A4 Refereed article in a conference publication

Analyzing Third-Party Data Leaks on EU Healthcare Websites




AuthorsRajapaksha, Sammani; Heino, Timi; Puhtila, Panu; Rauti, Sampsa

EditorsTatti, Nikolaj; Kasurinen, Jussi; Päivärinta, Tero

Conference nameAnnual Doctoral Symposium of Computer Science

Publication year2026

Journal: CEUR Workshop Proceedings

Book title Proceedings of the Annual Doctoral Symposium of Computer Science 2025 (TKTP 2025), Helsinki, Finland, June, 2025

Article numberpaper10

Volume4181

eISSN1613-0073

Publication's open availability at the time of reportingOpen Access

Publication channel's open availability Open Access publication channel

Web address https://ceur-ws.org/Vol-4181/paper10.pdf

Self-archived copy’s web addresshttps://research.utu.fi/converis/portal/detail/Publication/515825408

Self-archived copy's licenceCC BY

Self-archived copy's versionPublisher`s PDF


Abstract

In the present-day web-based health services, users often reveal sensitive data concerning their health status. Specifically, this is often the case when using the search function in various online services. Users trust that their data stays confidential and private when using websites. However, at the same time, many online health services use third-party web analytics and other third-party services and libraries, which may put users’ sensitive data in jeopardy. In this study, we analyze 480 web-based health services in the EU area. We conduct a network traffic analysis of the data sent out to third-party services when using the studied health websites and provide an analysis of data leaks. We found that 60.2% of the studied websites leaked URLs without consent from the user. Moreover, 58.9% of the websites that had search functionality leaked search terms to third parties. Our study also highlights some regional disparities in website privacy. Our findings are a stark reminder of the current challenges in protecting users’ personal data in online health services. They highlight the urgent need for web developers and health website maintainers to reassess the used third-party services and fix the privacy issues.


Downloadable publication

This is an electronic reprint of the original article.
This reprint may differ from the original in pagination and typographic detail. Please cite the original version.




Funding information in the publication
This research has been funded by Academy of Finland project 327397, IDA – Intimacy in Data-Driven Culture.


Last updated on 16/03/2026 01:47:09 PM