I'm Mary Ann Kolbasak, the executive editor at Information Security Media Group. Today I'm speaking with Ian Cohen, who is CEO of Data Privacy Compliance firm Locker. We're going to be discussing a recent Locker study looking at trends and growing privacy concerns involving the use of tracking code on health-related websites and other related issues. So Ian, I understand that Locker's research analyzed about 3,419 U.S.
websites across four industries, including healthcare, technology, financial services, and retail. What did you look at and how did you conduct the research? We had a very specific number of sites across those four sectors. In addition to those four sectors, we also looked at the S&P 500.
Obviously, some of the companies we looked at in each sector fell into the S&P. And what we were looking for were changes based on what we saw last year, all the lawsuits against healthcare companies based on the Metapixel Video Privacy Protection Act, and what kind of changes had happened in the market since last year as a result of all of that action. We also were looking at based on the guidance that was given by the OCR recently, which was not very specific. We were trying to answer the question, what should companies do?
What's the core problem they're facing? Why is that problem happening and what should they do? And so that was our goal in the study. And what we really wanted to produce was quantifiable material, rather than just stating broadly that X, Y, or Z is a problem.
We wanted to give companies a sense of here's where they sit relative to everybody else. So that was the goal. Obviously, when you do these reports, the takeaways are somewhat emergent. Like you expect certain things, you don't expect other things.
And so that's why we do these studies. And the way we do it, just to be super clear, we use a scanning technology that's core to our own product. And the way it works essentially is we act just like an end user. And that means that we're looking at each one of these sites from the perspective of the end user, a consumer that would come to the site.
And because we're looking at it through the browser, we're seeing exactly what that consumer would see and exactly what trappers that consumer would get. And that's a very important part of doing this kind of study. So what did you find? I mean, what I do understand is that about 33% of the healthcare companies that you research are utilizing meta-pixels, for instance, on their websites.
And I also understand that this percentage fell a little bit since last year. But since one third of healthcare websites are still using these trackers, despite lawsuits and fines and warnings from the FTC and the Department of Health and Human Services, what do you think's going on? Are enough of these companies kind of realizing that they maybe shouldn't be using these trackers, or maybe they should be using them in a different way? I was surprised.
So yes, it fell very high based on the hundreds of lawsuits last year about the meta-pixels. What I really think is going on, when we work with large companies, we can see everything going on. And the company has devoted substantial resources to their privacy program. What I think is largely going on is that a lot of the companies or health care companies, which includes hospitals and non-profits, a lot of them don't likely know that they have the meta-pixels on their site.
I don't believe that the meta-pixels that we're finding is there because of that intention. I think it's more saying it's very difficult to find all these technologies on your site. It's very difficult to see every track around and say, let alone control it. And that's what I really think is going on.
And I think that when we look at new laws like the Washington State, my Health My Data Act, which is requiring specific opt-in consent for any kind of medical data. And that's broadly defined. This is something that companies that still have the meta-pixels on their site must address and more. So I thought, just at the end of the day, that it really goes to just a lack of visibility because of the tool sets they use.
Besides meta-pixels, what other sorts of trackers are being used often on healthcare websites? And what are the differences between the trackers and the concerns? I think the biggest issues we actually saw were the trackers that get caught up in wire-tapping lawsuits. So specifically, I don't mean to focus the whole thing on lawsuits, but because they drive a lot of change and because we're talking about companies and two companies here, I want to address them.
So the types of marketing tools that are called session replay devices. So these are marketing tools that I think most of the people listening already know about, but like crazy akin full story. These are really interesting tools that allow the product and marketing team to optimize their websites by seeing if a consumer can go through a certain kind of form effectively. If you set these up incorrectly, you're tripping over wire-tapping laws in certain states, and California has been a big one, Pennsylvania has been another one.
So I think that the trackers that were doing session replay recording probably were at the top of the list of concerns. The other big one is the Video Privacy Protection Act. And that's a very old law. So the Video Privacy Protection Act was a law that came out in, I think it was 1988 during Robert Bork's Supreme Court confirmation hearing.
And some intrapid reporter got a hold of his blockbuster video records and published his rental history. And so that law has seemingly very little to do with anything going on right now on the internet. That being said, has been used by a lot of private class action lawsuits to sue a company for gathering data through a video player. And so those were kind of the surface level things.
I think our, so what really surprised us was we saw that 67% of the websites now have a consent banner on their site. That's somewhat good. 98% plus over 98% of these websites that have consent banners are dropping cookies and trackers before anybody interacts with the banner. So what that means is if you go to a website, a lot of stuff is actually being loaded into your browser that can track you before the consent, before you have any interaction with the consent banner.
And that's going to be a huge problem based on what's going on with laws like the Washington My Help My Data Act in Nevada in Connecticut. So I think for the healthcare organizations and hospitals in particular, this is something that just has to change. So I thought that my takeaway from seeing a consent banner, seeing the failure rate, it really led to, I think, bigger issue that there's just a lack of consistent rules and guidance. And I don't think it's a surprise why that exists.
There's a lot of confusion amongst companies about exactly what they're supposed to do because you've got guidance coming from the federal level. And it's not necessarily very clear all the time. But the states are the ones who are actually driving most of the privacy laws right now. So you're navigating a bit of a maze right now.
And an area that's hard, just intrinsically hard to see, let alone control. So I, what we walked away with was, I think to give you a single headline in this, a lot of stuff is going into companies either don't know about or cannot control with what they're currently doing. And I think that's really at the forefront of why you still see 33% of the sites with the meta pixel on it. And if you add up all the social trackers, you know, you're talking about a number close to 60%.
So yeah, it's not a simple problem to solve, but we're getting to a point where every company, at least in healthcare and most retail and financial services just have to deal with these problems head on. So when it comes to the video, what sort of trackers are we talking about? Is it like TikTok? What sorts of issues?
Yeah, exactly right. So if I put up a video on my site and then that video, TikTok or Facebook grabbing data through the video player or in conjunction with the video player, that is enough for the Video Privacy Protection Act to kick in. And I think that we're starting to see more and more of those lawsuits getting thrown out. But I think just basic hygiene for any healthcare website for sure.
And any retail website that has a healthcare component to it, best practice. Don't have the benefits on your site at all. Don't have a TikTok pixel on your site at all. And just to start with a kind of like zero base budgeting.
If there's nothing wrong with running a marketing program, there's nothing wrong with being transparent about the data you are going to use to serve up good content to people. But there's a lot of unwanted trackers ending up on these sites. And that's really the problem. It's not that the sites are going and placing the meta pixel or the TikTok pixel on the website.
It's that they're getting served by a downstream tracker so that a company will put a tracker on their site or analytics to what I want to call everything a tracker. And that tracker will in turn drop another tracker, not because cloud software is using other cloud software. And that second tracker will go ahead and drop its own tracker. So you get this growing exponential effect of trackers that are further and further out from the visibility of the website owner.
So Ian, I also understand that there's a risk of third party brokers sharing the sensitive data that's collected through the trackers with foreign adversaries such as China, Russia, Iran. What did you find? Yes, so directly sharing exactly, right? And this has to do with the Biden executive order.
But I think just common sense is most US companies do not want to be sharing data with Iran, Russia, China, North Korea, Cuba, and then Venezuela at times. So most websites in addition to that have contractual limitations based on their different vendors and partners that prohibit data going to other countries. So most sites have a suppression list of countries they can't send data to. What we found was 2% of the websites have web trackers actually coming from China or Russia.
And it might not sound like a giant number, but when you think about over 100 million businesses in the US, and if you start slicing that by larger businesses, you're still talking about millions and millions of businesses. So that's a big number, 2%. And we saw the largest number of those trackers in tech. We saw 6.46% of tech websites were sending data to either Russia or China and 2.7% of the S&P 500.
I'll give it to healthcare. Healthcare had 0.5%. So healthcare was the best of the bad. So I think that's part of it.
The second component that I think people have to start taking into consideration is that 12% of the websites had a TikTok pixel embedded on their platforms. And so this means on retail, 24.7% of the sites had a TikTok pixel across 10%, 8.7%, 4.4% of healthcare websites. And I think the reason why it's a concern is kind of obvious. One, you have the executive order about don't share data with the following countries.
Full stop. And then you have the house that just passed the ban on TikTok, which may or may not actually become a law, and if it does become a law, it may get challenged. But I still think there are a number of sites you don't need a law to not share data with TikTok, particularly if they're a hospital or regulated entity. So I found that kind of disturbing.
So 2% of the sites were sending data directly or getting requests for data from Russia and China, and 12% on top of that had the TikTok pixel. So yeah, I think overall, really, we expect it to see a lot more improvement than we did. And we saw some improvement, but we really expect to see a whole lot more. And I think what's coming this year with some of these new laws in the way they're enforced with private rights of action, I think there's some pain coming.
And so we're hoping the reports eye opening for people and that they can understand a little bit better what they should go back and check on their own sites to see. So with that said, Ian, what steps can healthcare sector entities take to assess their use of trackers? And if they haven't done that already, how do they get started? They have to do a complete inventory of all their, I'm going to call them digital objects.
And here's why we talk about cookies, but there's a lot more going on. There's cookies, there's pixels, we read about the meta pixel, there's trackers, there's beacons, there's tags. You just need a complete inventory. That's step one.
And sit down and make sure, first and foremost, number one, that these are the folks that you actually have a contract with. Because if you don't, it's not giving you any benefit. And you're sharing data with a third party that you have no knowledge of. Number two, it changes almost every day.
So even if you're using a consent manager, this is very important to keep in mind. So if I run a report to verify whether or not a consent manager is actually doing everything it's supposed to do, I don't have an exact percentage. But most of the time, we find four problems. Number one, we see that they're just missing trackers altogether.
It just didn't get picked up because you might look at it one day. And the next day, it's a very dynamic ad tech ecosystem that trackers will change. Number two, the categorization of that tracker isn't known. So it gets served up even though a customer hits reject all, which is going to number three, which is the fact that after you reject all, you got to make sure it's really doing that.
And the only way that that can be done is if you constantly keep your list up to at least weekly. So you ask for advice, you always have all the trackers in your site. Get rid of any of the ones that are not ones you actually do business with. Make sure that any pages that have formed data on it where a customer, particularly a patient, might be entering a form, do not have trackers on them.
And frankly, you're going to have to get some new tools because you need real-time detection these days. You can't just run something once a month or once a quarter. It doesn't work. I think it's always best, as a general rule, and we've all said this over and over again, data minimization is always a really good thing.
We often find it we're collecting a lot more data than we want or need. And it's just putting our companies at risk and the consumers privacy at risk for no real upside. So data minimization is always a good play. And finally, and there's a lot of privacy issues concerning web trackers and similar sort of tracking technology.
Are there any security issues that you should also be aware of related to their use? Yeah, they can get very serious, like the mage card attacks, if you write about those. You know, those are happening because of piggybackers. So I'll be really specific.
So a piggybacker is a script that's, as the word suggests, piggybacking on another script. So you might build your site using tools like Datadog and Tableau and use a bunch of analytics tools like Google Analytics and marketing tools in that whole stack. As I said, all these pieces of cloud software use other cloud software. So the environment's right for a third party to piggyback.
Now, sometimes the piggybacking is as simple as, okay, well, I got a track right, didn't know existed. I'll get rid of it. It's harmless. But what you're doing is essentially, you're leaving a section of your stack unmonitored.
So a piggybacker can be a lot worse. A piggybacker can be an intrusion. And so in general, like cyber security, roll on is a lower your surface area. And that that is the same as data minimization lower the surface area, the number of dependencies you have on your page, because each one of those is a responsibility you have to keep up with.
So there's security issues there. And the main one is that somebody can exfiltrate sensitive consumer data. So if you've looked at some of the bigger serious breaches in the past, oftentimes they have to do with a third party that essentially was there for a good purpose, like collecting a donation or a piece of form software or a point of sale software. And a piggybacker is there basically branching off the data and grabbing their own copy of that data.
And so I could talk to you about many other risks, but that's the main one I'd say, to be very aware of. Well, thank you so much, Ian. I've been speaking to Ian Cowen. I'm Mary Ann Cobis at McGee of Information Security Media Group.
Thanks for joining us.