The Health Data Loophole Nobody Closed

Tuesday 5 May 2026 topic: State health insurance exchanges sharing citizenship and race data with ad tech giants via pixel trackers

Chart chart-1.png

A Bloomberg investigation published this week found that nearly all 20 U.S. state-run health insurance marketplaces, plus Washington D.C., have embedded advertising pixel trackers that silently transmit applicants’ personal data to Google, Meta, TikTok, Snap, and LinkedIn. Over seven million Americans purchased insurance through these exchanges this year. The data flowing out the back door includes race and ethnicity, citizenship and immigration status, sex, ZIP codes, email addresses, and — in New York’s case — page visits indicating whether applicants have incarcerated family members. The story isn’t that pixel trackers are invasive. We’ve known that since The Markup started documenting state health data leaks in 2022. The story is that four years later, the problem has barely been touched — and the regulatory gap that allows it remains wide open.

The HIPAA Illusion

The most common reaction to this story is: “Isn’t that illegal under HIPAA?” It isn’t. As one Hacker News commenter put it bluntly: “HIPAA applies to healthcare professionals and providers, not ad tech companies. And race and citizenship are not personal health-related data.” This is technically correct and practically devastating. HIPAA covers “covered entities” — hospitals, insurers, healthcare providers — and their business associates. State enrollment websites, where millions of Americans enter sensitive personal information to shop for health insurance, fall outside that definition entirely. No federal data privacy law fills the gap. The result is a regulatory no-man’s-land where government websites collect data that would trigger HIPAA violations at a hospital, then leak it to some of the largest surveillance advertising companies on earth.

EPIC (the Electronic Privacy Information Center) published a comprehensive report in January 2026 titled “Beyond HIPAA” that documents this structural failure in detail. Their finding: the health data privacy crisis is driven by “ubiquitous online tracking, unregulated digital technologies, and weak privacy laws” — and it disproportionately harms marginalized communities. When immigration status flows to TikTok’s servers in a country where ICE operates at hospitals and immigration enforcement is intensifying, the harm isn’t theoretical. People retreat from care. They don’t sign up for insurance. They disappear from systems that were designed to help them.

Brittle Filters and Convenient Ignorance

The technical details of the Bloomberg investigation are almost more damning than the headline. When confronted, the tech companies all pointed to their terms of service, which prohibit advertisers from sharing sensitive health data. The compliance burden, they argued, falls on the website operators — the states. But the states, in many cases, don’t understand what the trackers are doing. As cybersecurity researcher Zach Edwards told Bloomberg: “The onus is on them to do it safely. You can’t protect something that you don’t understand.”

TikTok’s filtering is a case study in performative privacy. The company implemented keyword-based filtering to strip sensitive data before it reached their ad targeting systems. But the filter list was crude — it blocked “Asian” and “Black” but not “Cambodian” or “Indian.” When Washington D.C.’s exchange sent race data including “Cambodian” to TikTok, the filter simply didn’t catch it. Edwards called it “a flawed and brittle process for filtering unwanted information.” Meta, meanwhile, had an optional feature linking site visits to Facebook profiles — which allowed them to retarget a Bloomberg journalist with ads based on visits to ten different state exchange sites.

The pattern is consistent: states deploy trackers without understanding them, tech companies implement half-hearted filters and disclaim responsibility, and nobody is accountable because no single entity is legally required to be. Hospital websites, facing actual litigation risk, have reduced tracker usage from 98% in 2021 to 30% in 2025. State exchanges — which handle more sensitive demographic data than most hospital pages — faced no such pressure until journalists started knocking.

What Gets Leaked, and Why It Matters

It’s worth pausing on exactly what kinds of data were shared, because the granularity is striking. New York’s exchange shared page visits during enrollment with TikTok, Meta, Snap, and LinkedIn — including pages about coverage for incarcerated family members. Maryland’s exchange sent visits to pages about noncitizen pregnant residents and DACA recipients to LinkedIn, Snapchat, Google, and Meta. New Mexico’s “Zero Dollar Income Affidavit” page triggered requests to Google’s ad network. Rhode Island’s Medicaid pages sent data to Google, Meta, and Nextdoor.

This isn’t anonymized analytics. It’s behavioral profiling of people navigating government services, mapped to their social media accounts. A person visiting a DACA coverage page in Maryland gets tagged by LinkedIn and Google. Someone checking Medicaid eligibility in Rhode Island triggers a Meta tracking event. The data may not include a name, but it includes enough signals — ZIP code, email, browsing patterns — to identify individuals, especially when cross-referenced with the vast datasets these companies already hold.

The Accountability Gap

Several states removed trackers after Bloomberg’s inquiry. Virginia pulled Meta’s pixel. Washington paused TikTok’s tracker. New Mexico removed one described as a “relic.” California, the only state reviewed that had already cleaned house, removed its trackers in 2025 after an earlier security report. But these are reactive cleanups, not systemic fixes. The Markup has been reporting on this exact problem since 2022 — first catching California, then four more states in 2025. Bloomberg’s 2026 investigation shows nearly every remaining state still had trackers.

The enforcement picture is bleak. The FTC and state attorneys general can pursue consumer protection cases, but the approach is case-by-case and reactive. There is no federal privacy law with teeth. The patchwork of state privacy laws defines “sensitive data” inconsistently and exempts government services in ways that would be absurd if they weren’t so predictable. As EPIC’s Sara Geoghegan told Bloomberg: “It is very harmful that these tracking technologies are so embedded in these sites because people would expect this information to be private.”

The uncomfortable truth is that the pixel tracker problem is a symptom, not the disease. The disease is a digital infrastructure where surveillance advertising is the default, government websites are built with the same tools as e-commerce stores, and nobody — not the states deploying the trackers, not the companies collecting the data, not the regulators who could intervene — is required to stop it. Hospital websites cleaned up their act because they got sued. State exchanges have no such incentive structure. Until they do, seven million Americans’ most sensitive personal data will keep flowing to companies whose entire business model depends on collecting it.

Sources