{"database": "press", "table": "releases", "rows": [["https://www.warner.senate.gov/public/index.cfm/pressreleases?ID=03CEBFC8-5E76-45A6-A8A1-1899690412B6", "Warner Expresses Concern Over Meta's Collection of Sensitive Health Information", "2022-10-20", "2022", "2022-10", "Democrat", "Senate", "VA", "Mark R. Warner", "W000805", "www.warner.senate.gov", "warner", "https://www.warner.senate.gov/public/index.cfm/pressreleases", "scraper", "WASHINGTON \u2013 Today, U.S. Sen. Mark R. Warner (D-VA) wrote to Meta CEO Mark Zuckerberg expressing concern and requesting more information regarding Meta\u2019s practice of collecting user\u2019s health information through tracking applications.\n\nIn the letter, Sen. Warner highlighted the need for user privacy and increased transparency around how user data is collected online, which has become increasingly important as the use of telehealth appointments, online appointment booking, and electronic record keeping have risen exponentially over the course of the pandemic.\n\n\u201cAs we increasingly move health care online, we must ensure there are strong safeguards in place surrounding the use of these technologies to protect sensitive health information,\u201d wrote Sen. Warner.\n\nSpecifically, Sen. Warner called attention to Meta Pixel, a tracking tool that sends Meta a packet of data whenever a user clicks a button to schedule a doctor\u2019s appointment \u2013 without the knowledge of the individual making the appointment.\n\nHe continued, \u201cI am troubled by the recent revelation that the Meta Pixel was installed on a number of hospital websites \u2013 including password-protected patient portals \u2013 and sending sensitive health information to Meta when a patient scheduled an appointment online. This data included highly personal health data, including patients\u2019 medical conditions, appointment topics, physician names, email addresses, phone numbers, IP addresses, and other details about patients\u2019 medical appointments.\u201d\n\nSen. Warner also noted allegations that this practice of data harvesting and collection has been used by Meta to target advertisements across their platforms. In August of this year, two lawsuits were filed against the company over the alleged unlawful collection and sharing of health data without consent.\n\nTo address these concerns, Sen. Warner requested Meta respond to the following questions:\n\nWhat information does Meta have access to or receive directly from the Meta Pixel, either currently or previously?\n\nHow does Meta store information received through the Meta Pixel?\n\nHas information Meta received from the Meta Pixel ever been used to inform targeted advertisements on Meta\u2019s platforms?\n\nHow does Meta handle sensitive information that it receives from third parties that violate its business guidelines?\n\nWhat steps is Meta taking to safeguard sensitive health information, particularly with third-party vendors? Since the release of The Markup\u2019s report in June, what additional steps have been taken?\n\nAccording to the report released by the New York State Department of Financial Services last year, Meta stated that the filtering system was \u201cnot yet operating with complete accuracy.\u201d What improvements have been made to make the filtering system more effective? How is Meta testing and evaluating the filtering system\u2019s ability to identify sensitive health information?\n\nWhere required by law, does Meta always comply with any and all notification requirements when the Meta Pixel handles or transmits protected information, in the manner and time required by such laws?\n\nSen. Warner has been a leader in Congress pushing for increased transparency and protections surrounding user data and privacy. He introduced the DASHBOARD Act, which works to increase transparency around data collection; the DETOUR Act, which would prohibit companies like Meta from using deceptive dark patterns to manipulate users into handing over their data; and the Public Health Emergency Privacy Act, which would set strong and enforceable privacy and data security rights for health information.\n\nA copy of the letter can be found here and below.\n\nOctober 20, 2022\n\nDear Mr. Zuckerberg:\n\nI write to you today to express my concern regarding Meta\u2019s collection of sensitive health information through the Meta Pixel tracking tool without user consent.\n\nAs you know, I have long worked to protect user privacy and increase transparency around how user data is collected and shared. This mission is more urgent than ever as the last two years have shown us the importance of health care technology, with many relying on electronic health records, online appointment booking, and virtual patient portals to receive care during the pandemic. As we increasingly move health care online, we must ensure there are strong safeguards in place surrounding the use of these technologies to protect sensitive health information.\n\nI am troubled by the recent revelation that the Meta Pixel was installed on a number of hospital websites \u2013 including password-protected patient portals \u2013 and sending sensitive health information to Meta when a patient scheduled an appointment online. This data included highly personal health data, including patients\u2019 medical conditions, appointment topics, physician names, email addresses, phone numbers, IP addresses, and other details about patients\u2019 medical appointments. Additionally, of particular concern are the recent allegations that Meta has used Meta Pixel data to inform targeted advertisements on Meta\u2019s platforms. The use of the Meta Pixel is widespread, as the tool was installed in the systems of 33 of the top 100 hospitals in the country and inside the patient portals of seven health systems at the time of the investigation.\n\nUnfortunately, privacy issues involving the Meta Pixel are not new, as there has been previous scrutiny of the Meta Pixel outside of the health care context. Reports published earlier this year found that the Pixel sent personal information to Meta that was collected from the Free Application for Federal Student Aid (FAFSA) on the website of the Federal Student Aid (FSA) office within the U.S. Department of Education. Data sent to Meta includes applicant first and last name, email addresses, and zip codes. Additionally, this is not the first time that your company has been involved in the wrongful collection of sensitive health information. In 2021, an investigation by the New York State Department of Financial Services found that Meta (then Facebook) collected user data from several health and wellness apps, including results from blood pressure and heart rate readings, menstruation and fertility tracking, pregnancy status, and other deeply personal information.\n\nMeta\u2019s own business guidelines state that the company \u201c[doesn\u2019t] want websites or apps sending [Meta] sensitive information about people,\u201d including sensitive health information, which Meta identifies as medical conditions, sexual and reproductive health, mental health, details regarding medical devices and trackers, treatments, test results, body specifications or cycles, locations of treatment, and other health-related data. Yet, in this most recent case and as we have seen previously, Meta is continuing to access this highly sensitive information.\n\nIt is critical that technology companies like Meta take seriously their role in protecting user health data. Without meaningful action, I fear that these continuing privacy violations and harmful uses of health data could become the new status quo in health care and public health.\n\nTo address the concerns raised in this letter, I request that you provide responses to the following questions by November 3, 2022:\n\nWhat information does Meta have access to or receive directly from the Meta Pixel, either currently or previously?\n\nHow does Meta store information received through the Meta Pixel?\n\nHas information Meta received from the Meta Pixel ever been used to inform targeted advertisements on Meta\u2019s platforms?\n\nHow does Meta handle sensitive information that it receives from third parties that violate its business guidelines?\n\nWhat steps is Meta taking to safeguard sensitive health information, particularly with third-party vendors? Since the release of The Markup\u2019s report in June, what additional steps have been taken?\n\nAccording to the report released by the New York State Department of Financial Services last year, Meta stated that the filtering system was \u201cnot yet operating with complete accuracy.\u201d What improvements have been made to make the filtering system more effective? How is Meta testing and evaluating the filtering system\u2019s ability to identify sensitive health information?\n\nWhere required by law, does Meta always comply with any and all notification requirements when the Meta Pixel handles or transmits protected information, in the manner and time required by such laws?\n\nI look forward to your prompt responses.\n\nSincerely,\n\n###", 1, "2026-03-30T01:40:41Z", "2026-04-06T18:34:28Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.warner.senate.gov/public/index.cfm/pressreleases?ID=03CEBFC8-5E76-45A6-A8A1-1899690412B6"], "units": {}, "query_ms": 1.2039260473102331, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}