Healthcare appointment site Doctoralia, which serves millions of people in Latin America and Europe, sent sensitive information about their medical appointments, including the specialties and names of doctors, to social media companies including TikTok, Google, and LinkedIn, according to a review of its websites.
The Markup and Agência Pública, an investigative journalism nonprofit in Brazil, reviewed multiple website domains operated by the company, which provides services similar to those ZocDoc offers in the United States, letting people looking for healthcare easily search for a variety of providers in the area, then book appointments. As part of a series on web tracking, the review looked at network traffic between Doctoralia domains in multiple countries and popular social media sites.
See our data here
According to the traffic logs, embedded online trackers followed visitors in Brazil, Colombia, Mexico, and other countries from nearly the second they started to search for care, then sent that data to the tech industry for advertising purposes.
If a visitor searched for a gynecologist based in Sao Paolo, Brazil, for example, the website sent searches for provider specialties and other information to Google through its marketing platform. If a visitor continued through to book an appointment, name and other information on the doctor, as well as the date and time of the appointment, was sent to the company.
The path taken in seeking medical care can itself provide clues about health issues that should remain private.
Brazilian gynecologist
Similar data was shared across other countries with other tech giants as well, according to the review. As in Brazil, searches for specialists in Colombia were sent to social media companies. If a user in Cartagena, for example, booked an appointment with a dermatologist, the provider’s name, as well as the data and time of the appointment, were sent to LinkedIn. The same happened with searches for any other specialists.
If a web user in Bogotá booked an appointment with a doctor through Doctoralia, whether a psychologist, dermatologist, or other care provider, information on that appointment was also shared with TikTok. The same happened for users in Mexico.
Doctoralia said it would conduct a detailed review of its online practices but noted it does not monetize patient data.
Still, experts said the information sharing violates privacy expectations and possibly Brazilian law.
“Even without a stated diagnosis, the path taken in seeking medical care can itself provide clues about health issues that should remain private to the patient,” said a Brazilian gynecologist who uses Doctoralia and spoke to Pública and The Markup on condition of anonymity.
For example, a search for gynecology, obstetrics or reproductive care may be related to trying to conceive, a possible pregnancy, infertility, choosing a contraceptive method or concern after a risky sexual encounter, the gynecologist added. In the doctor’s view, even though inference is not the same as diagnosis, the expectation of confidentiality in the relationship between patient and professional should also apply in the digital environment.
“When someone looks for a doctor, a test or a clinic, they are looking for care, guidance, help,” he said. “So there is a legitimate expectation of privacy.”
Was it illegal? Doctoralia promises a “detailed” review
The tracking on Doctoralia started before any personal information such as email addresses or names was entered, but the trackers often tied users to unique IDs. Social media companies say they can tie users’ social media profiles to browsing behavior through such identifiers.
The tracking also happened across providers and borders in Latin America, with some experts telling The Markup and Pública that government agencies may want to scrutinize the practices.
In Brazil, for example, a law provides for stringent privacy rights, especially for healthcare data.
The BreakdownPixel Hunt
This is how you stop data trackers from sucking up your health data
The Markup and CalMatters found multiple ways consumers can block the trackers quietly sending your data to tech companies, including those used on state-run health exchange websites.
“Obviously there is a risk here of permanent tracking based on unique IDs and building profiles that people are not aware of,” said Rafael Zanatta, co-director of Data Privacy Brazil, an advocacy organization. “There could be a massive violation of those fundamental rights.”
Chiara de Teffé, a professor of digital law at the Federal University of Rio de Janeiro, said the protections provided by Brazil’s General Data Protection Law are not limited to diagnoses and medical records. “Behavioral information may receive enhanced protection when, because of its context and the way it is processed, it reveals or allows inferences about aspects of someone’s health,” she says.
Brazil’s Federal Council of Medicine, the agency in charge of regulating and licensing medical professionals, meanwhile, told Pública and The Markup that “booking an appointment does not involve medical confidentiality” and “there is no sensitive data of any kind when a patient seeks a specialist.”
But the country’s National Supplementary Health Agency, which regulates private insurance, said “the medical specialty sought and other appointment-booking information may reveal aspects of a person’s health.”
Arsenia Nikolaeva, a spokesperson for Doctoralia parent company Docplanner, said in a statement that the trackers were used to monitor the company’s own social media campaigns and that Doctoralia “does not use these tools to sell personal data or to operate a commercial data product” and isn’t paid by social media companies for data. But the company said it would review its practices.
“We take the questions raised very seriously and are conducting a detailed technical and legal review of the matters described, including the relevant technical configurations,” Nikolaeva said in an email. “We remain committed to protecting personal data across all the markets in which we operate, and to acting appropriately based on the outcome of that review.”
The social media companies say they have rules against sending sensitive information, including health data, through their trackers. In practice, however, businesses have frequently been caught sending such information.
Sofie Diskin, a spokesperson for Google, said the company has “strict, long-standing policies against collecting private health information or advertising based on sensitive information” and provides customers with tools to help them avoid collecting health data.
A spokesperson for LinkedIn, Brionna Ruff, said the company’s policies “prohibit installation” of its signature tracker, the Insight Tag, on pages that collect sensitive data, and that the company doesn’t want such data.
TikTok didn’t respond to a request for comment.
Despite the tech companies’ policies, however, healthcare businesses have frequently been caught transmitting sensitive data, leading to regulatory scrutiny and a wave of lawsuits in the United States.
Pixel tracking
Since 2022, The Markup has been reporting on the pervasive use of “pixels,” tracking technology that social media companies use to follow web users.
Across the internet, invisible trackers embedded on websites report information on web users to major social media companies.
Companies like Meta, Facebook and Instagram’s parent company, freely offer the code for pixels to businesses and organizations, who place it on their sites. That code can then log data on visitors and transmit it back to the companies.
Those businesses can then target social media ads to customers who interacted with their site. If a person visited the page for a product but didn’t purchase it, for example, a business can send that visitor ads on Facebook for similar products they might be interested in instead. Meta takes payment from the business for the targeted ads.
The use of pixels is widespread, underpinning the economy of the internet by letting businesses target people who they want to reach, including those who might be the most interested in their products.
But tech companies and businesses that rely on pixels have been hammered with criticism e for tracking sensitive personal data. The practice has sparked lawsuits, demands from lawmakers, and regulatory scrutiny.
While social media companies say they don’t want to receive information on health or finances, for example, in practice it happens frequently.
In previous articles, The Markup has found pixel tracking in several potentially sensitive areas, including education, finances, and healthcare. Among other instances, the reviews have found pixels transmitting information from tax filing companies and the Department of Education’s financial aid service.
Pixel Hunt
Facebook Is Receiving Sensitive Medical Information from Hospital Websites
Experts say some hospitals’ use of an ad tracking tool may violate a federal law protecting health information
It isn’t the first time that companies have been in hot water for tracking health data. In 2022, a review by The Markup showed that Facebook was receiving sensitive medical information on appointments for major hospitals. The investigation led to lawsuits and several hospitals quickly changing their practices.
In separate investigations, The Markup found trackers sending information from abortion pill providers and major drug store chains to Meta and other social media companies. (Doctoralia appeared to use Facebook trackers but sent less sensitive information to the company than to others in cases The Markup reviewed.)
Meta and other social media companies have said in the past that they do not want sensitive information sent to them through tools like the pixel. They also say they use tools to automatically identify and filter out potentially confidential information.
But ultimately, the companies are operating inside a black box. While it’s not clear in any particular case what happens after the data is sent, companies can use it to target ads and power their algorithms in the future.
Privacy in Latin America
Doctoralia’s parent company, Docplanner Group, founded in Poland in 2012, says it operates a sprawling platform across 13 countries, from Turkey to Chile, letting 100 million people book 25 million appointments per month across countries, cultures, and languages.
The countries where Doctoralia operates have a patchwork of laws that provide varying protections for web users. In Mexico versus Colombia, for example, different laws and regulatory agencies govern how data is shared and protected.
Not all of the Doctoralia domains that The Markup and Pública tested sent data to social media companies, either. If a visitor to the Spanish version of Doctoralia searched for an appointment, for example, the search was not sent to outside companies in our testing. Doctoralia is based in Spain, where data is protected under the European Union’s General Data Protection Regulation.
In Germany, where Docplanner offers a similar platform, a pop-up allows visitors to turn off any tracking cookies. In the Latin American countries, by contrast, a pop-up informs readers of cookies but doesn’t immediately offer them a way to turn them off.
Unlike the unified law in the European Union, the most stringent privacy protections in Latin America comes from one country, Brazil, which has a comprehensive national privacy law, the General Data Protection Law.
Under the law, companies that process data are required to do so with full transparency on how the data will be used, and users must be given an ability to opt out.
The law also gives special protections to “sensitive” types of data, including demographic and health-related information. If a company handles that data, they must ask for it conspicuously and prominently. Failure to comply with the law can result in action from Brazil’s regulatory body, the National Data Protection Authority.
Zanatta, who works with the Authority as part of a government advisory board, said the tracking highlighted by The Markup and Pública would be something for regulators to examine. “There could be many legal problems here for sure,” he said.