Letter to Mark Zuckerberg, CEO of Meta Platforms, Inc. - Warner Expresses Concern Over Meta's Collection of Sensitive Health Information

Letter

Date: Oct. 20, 2022
Location: Washington, DC

Dear Mr. Zuckerberg:

I write to you today to express my concern regarding Meta's collection of sensitive health information through the Meta Pixel tracking tool without user consent.

As you know, I have long worked to protect user privacy and increase transparency around how user data is collected and shared. This mission is more urgent than ever as the last two years have shown us the importance of health care technology, with many relying on electronic health records, online appointment booking, and virtual patient portals to receive care during the pandemic. As we increasingly move health care online, we must ensure there are strong safeguards in place surrounding the use of these technologies to protect sensitive health information.

I am troubled by the recent revelation that the Meta Pixel was installed on a number of hospital websites -- including password-protected patient portals -- and sending sensitive health information to Meta when a patient scheduled an appointment online. This data included highly personal health data, including patients' medical conditions, appointment topics, physician names, email addresses, phone numbers, IP addresses, and other details about patients' medical appointments. Additionally, of particular concern are the recent allegations that Meta has used Meta Pixel data to inform targeted advertisements on Meta's platforms. The use of the Meta Pixel is widespread, as the tool was installed in the systems of 33 of the top 100 hospitals in the country and inside the patient portals of seven health systems at the time of the investigation.

Unfortunately, privacy issues involving the Meta Pixel are not new, as there has been previous scrutiny of the Meta Pixel outside of the health care context. Reports published earlier this year found that the Pixel sent personal information to Meta that was collected from the Free Application for Federal Student Aid (FAFSA) on the website of the Federal Student Aid (FSA) office within the U.S. Department of Education. Data sent to Meta includes applicant first and last name, email addresses, and zip codes. Additionally, this is not the first time that your company has been involved in the wrongful collection of sensitive health information. In 2021, an investigation by the New York State Department of Financial Services found that Meta (then Facebook) collected user data from several health and wellness apps, including results from blood pressure and heart rate readings, menstruation and fertility tracking, pregnancy status, and other deeply personal information.

Meta's own business guidelines state that the company "[doesn't] want websites or apps sending [Meta] sensitive information about people," including sensitive health information, which Meta identifies as medical conditions, sexual and reproductive health, mental health, details regarding medical devices and trackers, treatments, test results, body specifications or cycles, locations of treatment, and other health-related data. Yet, in this most recent case and as we have seen previously, Meta is continuing to access this highly sensitive information.

It is critical that technology companies like Meta take seriously their role in protecting user health data. Without meaningful action, I fear that these continuing privacy violations and harmful uses of health data could become the new status quo in health care and public health.

To address the concerns raised in this letter, I request that you provide responses to the following questions by November 3, 2022:

What information does Meta have access to or receive directly from the Meta Pixel, either currently or previously?
How does Meta store information received through the Meta Pixel?
Has information Meta received from the Meta Pixel ever been used to inform targeted advertisements on Meta's platforms?
How does Meta handle sensitive information that it receives from third parties that violate its business guidelines?
What steps is Meta taking to safeguard sensitive health information, particularly with third-party vendors? Since the release of The Markup's report in June, what additional steps have been taken?
According to the report released by the New York State Department of Financial Services last year, Meta stated that the filtering system was "not yet operating with complete accuracy." What improvements have been made to make the filtering system more effective? How is Meta testing and evaluating the filtering system's ability to identify sensitive health information?
Where required by law, does Meta always comply with any and all notification requirements when the Meta Pixel handles or transmits protected information, in the manner and time required by such laws?
I look forward to your prompt responses.

Sincerely,


Source
arrow_upward