Nearly all of the 20 state-run health insurance exchanges in the US have added advertising trackers that transmit user activity back to big tech companies, in some cases sending more data than state officials realized. Bloomberg News reviewed thousands of enrollment and informational webpages across these sites, as well as the Washington, DC exchange,
What the Documents Show
The scope of data transmission exceeded what many state officials themselves realized was occurring on their own systems. When Bloomberg informed states about the extent of data leakage, officials expressed surprise and concern—suggesting this privacy erosion happened without adequate oversight or explicit authorization from those managing these public-facing platforms. The data being transmitted extends far beyond typical advertising metrics. Users visiting state health exchange websites have information about their race, location data, immigration status, and health-related search behavior sent to advertising networks that feed into Meta's and TikTok's targeting systems. This represents a troubling conflation of health privacy with commercial data harvesting.
🔎 Mainstream angle: The corporate press either ignored this story entirely or buried it in a 3-sentence brief. The framing, when it appeared at all, focused on process rather than impact.Follow the Money
The mainstream technology press has largely framed similar discoveries as routine "ad tech" practices, but the specific context here—sensitive health information tied to immigration status and race—elevates the stakes considerably. These aren't voluntary social media users who might reasonably expect tracking; these are citizens attempting to access essential healthcare through government portals. The mechanism enabling this data transfer typically involves third-party services that states contracted to manage advertising or analytics. Rather than limiting these tools to measuring website traffic or campaign performance, the trackers operate with minimal guardrails, passing detailed user information upstream to platforms with documented histories of leveraging sensitive data for microtargeted advertising. Some state officials acknowledged they had not fully reviewed what data was being collected or where it was flowing, indicating a governance vacuum at the state level. Federal oversight of health exchange operations has apparently not kept pace with evolving data practices in the ad tech ecosystem.
What Else We Know
Privacy advocates emphasize the compounding harm: individuals seeking health insurance are not choosing to engage with Meta or TikTok—they're attempting to access government services. The power asymmetry is stark. These individuals cannot opt out without forgoing access to essential information, and they have no way to know their data is being harvested unless they inspect network traffic or read obscure privacy policies. For immigrants navigating the system, the transmission of immigration status data to commercial platforms raises additional concerns about downstream use, data breaches, or integration with other surveillance systems. The broader implication is that the line between public services and commercial data extraction has become dangerously blurred. Americans cannot reasonably expect their visits to government health portals to remain confidential—a baseline expectation that should be non-negotiable.
Primary Sources
- Source: r/privacy
- Category: Tech & Privacy
- Cross-reference independently — don't take our word for it.
What are they not saying? Who benefits from this story staying buried? Follow the regulatory filings, the court dockets, and the FOIA releases. The truth is in the paperwork — it always is.Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.
This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (a FOIA release, an agency's own policy or procurement document, court filings from surveillance litigation, or the wire reporting linked in the body) and reports what that source states, attributed to it — it does not allege intent behind a surveillance program beyond what the record shows. Part of our Surveillance State hub. Found an error? Tell us.
