Cerebral admits to sharing patient data with Meta, TikTok, and Google

Cerebral, a telehealth startup specializing in mental health, says it inadvertently shared the sensitive information of over 3.1 million patients with Google, Meta, TikTok, and other third-party advertisers, as reported earlier by TechCrunch. In a notice posted on the company’s website, Cerebral admits to exposing a laundry list of patient data with the tracking tools it’s been using as far back as October 2019.

The information affected by the oversight includes everything from patient names, phone numbers, email addresses, birth dates, IP addresses, insurance information, appointment dates, treatment, and more. It may have even exposed the answers clients filled out as part of the mental health self-assessment on the company’s website and app, which patients can use to schedule therapy appointments and receive prescription medication.

According to Cerebral, this information got out through its use of tracking pixels, or the bits of code Meta, TikTok, and Google allow developers to embed in their apps and websites. The Meta Pixel, for example, can collect data about a user’s activity on a website or app after clicking an ad on the platform, and even keeps track of the information a user fills out on an online form. While this lets companies, like Cerebral, measure how users interact with their ads on various platforms and track the steps they take afterward, it also gives Meta, TikTok, and Google access to this information, which they can then use to gain insight into their own users.

The exposed information could “vary” from patient to patient.

As noted by Cerebral, the exposed information could “vary” from patient to patient depending on several factors, including “what actions individuals took on Cerebral’s Platforms, the nature of the services provided by the Subcontractors, the configuration of Tracking Technologies,” and more. The company says it will notify affected users, and adds that “no matter how an individual interacted with Cerebral’s platform,” it didn’t expose social security numbers, credit card numbers, or bank account information.

After initially finding the security hole in January, Cerebral says it has “disabled, reconfigured, and/or removed” any of the tracking pixels on the platform to prevent future exposures, and has “enhanced” its “information security practices and technology vetting processes.”

Cerebral is required by law to disclose potential violations of HIPAA, also known as the Health Insurance Portability and Accountability Act. This bars healthcare providers from divulging patient information to anyone else other than the patient, or anyone the patient has consented to receive information about their health. The breach is currently under investigation by the US Office for Civil Rights and follows similar incidents involving pixel-tracking tools.

Last year, an investigation by The Markup found that some of the nation’s top hospitals were sending sensitive patient information to Meta through the company’s pixel. This sparked two class-action lawsuits, which allege Meta and the hospitals in question violated medical privacy laws.

Months later, The Markup also found that Meta was able to obtain financial information about users through the tracking tools embedded in popular tax services, such as H&R Block, TaxAct, and TaxSlayer. Meanwhile, other online medical companies, like BetterHelp and GoodRx got slapped with hefty fines from the FTC for sharing sensitive patient data with third parties earlier this year.

In addition to facing scrutiny over whether or not it has violated HIPAA regulations, Cerebral is facing an investigation by the Department of Justice and the Drug Enforcement Administration over its prescribing of controlled substances, such as Adderall and Xanax. It has since halted the prescription of these medications.

Read More
Emma Roth

Latest

Nestory Irankunda scores Australia’s first World Cup goal against Turkiye

Nestory Irankunda buried Australia’s opening goal of the 2026 FIFA World Cup on June 14, finishing a counter-attack in the 27th minute against Turkiye in Vancouver. At 20 years old, he became the youngest player in Socceroos history to score at a World Cup. The goal gave Australia a 1-0 lead in their Group D

Carlo Ancelotti takes responsibility for Brazil’s 1-1 draw with Morocco as crypto fan tokens enter the World Cup spotlight

Brazil opened their 2026 FIFA World Cup campaign with a 1-1 draw against Morocco on June 13, and Carlo Ancelotti accepted full responsibility for the tactical shortcomings that left the five-time champions splitting points in their Group C opener. Ancelotti promised improvement and reminded everyone that you don’t win a World Cup in your first

Scotland defeats Haiti 1-0 in World Cup opener, tops Group C

Scotland picked up their first World Cup victory in 28 years on June 13, beating Haiti 1-0 in their Group C opener at the 2026 FIFA World Cup. John McGinn scored the only goal of the match in the 28th minute, pouncing on a rebound after Haitian goalkeeper Johny Placide saved an initial effort from

Pyth Network Targets Bloomberg’s $50 Billion Market-Data Empire

Pyth Network is pushing deeper into the more than $50 billion market for financial data, launching 24/7 index products across metals, oil, and U.S. equities as it positions its onchain price feeds against incumbents like Bloomberg. Key Takeaways Pyth Network launched 24/7 indices for metals, oil, and U.S. equities, adopted by Coinbase and Kraken. Euronext

Newsletter

Don't miss

Nestory Irankunda scores Australia’s first World Cup goal against Turkiye

Nestory Irankunda buried Australia’s opening goal of the 2026 FIFA World Cup on June 14, finishing a counter-attack in the 27th minute against Turkiye in Vancouver. At 20 years old, he became the youngest player in Socceroos history to score at a World Cup. The goal gave Australia a 1-0 lead in their Group D

Carlo Ancelotti takes responsibility for Brazil’s 1-1 draw with Morocco as crypto fan tokens enter the World Cup spotlight

Brazil opened their 2026 FIFA World Cup campaign with a 1-1 draw against Morocco on June 13, and Carlo Ancelotti accepted full responsibility for the tactical shortcomings that left the five-time champions splitting points in their Group C opener. Ancelotti promised improvement and reminded everyone that you don’t win a World Cup in your first

Scotland defeats Haiti 1-0 in World Cup opener, tops Group C

Scotland picked up their first World Cup victory in 28 years on June 13, beating Haiti 1-0 in their Group C opener at the 2026 FIFA World Cup. John McGinn scored the only goal of the match in the 28th minute, pouncing on a rebound after Haitian goalkeeper Johny Placide saved an initial effort from

Pyth Network Targets Bloomberg’s $50 Billion Market-Data Empire

Pyth Network is pushing deeper into the more than $50 billion market for financial data, launching 24/7 index products across metals, oil, and U.S. equities as it positions its onchain price feeds against incumbents like Bloomberg. Key Takeaways Pyth Network launched 24/7 indices for metals, oil, and U.S. equities, adopted by Coinbase and Kraken. Euronext

Macron and Trump test their bruised bromance at G7 summit

For help please visit help.ft.com. We apologise for any inconvenience. The following information can help our support team to resolve this issue. Reason Challenge Request ID a0ba469e68afe135 Status Code 403

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID

Business groups are fighting Labor’s CGT changes. Here is where SMEs stand

Labor’s most contested tax reform in a generation cleared its first formal hurdle on Thursday and immediately ran into organised resistance. Treasurer Jim Chalmers introduced the government’s tax reform legislation to the House of Representatives on 28 May, bundling together four budget measures: the capital gains tax overhaul, new limits on negative gearing, a $250

Meet the most influential business owners from Southwest Nigeria

This article spotlights the most influential business owners from Southwest Nigeria, adjudged by their dominance in their respective sectors of the economy where they operate. The post Meet the most influential business owners from Southwest Nigeria appeared first on Nairametrics...