’s entire patient base. The tracking was disabled or removed. The organisation later agreed to pay $12.25 million to settle consolidated class action litigation.

This Is A Category The Corpus Did Not Have

Across 700 files this database records intruders, misconfigurations and suppliers. It had no file in which the data left by design, to a party the organisation had chosen, under a contract, for a business purpose.

Nothing was exploited. No credential was stolen and no vulnerability was involved. Somebody in marketing wanted to understand how patients used the portal, and the standard way to do that transmits what the visitor was looking at — which, on a patient portal, is a health matter.

The Affected Count Is The Whole Population

Three million is not a subset that clicked something unusual. It is everyone, because the code ran on the pages everyone uses.

We have recorded total-population exposure at 23-1031, where a mortgage servicer lost every current and former customer, and at 22-0630. Those required an intrusion. This one required a deployment, and the reason the number is round is that the mechanism had no reason to discriminate.

What Consent Was Given

A patient logging into a portal to view test results is performing a clinical act. They are not, in any sense they would recognise, agreeing that the page they opened may be reported to an advertising platform.

We have recorded controls that failed the people who used them at 22-0721 and 23-0808b, where the affected were precisely those who had exercised a privacy option. This is the version where no option was presented at all. The $12.25 million settlement across three million people is roughly four dollars each, which is the arithmetic filed at 25-1031 and 26-0721b.

The Instrument Does Not Fit

This desk grades severity, records dwell time, names actors and traces entry routes. Every one of those fields is empty or meaningless here.

The record below says actor "Not applicable" and vector "Tracking technology, by design", which is accurate and unsatisfying. We noted at 26-0802 that it is built from incidents that announce themselves. This announced itself only because somebody eventually asked what the third-party code on the portal was sending.

How we reported this

Compiled from the organisation’s breach notification, its HHS filing as reported, and contemporaneous coverage and litigation reporting, listed below. What was transmitted in any individual case is not established: the notification described categories of potentially disclosed information rather than confirmed transfers, and this desk does not assert that any specific record reached any specific vendor. Allegations in the class action are pleadings and are not carried beyond the settlement figure. Graded high on the disclosure and the settlement. Corrections: corrections@forensicpost.com.

Sources
  1. Advocate Aurora Health in potential 3 million patient leakThe Register
  2. Advocate Aurora says 3M patients’ health data possibly exposed through tracking technologiesFierce Healthcare
  3. Advocate Aurora Health Settles Pixel Lawsuit for $12.25 MillionHIPAA Journal
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary