{"id":24349,"date":"2024-04-18T07:10:06","date_gmt":"2024-04-18T15:10:06","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/04\/18\/news-18079\/"},"modified":"2024-04-18T07:10:06","modified_gmt":"2024-04-18T15:10:06","slug":"news-18079","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/04\/18\/news-18079\/","title":{"rendered":"Mental health company Cerebral failed to protect sensitive personal data, must pay $7 million"},"content":{"rendered":"\n<p>The Federal Trade Commission (FTC) has reached a settlement with online mental health services company Cerebral after the company was charged with failing to secure and protect sensitive health data.<\/p>\n<p>Cerebral has agreed to an order that will restrict how the company can use or disclose sensitive consumer data, as well as require it to provide consumers with a simple way to cancel services.<\/p>\n<p>After a data breach in 2023 Cerebral <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/mental-health-provider-cerebral-alerts-31m-people-of-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">disclosed<\/a> that it had been using invisible pixel trackers from Google, Meta (Facebook), TikTok, and other third parties on its online services since October 2019.<\/p>\n<p>A tracking pixel is a piece of code that website owners can place on their website. The pixel collects data that helps businesses track people and target adverts at them. That\u2019s nice for the advertisers, but the combined information of all these pixels potentially provides a company with an almost complete picture of your browsing behavior and a lot of information about you.<\/p>\n<p>The <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2024\/04\/proposed-ftc-order-will-prohibit-telehealth-firm-cerebral-using-or-disclosing-sensitive-data\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">FTC statement<\/a> claims that by using these tracking pixels, which are invisible to the website visitor unless they look at the underlying code, Cerebral provided the sensitive information of nearly 3.2 million consumers to these third parties.<\/p>\n<p>The complaint points out that to get consumers to sign up for Cerebral&#8217;s services and to provide detailed personal data, the company claimed to offer \u201csafe, secure, and discreet\u201d services, saying that users\u2019 data would be kept confidential.<\/p>\n<p>Also, according to the complaint, the company specifically claimed in many instances that it would not share users\u2019 data for marketing purposes without obtaining people&#8217;s consent.<\/p>\n<p>Many organizations are unclear about how much information the social media companies behind the tracking pixels can gather. In the <a href=\"https:\/\/cerebral.com\/static\/hippa_privacy_breach-4000c6eb21449c2ecd8bd13706750cc2.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Notice of HIPAA Privacy Breach<\/a> Cerebral disclosed that the following data were potentially exposed:<\/p>\n<ul>\n<li>Full name<\/li>\n<li>Phone number<\/li>\n<li>Email address<\/li>\n<li>Date of birth<\/li>\n<li>IP address<\/li>\n<li>Cerebral client ID number<\/li>\n<li>Demographic information<\/li>\n<li>Self-assessment responses and associated health information<\/li>\n<li>Subscription plan type<\/li>\n<li>Appointment dates<\/li>\n<li>Treatment details and other clinical information<\/li>\n<li>Health insurance\/pharmacy benefit information<\/li>\n<\/ul>\n<p>Among other penalties, Cerebral has to refund $5.1 million to customers who were impacted by deceptive cancellation practices and pay a $10 million civil penalty, limited to $2 million due to Cerebral&#8217;s inability to pay the full amount.<\/p>\n<p>The number of breaches concerning health information is shocking. As required by section 13402(e)(4) of the HITECH Act, the Secretary of the US Department of Health and Human Services Office for Civil Rights publishes <a href=\"https:\/\/ocrportal.hhs.gov\/ocr\/breach\/breach_report.jsf\">a list of breaches<\/a> that reveal unsecured protected health information affecting 500 or more individuals.<\/p>\n<p>We have <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2022\/10\/health-care-provider-notifies-patients-of-potential-breach-of-personal-data-due-to-tracking-pixels\">reported<\/a> about similar cases that involved tracking pixels. Research done by <a href=\"https:\/\/themarkup.org\/pixel-hunt\/2022\/06\/16\/facebook-is-receiving-sensitive-medical-information-from-hospital-websites\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">TheMarkup<\/a> in June of 2022 showed that Meta\u2019s pixel showed up on the websites of 33 of the top 100 hospitals in America.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-protecting-yourself-from-a-data-breach\">Protecting yourself from a data breach<\/h2>\n<p>There are some actions you can take if you are, or suspect you may have been, the <a href=\"https:\/\/www.malwarebytes.com\/blog\/personal\/2023\/09\/involved-in-a-data-breach-heres-what-you-need-to-know\">victim of a data breach<\/a>.<\/p>\n<ul>\n<li><strong>Check the vendor&#8217;s advice.<\/strong> Every breach is different, so check with the vendor to find out what&#8217;s happened, and follow any specific advice they offer.<\/li>\n<li><strong>Change your password.<\/strong> You can make a stolen password useless to thieves by changing it. Choose a&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.malwarebytes.com\/computer\/how-to-create-a-strong-password\" target=\"_blank\">strong password<\/a>&nbsp;that you don&#8217;t use for anything else. Better yet, let a&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.malwarebytes.com\/what-is-password-manager\" target=\"_blank\">password manager<\/a>&nbsp;choose one for you.<\/li>\n<li><strong>Enable two-factor authentication (2FA).<\/strong> If you can, use a FIDO2-compliant hardware key, laptop or phone as your second factor. Some forms of&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.malwarebytes.com\/glossary\/multi-factor-authentication-mfa\" target=\"_blank\">two-factor authentication (2FA)<\/a>&nbsp;can be phished just as easily as a password. 2FA that relies on a FIDO2 device can\u2019t be phished.<\/li>\n<li><strong>Watch out for fake vendors.<\/strong> The thieves may contact you posing as the vendor. Check the vendor website to see if they are contacting victims, and verify any contacts using a different communication channel.<\/li>\n<li><strong>Take your time.<\/strong> Phishing attacks often impersonate people or brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.<\/li>\n<li><strong>Set up identity monitoring.<\/strong> <a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\">Identity monitoring<\/a> alerts you if your personal information is found being traded illegally online, and helps you recover after.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"h-check-your-digital-footprint\">Check your digital footprint<\/h2>\n<p><p>Malwarebytes has a new free tool for you to check how much of your personal data has been exposed online. Submit your email address (it\u2019s best to give the one you most frequently use) to our\u00a0<a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">free Digital Footprint scan<\/a>\u00a0and we\u2019ll give you a report and recommendations.<\/p>\n<\/p>\n<div class=\"wp-block-malware-bytes-button mb-button\" id=\"mb-button-7ba16f0b-04e8-4679-9512-2f21a0971dcf\">\n<div class=\"mb-button__row u-justify-content-center\">\n<div class=\"mb-button__item mb-button-item-0\">\n<p class=\"btn-main\"><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=b2c_pro_acq_fy25dfplaunch_171269600960&amp;utm_content=V1\">SCAN<\/a><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">  NOW<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don&#8217;t just report on threats &#8211; we help safeguard your entire digital identit<\/strong>y<\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using <a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\">identity protection<\/a><\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/04\/mental-health-company-cerebral-failed-to-protect-sensitive-personal-data-must-pay-7-million\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The Federal Trade Commission (FTC) has reached a settlement with online mental health services company Cerebral after the company was charged with failing to secure and protect sensitive health data. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[31292,10665,18118,32,5897,27821],"class_list":["post-24349","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-cerebral","tag-ftc","tag-hipaa","tag-news","tag-privacy","tag-tracking-pixels"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24349"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24349\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}