Site navigation

NHS Trusts Shared Patient Data with Meta

Elizabeth Greenberg

,

nhs meta pixel
Twenty NHS Trusts have been found to be sharing private patient data with Meta, according to an investigation by The Observer. 

A new investigation by The Observer has revealed that several NHS Trusts have shared patient data with Facebook parent company, Meta.

The report, issued by The Guardian, uncovered a tracking tool in 20 NHS Trust websites that allows the to share confidential patient information with Meta, despite having no consent and claiming to never do so.

Any data that is found on Meta Pixel can be accessed by Meta and used in their targeted advertising.

The data can be matched to user’s IP address and even their Facebook account, essentially identifying them to Meta.

The tracker collected data from patients who accessed hundreds of NHS websites about a range of topics, including HIV treatment, gender identity services, resources on self-harm, cancer, and even children’s services.

According to The Guardian, millions of patients could have been affected.

Currently, 17 of the 20 NHS Trusts have said they removed Meta Pixel from their sites, with eight issuing apologies to their patients.

While many trusts claimed they had no knowledge they were sending patient data to Facebook when they used the tracking tool to analyse their campaigns, the Information Commissioner’s Office (ICO) is investigating further.

Privacy experts are understandably alarmed at the prospect of patient data being shared with the major tech conglomerate.

According to the Guardian, the data sent to Facebook potentially includes ‘special category health data,’ which is protected under law and is illegal to share without consent or another lawful basis.

While Facebook says it does not allow organisations to send it sensitive health information and has mechanisms to sort through this data, it is impossible to track how such information is used once it reaches Meta’s servers.

In their investigation, The Observer performed ‘tests’ to determined how data was transferred to Facebook from the NHS webpages – in most cases, the information was sent automatically when the website was loaded, even before the user could select their cookies preferences.

Further, only three Trusts had privacy policies mentioning Facebook and Meta.


Recommended


Wolfie Chrisl, a data privacy campaigner, told The Guardian: “This should have been stopped by regulators a long time ago. It is irresponsible, even negligent, and it must stop.”

He went on to say that Meta was not doing enough to monitor the data pages shared with them: “Meta says we don’t permit certain types of data being sent to us but they haven’t spent enough on resources to audit this.”

Meta stipulated that they had informed the Trusts of the tool’s privacy and data policies, and that the burden was on the Trusts to make sure they complied with relevant data laws.

NHS England has also pushed the issue onto individual Trusts, though a spokesperson did say “The NHS is looking into the issue and will take further action in necessary,” as reported by The Guardian.

Most Trusts say they adopted the Meta Pixel tool in order to track the success of recruitment campaigns – but if these tracking tools were necessary for all the websites regarding specialist medical advice and treatments should be brought to question.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data