Do Tech Giants Violate HIPAA by Tracking Trends?

The Social Dilemma of Health (SDoH).

In March 2018, the world was shocked when it became public knowledge that Cambridge Analytica, a company based in the United Kingdom, had used data from Facebook to impact the presidential election in the United States. It turned out that they had also provided data to the groups supporting Brexit in the U.K.

It should not be a surprise that Facebook had shared data on its users for profit. Facebook said they allowed some access to Cambridge Analytica, but the company had used survey questions to hack into Facebook data, in a manner not intended by Facebook. I am dubious about this claim. The old saying in technology is that if the product is free, then the user is the product. 

The business models of Facebook, Twitter, Instagram, and TikTok are similar in that the service to users is free. Companies that wish to advertise on these platforms get the benefit of placing the user’s eyeballs on screens where advertisements are seen. 

First, advertisers get access to the age, race, sex, and lots of other demographic information on the people that click on the advertisers’ “landing pages” from the social media platform. This is the information companies get when you simply access their site. 

Media companies like Facebook also know what social groups you joined and, critically, with whom you are connected. They create user “profiles” with various amounts of sensitive data. 

In the case of Cambridge Analytica, they obtained 87 million Facebook user profiles. Included with these profiles were Facebook pages each user “liked.” Also included in the profiles were the user’s date of birth and location.     

In the case of Google, in exchange for answering users’ Internet searches, the company has information not just on what was searched for, but in many cases, on every location users have been, sometime for years.

Let’s go back to our first observation about social media companies. Users are the product. While Facebook apologized for the Cambridge Analytica breach, what they didn’t say was that they had stopped collecting and selling this data in some fashion.    

In the case of healthcare, I ask the question: does having data, even if it is saved in grouped data, violate the Health Insurance Portability and Accountability Act (HIPAA)? If the manufacturer of a drug used to treat hemophilia knows the number of people searching for its drug by ZIP code, directly or indirectly, does this violate at least the spirit of HIPAA? 

I understand that Facebook and Google hope you believe that they do not maintain data at an individual level. They say that the data they sell to advertisers excludes individual data. I would argue that by simply reviewing enough of the data they sell, advertisers could match data to individuals. This is how collection companies perform “skip tracing:” finding people to collect unpaid accounts. 

I think it is time to look at how much data technology companies have that may constitute a violation of HIPAA. I also think it is time not to consider just individual data, but how data summarized into grouped data may violate HIPAA.  

Facebook
Twitter
LinkedIn

Timothy Powell, CPA, CHCP

Timothy Powell is a nationally recognized expert on regulatory matters, including the False Claims Act, Zone Program Integrity Contractor (ZPIC) audits, and U.S. Department of Health and Human Services (HHS) Office of Inspector General (OIG) compliance. He is a member of the RACmonitor editorial board and a national correspondent for Monitor Mondays.

Related Stories

Special Bulletin

The Undoing of SDoH Reporting

In a sweeping policy shift, the Centers for Medicare & Medicaid Services (CMS) has proposed significant rollbacks to Social Determinants of Health (SDoH) and equity-related

Read More

Leave a Reply

Please log in to your account to comment on this article.

Featured Webcasts

2026 IPPS Masterclass 3: Master MS-DRG Shifts and NTAPs

2026 IPPS Masterclass Day 3: MS-DRG Shifts and NTAPs

This third session in our 2026 IPPS Masterclass will feature a review of FY26 changes to the MS-DRG methodology and new technology add-on payments (NTAPs), presented by nationally recognized ICD-10 coding expert Christine Geiger, MA, RHIA, CCS, CRC, with bonus insights and analysis from Dr. James Kennedy.

August 14, 2025
2026 IPPS Masterclass Day 2: Master ICD-10-PCS Changes

2026 IPPS Masterclass Day 2: Master ICD-10-PCS Changes

This second session in our 2026 IPPS Masterclass will feature a review the FY26 changes to ICD-10-PCS codes. This information will be presented by nationally recognized ICD-10 coding expert Christine Geiger, MA, RHIA, CCS, CRC, with bonus insights and analysis from Dr. James Kennedy.

August 13, 2025
2026 IPPS Masterclass 1: Master ICD-10-CM Changes

2026 IPPS Masterclass Day 1: Master ICD-10-CM Changes

This first session in our 2026 IPPS Masterclass will feature an in-depth explanation of FY26 changes to ICD-10-CM codes and guidelines, CCs/MCCs, and revisions to the MCE, presented by presented by nationally recognized ICD-10 coding expert Christine Geiger, MA, RHIA, CCS, CRC, with bonus insights and analysis from Dr. James Kennedy.

August 12, 2025

Trending News

Featured Webcasts

The Two-Midnight Rule: New Challenges, Proven Strategies

The Two-Midnight Rule: New Challenges, Proven Strategies

RACmonitor is proud to welcome back Dr. Ronald Hirsch, one of his most requested webcasts. In this highly anticipated session, Dr. Hirsch will break down the complex Two Midnight Rule Medicare regulations, translating them into clear, actionable guidance. He’ll walk you through the basics of the rule, offer expert interpretation, and apply the rule to real-world clinical scenarios—so you leave with greater clarity, confidence, and the tools to ensure compliance.

June 19, 2025
Open Door Forum Webcast Series

Open Door Forum Webcast Series

Bring your questions and join the conversation during this open forum series, live every Wednesday at 10 a.m. EST from June 11–July 30. Hosted by Chuck Buck, these fast-paced 30-minute sessions connect you directly with top healthcare experts tackling today’s most urgent compliance and policy issues.

June 11, 2025
Open Door Forum: The Changing Face of Addiction: Coding, Compliance & Care

Open Door Forum: The Changing Face of Addiction: Coding, Compliance & Care

Substance abuse is everywhere. It’s a complicated diagnosis with wide-ranging implications well beyond acute care. The face of addiction continues to change so it’s important to remember not just the addict but the spectrum of extended victims and the other social determinants and legal ramifications. Join John K. Hall, MD, JD, MBA, FCLM, FRCPC, for a critical Q&A on navigating substance abuse in 2025.  Register today and be a part of the conversation!

July 16, 2025

Trending News

Happy National Doctor’s Day! Learn how to get a complimentary webcast on ‘Decoding Social Admissions’ as a token of our heartfelt appreciation! Click here to learn more →

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 2 with code CYBER24