Massive Breach: 4.7 Million Blue Shield Patients’ Health Data Exposed to Google for Nearly 3 Years


# Blue Shield of California Exposes 4.7 Million Members’ Health Data to Google

Blue Shield of California has disclosed a significant data breach affecting 4.7 million members, whose protected health information was inadvertently shared with Google’s analytics and advertising platforms over a nearly three-year period.

The nonprofit health plan, which serves approximately 6 million Californians, revealed that between April 2021 and January 2024, a misconfiguration in Google Analytics allowed sensitive member data to be shared with Google Ads and potentially other advertisers.

“Google may have used this data to conduct focused ad campaigns back to those individual members,” the organization stated in its breach notification.

## Exposed Information

The compromised data includes:
– Insurance plan details (name, type, group number)
– Location information (city, zip code)
– Gender and family size
– Blue Shield account identifiers
– Medical claim details (service dates, providers, patient names)
– Financial responsibility information
– “Find a Doctor” search criteria and results

The health plan confirmed that more sensitive personal information such as Social Security numbers, driver’s licenses, and financial account details were not exposed in this incident.

## Response and Recommendations

Blue Shield discovered the breach on February 11, 2025, and has since reconfigured its analytics settings. The organization has not offered identity theft protection services but recommends that affected members monitor their accounts and credit reports for suspicious activity.

This marks the second major data security incident for Blue Shield of California within a year. In 2023, approximately one million members had their data compromised when BlackSuit ransomware actors breached Connexure, one of the organization’s software providers.

Share This Article