Kaiser Permanente notified 13.4 million current and former members in April 2024 that tracking technologies on its websites and mobile applications may have transmitted their information to third-party vendors, named in reporting as including Microsoft, Google and X.
Reported transmitted data includes names and IP addresses together with how people navigated Kaiser’s sites, apps and health encyclopedia. The organisation removed the tracking code. It later agreed to a settlement reported at up to $47.5 million.
Nobody Attacked Anything
The code was installed deliberately, by the organisation, to understand how members used its services. It did what it was configured to do.
This is the second such case in the file set after Advocate Aurora in 2022, and the pattern is identical: the affected population is everyone, because the code ran on the pages everyone uses. There is no intrusion, no entry route and no actor to name.
Which Page You Opened Is The Medical Fact
A member looking up a condition in a health encyclopedia is not browsing. The page is the thing that reveals what they are worried about, and the navigation record is the diagnosis in all but name.
The settlement works out at a few dollars a head across 13.4 million people. That arithmetic recurs whenever a remedy is divided by a population, and it is the reason a large settlement figure and a meaningful remedy are different things.
Compiled from Kaiser’s notification, public reporting and settlement coverage, listed below. What reached any individual vendor in any individual case has not been established and we are not asserting it. Corrections: corrections@forensicpost.com.