
Advocate Aurora Health discloses data breach, 3 million could be affected
The system says there’s no evidence of fraud or misuse of information. The breach stems from an online tool meant to track patient trends, and other health systems have reported similar incidents.
The Advocate Aurora Health system says the system has suffered a breach affecting patient information.
Advocate Aurora, one of America’s largest non-profit health systems, said in a
Pixels and other technologies on patient portals, available through MyChart and LiveWell websites, and some scheduling widgets, transmitted some patient information, Advocate Aurora said.
As many as 3 million people could be affected, according to the U.S. Department of Health and Human Services Office of Civil Rights. Organizations are required by federal law to notify the health department about breaches of health data that affect 500 people or more.
To date, the Advocate Aurora incident has affected more people than any other breach reported this year to the HHS Office of Civil Rights. Other health systems have recently reported similar breaches involving tracking tools sending data to Facebook.
At this point, Advocate Aurora said its investigation indicates no Social Security numbers, financial account, credit card, or debit card information was involved in the breach.
Advocate Aurora, which serves patients in Illinois and Wisconsin, said it has disabled the pixel technology. The health system said out of caution, it is assuming that all users of Advocate Aurora MyChart accounts, the LiveWell application, and anyone who used the health system’s scheduling widgets, may have been affected.
The system said it hasn’t found any evidence of fraud stemming from the incident, and said the pixels would be very unlikely to result in identity theft or any financial harm. Patients and customers are advised to monitor their financial accounts for any signs of unusual activity.
Advocate Aurora said the following patient information could have been exposed: IP addresses; dates, times, and/or locations of scheduled appointments; type of appointment or procedure; communications with others through MyChart, which may have included first and last name and medical record numbers; information about whether patients have insurance; patients’ proximity to an Advocate Aurora Health location; and, for those with a proxy MyChart account, your first name and the first name of your proxy.
Other hospitals have been using tracking technology on their websites have inadvertantly sent patient information to Facebook.
An analysis found that 33 of Newsweek’s top 100 hospitals were using the Meta Pixel and sending sensitive data to Facebook, according to an investigation by
Meta, Facebook’s parent company, faced questions about the collection of patient data in a Senate committee hearing last month.
Meta has faced a growing number of questions about collecting health information. A complaint filed in California alleges that more than 600 hospital systems and medical provider websites have sent data to Facebook via its tracking tool,
Advocate Aurora said it will continue to examine ways to reduce the risk of unintentional disclosures of patient information. The system said it will use a more robust vetting process before deploying any tracking information on its websites in the future.
Patients are advised they can obtain a free annual credit report by visiting
- Read more:
Ransomware attacks on hospitals are rising
Advocate Aurora operates 27 hospitals and more than 500 sites of care in Illinois and Wisconsin.
Healthcare systems around the country have dealt with breaches of patient information. Millions of Americans have been affected by healthcare breaches this year.
Many hospitals have been affected by breaches that have occurred as
















































