Third-party data leaks on websites of medical condition support associations




Rauti, Sampsa; Carlsson, Robin; Puhtila, Panu; Heino, Timi; Mäkilä, Tuomas; Leppänen, Ville

PublisherOAE Publishing Inc.

2025

 Journal of Surveillance, Security and Safety

6

1

16

2694-1015

DOIhttps://doi.org/10.20517/jsss.2024.15

https://doi.org/10.20517/jsss.2024.15

https://research.utu.fi/converis/portal/detail/Publication/508540384



The internet has become a primary source of health information for many people. For example, the websites of many medical condition support associations, meant for people suffering from various medical conditions, contain information on different medical conditions, treatments, and general health advice. However, accessing such information can be a serious privacy threat for the end user. In this article, we study the privacy of the websites of 18 Finnish medical condition support associations. The websites were analyzed to find leakages of sensitive personal data to third parties. Our investigation concludes that 88.9% of the websites leaked potentially sensitive personal data to third parties, usually private corporations offering web analytics tools such as Google Analytics. Furthermore, we discovered that users are not adequately informed about these data processing activities. We suggest several measures to alleviate third-party data leaks on websites handling sensitive personal data.


This research has been funded by the Academy of Finland project 327397, IDA – Intimacy in Data-Driven Culture.


Last updated on 26/01/2026 02:10:03 PM