This repo contains data for our story "We caught 4 more states sharing personal health data with Big Tech".
The Markup and CalMatters used The Markup's Blacklight tool to scan the healthcare exchange websites of 19 states and the District of Columbia. We were looking for sites that shared personally identifying information through ad trackers and third-party cookies. Prioritizing the exchanges that had a greater than average number of trackers and cookies, we navigated each site as we watched activity in the browser's network panel. As we filled forms on the sites, we watched for communication with the platforms that our scans had identified as ad tracker providers. Through this process, we found that the exchange sites of the five states below were sending personal health data to advertising and analytics services.
For each state, we're providing a copy of our initial Blacklight scan, screenshots of the relevant network activity in the browser's network panel, and a HAR file, which documents network activity. HAR files can be read in many modern browsers and with the HAR Analyzer tool.
The network traffic captured in these HAR files was generated as a Markup reporter investigated the site, entering made-up data about people that don't exist. Personally identifying information has been redacted from the HAR files. Any unredacted information that appears to be personally identifying (e.g. names, birth dates, marital status, ethnicity, race, gender) is not real.
All the initial Blacklight scans can be found here, including those for states that we didn't find sharing personal health data.
Our findings for Covered California, the exchange for the State of California, are detailed in our story "How California sent residents’ personal health data to LinkedIn".
The Blacklight scan results for nevadahealthlink.com on April 28, 2025.
The HAR file for nevadahealthlink.com captured on May 19, 2025.
Note: We do not have a HAR file showing the Nevada exchange site sending data to LinkedIn, as shown in the screenshots below.
Showing the following information being sent to LinkedIn:
- The name (Lipitor) and dosage (10 Mg Tab) of medication used by a member of the applying household
- The name (Atovrastatin) and dosage (10 Mg Tab) of medication used by a member of the applying household
- The name (Fluoxetine) and dosage (20 Mg Tab) of medication used by a member of the applying household
- The name (Norethindrone) and dosage (0.35 Mg Tab) of medication used by a member of the applying household
- The name (Spironolactone) and dosage (50 Mg Tab) of medication used by a member of the applying household
Showing the following information being sent to Snapchat:
- The name (Fluoxetine) of medication used by a member of the applying household
- The name (Norethindrone) of medication used by a member of the applying household
- The name (Spironolactone) of medication used by a member of the applying household
The Blacklight scan results for coverme.gov on April 28, 2025.
The HAR file for coverme.gov captured on May 29, 2025.
Showing the following information being sent to Google:
- The name (Fluoxetine) and dosage (20 Mg Tab) of medication used by a member of the applying household
- The name (Spironolactone) and dosage (50 Mg Tab) of medication used by a member of the applying household
- The name (Franklin Memorial) of a hospital used by a member of the applying household
The Blacklight scan results for healthsourceri.com on April 28, 2025.
The HAR file for healthsourceri.com captured on May 21, 2025.
Showing the following information being sent to Google:
- The name (Nguyen) of a doctor used by a member of the applying household
- The name (Smith) of a doctor used by a member of the applying household
- The name (Prozac) and dosage (20 Mg Tab) of medication used by a member of the applying household
- The name (Spironolactone) and dosage (50 Mg Tab) of medication used by a member of the applying household
The Blacklight scan results for mahealthconnector.org on April 28, 2025.
The HAR file for mahealthconnector.org captured on May 8, 2025.
Showing the following information being sent to LinkedIn: