Blue Shield of California Reports Major Data Breach Impacting 4.7 Million Members
Blue Shield of California has announced a major data breach affecting approximately 4.7 million members — the majority of its nearly 6 million customers.
The breach occurred due to a misconfiguration of Google Analytics on the insurer’s websites, which inadvertently shared protected health information (PHI) with Google’s advertising platforms over nearly three years, from April 2021 to January 2024.
The company discovered the issue during an internal review on February 11, 2025, identifying that sensitive member data had been improperly exposed to Google Ads, potentially enabling targeted advertising.
“On February 11, 2025, Blue Shield discovered that, between April 2021 and January 2024, Google Analytics was configured in a way that allowed certain member data to be shared with Google’s advertising product, Google Ads, that likely included protected health information,” the company stated in its breach notification.
Details of the Exposed Data Include:
- Insurance plan name, type, and group number
- City, ZIP code, gender, and family size
- Blue Shield-assigned online account identifiers
- Medical claim service dates and providers
- Patient names and financial responsibility information
- “Find a Doctor” search queries and results
Blue Shield emphasized that no Social Security numbers, driver’s license numbers, or banking and credit card information were compromised. The company also confirmed that “no bad actor was involved,” and that Google has not shared the data externally.
This incident highlights growing concerns about HIPAA compliance with online tracking technologies. HIPAA requires health organizations to safeguard PHI and secure Business Associate Agreements (BAAs) with any third-party vendors handling such data. Google, however, explicitly states that Google Analytics is not HIPAA-compliant and does not provide BAAs — making its use on healthcare-related web pages particularly risky.
Security experts point to technical misconfigurations and a lack of transparency into data collection as root causes.
“Many healthcare companies are caught unaware of potential data privacy problems because they either don’t fully know what their analytics tools are collecting, or they don’t know how to set up Google Analytics correctly,” said Ian Cohen, CEO of Lokker.
Following the discovery, Blue Shield severed the connection between Google Analytics and Google Ads in January 2024 and initiated a full security review of its websites and protocols. The company advises affected members to monitor account statements and credit reports for unusual activity.
This is Blue Shield’s second major IT security incident within a year. In 2024, the BlackSuit ransomware group compromised nearly one million members’ data by targeting Connexure, a Blue Shield software solutions provider.
According to the U.S. Department of Health and Human Services’ Office for Civil Rights, this breach is currently the largest healthcare-related data incident reported in 2025.




