This article was originally published by The Defender — Children’s Health Defense’s News & Views Website.
Google, Microsoft, Facebook, TikTok and the majority of medical and healthcare websites illegally harvest and sell private health information despite a federal crackdown on the practice, according to a new cybersecurity report.
The report, by Toronto-based cybersecurity firm Feroot Security, analyzed hundreds of healthcare websites and found that more than 86% are collecting private data and transferring it to advertisers, marketers and Big Tech social media companies without user consent and in violation of privacy laws.
As patients or consumers browse their favorite or trusted medical websites or sign in to hospital portals to access their private health records, invisible bits of HTML code — called “tracking pixels” — embedded on the websites harvest private information, such as whether patients have cancer, erectile dysfunction or are behind on their hospital bill.
The information is repackaged and sold for a variety of uses, including to companies that target individual users with internet ads, according to the report.
The risk of having personal data scraped is particularly high on log-in and registration pages where internet users supply troves of information, unaware it is being hijacked and sold. More than 73% of log-in and registration pages have invisible trackers that pirate personal health information, the study found.
Approximately 15% of the tracking pixels analyzed by Feroot record users’ keystrokes, harvesting social security numbers, usernames and passwords, credit card and banking information, and an infinite variety of personal health data, including medical diagnosis and treatment.
The study showed that “Google is the absolute dominant collector” of data. Ninety-two percent of the websites loaded on the Google search engine contained data-harvesting technology across wide sectors of the U.S. economy including healthcare and telehealth, banking and financial services, airlines, e-commerce, and the federal and state governments.
The number two offender was Microsoft with 50.4% of websites on its platform hiding tracking tools, with Facebook next at 50.2% percent and TikTok at 7.41% percent and growing fast.
Google, as the driver of its parent Alphabet, the world’s fourth largest company, is often called “the most powerful company in the world.” It counts on advertising, a lifeblood of the global digital economy, for 80% of its revenue.
Microsoft and Facebook “round up the Top 3” of companies that systematically breach data, the report said. Representatives of Google, Microsoft, and Facebook denied their companies used tracking pixels to harvest personal data.
Website owners are responsible for controlling data collection, a Google spokesperson said. Google policy prohibits Google Analytics and advertising customers, including for example hospital or telehealth websites, from collecting health data in violation of the U.S. Health Insurance Portability and Accountability Act (HIPAA). It’s up to the websites to determine “whether they are HIPAA-regulated entities and what their obligations are under HIPAA,” Google policy says.
Personal health data collected by a tracker or third party without a user’s consent is a violation of HIPAA, said Feroot CEO Ivan Tsarynny.
Big Tech companies “do have policies that talk about protecting health info,” Tsarynny said. But “the real-world application of these policies is a different story.”
Feroot’s study comes as “concern grows regarding data mining companies using pixels/trackers that load into browsers from websites to collect privacy and sensitive user data,” the report stated.
“Compliance regulators and government authorities are increasingly stepping in with bans, restrictions, and executive orders to curb them.”
Eighteen major hospital systems were sued this year for sharing patients’ sensitive health data with Google, Facebook and other tech giants in violation of privacy laws, according to Becker’s Hospital Review.
They include prominent academic medical centers such as the University of Pittsburgh Medical Center, the University of Chicago Medical Center, the University of Iowa Medical Center, Chicago-based Northwestern Memorial Hospital and the University of California San Francisco Medical Center.
Prompted by growing concerns over data theft and the article, “‘Out of Control’: Dozens of Telehealth Startups Sent Sensitive Health Information to Big Tech Companies,” Feroot launched an investigation “to ascertain the exact magnitude and pervasiveness of social media pixels/trackers collecting and transferring personal, sensitive, and private data using pixels or trackers.”
The security platform Feroot sells to companies “made it possible to get detailed facts regarding active client-side e-skimming,” the company said.
Feroot collected data on pixels/trackers during an eight-week period in January and February.
The company said it examined more than 3,675 organizations with unique websites in seven economic sectors. It studied 108,836 unique web pages, including especially vulnerable login, registration and credit card processing pages, 227 trackers and 7 million data transfers.
Key findings from ‘Beware of Pixels & Trackers’:
- Pixel trackers are “common and abundant” — an average of 13.16 pixels/trackers were found per website, “with Google, Microsoft, Meta (owner of Facebook), ByteDance (owner of TikTok), and Adobe being some of the most common.”
- “Mission-critical” webpages, such as log-in or registration pages, increase the risk of exposing private information. An average of 5.96% of websites had pixels/trackers on webpages reading user input forms containing privacy or sensitive data.
- Pixel trackers transfer data to foreign locations around the globe — “about 5% of the data transferred by pixels/trackers loaded from US-based websites is sent outside the US.”
- Pixel trackers collect and transfer data without first obtaining the explicit consent of visitors.
- Pixels and trackers are loading from domains banned by the U.S. government and various U.S. states and even from some of those same governments, including Russia and China. Data obtained by Russian and Chinese websites is a security risk from surveillance and spying.
- Meta (owner of Facebook and Instagram) and TikTok, owned by Chinese company ByteDance, were “particularly worrisome” for privacy invasion and surveillance risks. Thirty-four U.S. states, both Republican and Democratic-controlled, have banned the use of TikTok on government devices. Montana in May banned the app on all personal devices.
- TikTok is often present whether or not the TikTok app is deleted. TikTok pixels/trackers can still “load into webpages handling mission-critical user data and can collect and transfer it.”
GoodRX case highlights corporate deceit around data-sharing
While corporations face losing profit and reputation from data breaches or fines for causing them, individuals face a potentially catastrophic loss of privacy when major health websites harvest and sell their information, according to the Federal Trade Commission (FTC).
In February, the FTC fined popular discount drug and telehealth site GoodRx for “failing to report its unauthorized disclosure of consumer health data to Facebook, Google, and other companies.”
The action to “bar GoodRx from sharing consumers’ sensitive health information for advertising” was the FTC’s first enforcement action under its Health Breach Notification Rule.
“Digital health companies and mobile apps should not cash in on consumers’ extremely sensitive and personally identifiable health information,” FTC Bureau of Consumer Protection Director Samuel Levine said in a news release after the settlement. “The FTC is serving notice that it will use all of its legal authority to protect American consumers’ sensitive data from misuse and illegal exploitation.”
The FTC enforcement against GoodRx revealed a particularly egregious, yet not uncommon, example of how corporate health and medical websites betray patient trust and manipulate patient data, the FTC said.
According to the FTC’s complaint, GoodRx violated the law by improperly sharing sensitive personal health information since at least 2017, though it promised otherwise.
The company “deceptively promised its users that it would never share personal health information with advertisers or other third parties,” the FTC charged, and deceptively displayed a seal at the bottom of its telehealth services homepage “falsely suggesting to consumers that it complied with … HIPAA.”
In reality, the FTC complaint said, GoodRx “monetized its users’ personal health information, and used data it shared with Facebook to target GoodRx’s own users with personalized health- and medication-specific advertisements on Facebook and Instagram.”
For example, GoodRx in August 2019 made lists of its users “who had purchased particular medications such as those used to treat heart disease and blood pressure, and uploaded their email addresses, phone numbers, and mobile advertising IDs to Facebook so it could identify their profiles,” according to the complaint.
“GoodRx then used that information to target these users with health-related advertisements.”
People who accessed GoodRx coupons to purchase, for instance, Viagra would see ads for erectile dysfunction medication on their Facebook or Instagram page ads, the FTC says.
“Similarly, people who had used GoodRx’s telehealth services to get treatment for sexually transmitted diseases would get ads for STD testing services.”
GoodRx disclosed to Facebook the medication purchase data it receives from pharmacy benefit managers and also used the data to target ads.
By using Facebook’s ad targeting platform, the FTC said, “GoodRx designed campaigns that targeted customers with ads based on their health information. For example, if a customer had revealed a possible erectile dysfunction issue to GoodRx, they might have seen an ad on Facebook like Exhibit A in the FTC complaint.”

In February, California-based GoodRx, a $2.1 billion company, paid a $1.5 million civil penalty to the FTC to settle the complaint and denied any wrongdoing.
Howard Danzig, founder and president of Employers Committed to Control Health Insurance Costs, said “fining GoodRx just $1.5 million dollars is not even a slap on the wrist. While many employers are so vigilant about respecting the guidelines of the HIPAA privacy laws, large tech companies basically get a pass.”
“How about major penalties for Facebook, Google and any others who were the beneficiaries of this information?” he wrote on his LinkedIn page with almost 9,000 followers.
“How about determining whether or not there were any criminal violations that should be pursued against the individuals who actually collaborated to do this? How about ‘REPARATIONS’ from the companies involved to the people and customers whose privacy was breached?”
The data breach occurred for “advertising purposes,” he noted. “How far afield can this really be taken and how far afield has it been taken?”
This article was originally published by The Defender — Children’s Health Defense’s News & Views Website under Creative Commons license CC BY-NC-ND 4.0. Please consider subscribing to The Defender or donating to Children’s Health Defense.
Bypass Big Tech Censors
Two Storms, One Harvest
Every food crisis in living memory has been a one-shock event. The 2008 price spike was a commodity bubble. The 2020 shortages were a logistics failure. The 2022 grain scare was a war on one exporter’s ports. Each time, the system bent, adjusted, and recovered, and each time the experts assured us afterward that global markets are simply too big and too diversified to fail.
What nobody in Washington seems eager to discuss is that 2026 is shaping up to be something the modern food system has never actually faced. Two independent shocks, one climatic and one geopolitical, are converging on the same harvest cycle at the same time. Not sequentially. Simultaneously.
Start with the weather. The Pacific Ocean is currently building toward what forecasters now openly call a record event. NOAA’s Climate Prediction Center puts the odds of at least a strong El Niño near 88 percent, with roughly two in three odds it reaches “very strong” status, the tier reserved for perhaps three or four events in the entire satellite era. Every major global model now projects a median peak in Super El Niño territory, and most of them project it exceeding the 2015-16 event, which until now held the modern record. Sea surface anomalies were already brushing the super threshold in mid-July, months before these events normally peak. The atmosphere has already shifted into El Niño mode, and the event is forecast to crest in late fall and early winter.
This is not about “climate change.” It’s about the standard cycles of weather, and the cycle we’re currently in is one that has likely devastated societies in the past. We’re better prepared as a society today, but not all Americans are equally prepared.
Serious households have started doing the quiet math on their own. Grocery bills tell part of the story, and the forecast maps tell the rest, which is why long-term food storage has moved from fringe hobby to mainstream line item in the family budget, with established suppliers like Heaven’s Harvest seeing demand from people who five years ago would have rolled their eyes at the idea. That instinct is not paranoia. It is pattern recognition, and the pattern is worth walking through carefully.
Editor’s Note: Heaven’s Harvest IS a sponsor, but the warnings of this article are real and would be written even if we didn’t have a survival food sponsor. With that said, those who take advantage of what they offer can use promo code “Patriot” for 15% off.
The Fertilizer Clock Is Already Running
While the Pacific warms, the second shock has been unfolding in the Strait of Hormuz. The conflict with Iran turned the world’s most important energy chokepoint into a contested waterway, and the consequences reach far beyond the gas pump. Roughly a third of global fertilizer trade moves through Hormuz, and the disruption sent urea prices up 86 percent year over year by March, with a 53 percent jump in a single month.
The World Bank projects energy prices rising about 24 percent in 2026 and fertilizer about 31 percent. By its own accounting, fertilizer prices ran 35 percent higher in the first five months of this year than the same period last year.
Here is the mechanism the nightly news will not explain. Fertilizer is not a grocery item. It is a time-delayed input. The nitrogen a farmer in Iowa or Punjab could not afford to apply this spring does not show up as a problem this spring. It shows up as a thinner harvest six to twelve months later.
The World Bank’s own food security brief concedes that the effects of reduced applications earlier this season “are likely to become visible only later in harvest outcomes.” Translate that from institutional language into plain English and it means this. The damage is already done, it is already in the ground, and we are simply waiting for it to arrive on the shelf.
Now check the calendar. Six to twelve months from the spring planting season lands us squarely in late 2026 and early 2027. Which is precisely when the strongest El Niño in the instrumental record is forecast to peak, bringing its signature droughts to Southeast Asia, Australia, southern Africa, northern Brazil, and South Asia, the very regions that grow the world’s rice, sugar, and oilseeds.
The World Bank warns openly that a strong El Niño “could disrupt multiple crop belts simultaneously” on top of the conflict-driven input costs. Their baseline projection assumes the Middle East disruptions ease by autumn. What in the last two years of Middle East history suggests that assumption is safe?
The System Has No Slack Left
The comfortable answer is that global markets always adjust. But adjustment requires slack, and the slack is gone. Global cereal production is expected to decline from last year’s records even before El Niño does its work. The UN World Food Programme, hardly a den of right-wing preppers, is calling this the most significant disruption to its supply chains since Covid and the invasion of Ukraine, and its supply chain director put the stakes bluntly.
Today’s supply chain challenges are tomorrow’s hunger crisis.
There is also a political dimension that markets cannot price. When food gets scarce, governments do not behave like economists. They behave like politicians. Export bans, hoarding mandates, and panic buying at the national level turned the modest rice shortfall of 2008 into a global crisis, and analysts are already warning that import-dependent nations are the first dominoes.
The 2015-16 Super El Niño, a far weaker event than what is now forecast, threw tens of millions into food stress across Africa and Asia. This one is projected to be stronger, and it arrives with fertilizer already rationed by price and shipping lanes already contested by missiles.
What Joseph Knew
Scripture does not treat preparation for lean years as faithlessness. It treats it as wisdom delivered in advance to those willing to act on it.
Behold, there come seven years of great plenty throughout all the land of Egypt: And there shall arise after them seven years of famine; and all the plenty shall be forgotten in the land of Egypt.
Joseph did not respond to that warning with a hashtag or a committee. He stored grain during the years of abundance, and when the famine came, Egypt stood while its neighbors begged. The lesson is not that famine is certain. It is that the time to prepare is precisely when preparation still looks optional.
Nobody who filled a pantry in a year of plenty has ever regretted it, and nobody standing in an empty aisle has ever been glad he waited for certainty.
None of this calls for panic, and panic is the enemy of sound judgment anyway. It calls for the same unglamorous prudence our grandparents considered ordinary. Keep some cash margin, know your local growers, and put real food in deep storage while it is cheap and available, because the entire arc of this story is that cheap and available is a closing window.
Families looking for a straightforward place to start can visit Heaven’s Harvest and use promo code Patriot for 15 percent off long-term storable food. The forecasts may yet soften, the strait may yet reopen, and we should pray they do. But hope is a fine thing to hold and a foolish thing to eat.



