HealthCare.gov Includes Health Data in its own URLs

The website, Healthcare.gov leaks data via referer (mispelled accidentally, but stuck) headers.

When you visit a website in general, the referer codes tells the new loading site, where you came from. Since healthcare.gov stores information in the referer headers, It’s easy to glean personal information.

healthcaregovlogo

With healthcare.gov, information is automatically sent to 14 other websites, some of which are advertising companies who specialize in user profiling.

Here is an example URL.

https://www.healthcare.gov/see-plans/85308/results/?age=45&smoker=0&parent=&pregnant=0&mec=&zip=85308&state=AZ&income=32500&

It’s not that big of a deal, except that they violate their own rules of privacy, the information won’t be protected because it’s not ‘sensitive’, but eventually it can all be correlated and put together to profile you… Cyberprofiling…

Maybe it is a big deal…

This entry was posted in Security Blog and tagged , , , , , , , . Bookmark the permalink.