The state began investigating Facebook after a 2019 WSJ report claimed that personal health apps, including period and pregnancy tracker app called Flo, were quietly passing data to the social media giant.
Facebook’s official terms had prohibited app developers from giving the company data from children about health and other sensitive topics, but the company told the New York financial services department it had “routinely obtained” such information from developers, going against its own service terms and policies, according to the Feb. 18 report.
Flo Health reached a settlement in January with the Federal Trade Commission in which it said it would now get users’ consent before sharing the health information.
After admitting it had received sensitive data without permission, Facebook rolled out actions to block app developers from providing data that included 70,000 terms related to topics such as sexual health and medical conditions. The company also built a machine learning system to improve its detection of private data, according to the report.
More articles on cybersecurity:
HHS lifts HIPAA penalties in Texas due to winter storm
Scammers post fake vaccine registration website, pose as Ohio health system
Email phishing attack at Michigan clinic exposes 2,500 patients’ info
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.