Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

Healthcare Data Breach Exposes 1.3 Million Patients

Healthcare Data Breach Exposes 1.3 Million Patients

Randy Hall By Randy Hall Updated Jul 2024 2 min read Share

Do you make use of the "MyChart" portal to refill prescriptions, contact your healthcare providers or make appointments?

If so, you should know that recently, the healthcare giant Novant disclosed a data breach that impacted more than 1.3 million patients.  Impacted patients had their personal information collected by a Meta Pixel ad tracking script.

Meta Pixel, which was formerly known as Facebook Pixel, is a mostly innocuous tracking script used by Facebook advertisers to track the performance of their ads.

According to Novant's disclosure, the unauthorized access of patient data began in May of 2020 when the company ran a promotional campaign that involved Facebook advertisements.  In a bid to track the effectiveness of those advertisements, Novant utilized the Meta Pixel code.

Unfortunately, the code was not configured correctly on the Novant site, and the company's "MyChart" portal began transmitting personal information to Meta and its advertising partners.

The patient information that may have been exposed includes:

  • Patient Email address
  • Patient Phone number
  • Patient Emergency contact information
  • Appointment type and date
  • Patient physician
  • Portal menu selections
  • IP address
  • And any content typed into the "free text" boxes

Unfortunately, the MyChart portal is not a Novant specific technology.  It is utilized by a total of 64 different healthcare service providers around the country. So even if you don't use Novant to meet your healthcare needs, your personal data may have been compromised due to the misconfiguration of the tracker.

If there's a silver lining to be found in all of this, it lies in the fact that the company has now identified all  the patients whose data was compromised and has already reached out to them.  If you haven't received a notification, then you can breathe a sigh of relief as your data was not compromised.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime