Pixel-sized trackers on 20 US state-run health insurance exchanges transmitted applicants' race, sex and citizenship information to major ad-tech firms, a Bloomberg investigation found. The trackers were linked to Google, Meta, LinkedIn, Snap and TikTok and sometimes carried other sensitive fields, according to the report. Washington, D.C. Paused a TikTok pixel rollout and Virginia removed a Meta tracker after the findings, highlighting how simple web tools can expose large numbers of people using government health sites.

A Bloomberg-led review of state health exchange websites found that pixel-sized trackers were embedded across most of the 20 state-run marketplaces. Those pixels are small pieces of code. They're commonly used for web analytics and digital advertising. But when placed on pages that collect medical or demographic information, they can also capture personal details.

The investigation showed trackers connected to major ad and social platforms. The platforms named include Google, LinkedIn, Meta, Snap and TikTok. This review said some marketplaces transmitted precise application answers. New York's exchange, for example, reportedly shared whether an applicant said they had incarcerated family members. That's sensitive personal information.

Which fields were exposed

Bloomberg reported that the Washington, D.C. Exchange asked applicants about sex and race. TikTok's pixel attempted to redact some of those race fields, but the report said some entries were masked and others were not. A spokesperson for the D.C. Exchange told Bloomberg that residents' email addresses, phone numbers and country identifiers were also passed to TikTok.

Virginia removed a Meta tracker after the investigation found it was sharing ZIP codes with the company. Other states adjusted or removed similar tags once the data flows were reported. Those changes show the findings had an immediate technical and operational impact on state websites.

How pixels work and why they matter

Pixels are tiny snippets of code that send information to third parties when a web page loads. Site owners install them to measure page traffic, spot errors and run targeted advertising. When configured correctly, they help operators understand how users move through a site.

When misconfigured, they can send form answers to the third-party domains that host the tags.

Health exchange sites gather many details from applicants. They often ask for demographic information to determine eligibility and subsidies. The investigation noted that more than seven million Americans purchased health insurance this year through a state exchange. That scale means any leak on an exchange site can affect a large number of people.

Privacy experts and civil libertarians have previously warned that third-party trackers on health sites are risky. The report points out that misconfiguration has already affected private companies. Several telehealth startups and large healthcare providers have notified millions of users in the past after finding that health-related data was swept up and shared with ad tech firms.

But the Bloomberg review highlights a different risk. It shows how trackers embedded on government-run portals can expose citizens' information at scale. Government websites often carry trust signals and are primary access points for public services. When those portals pass personal fields to ad platforms, the exposure moves beyond isolated corporate slip-ups to something that touches public infrastructure.

State responses and technical fixes

Not every state took the same steps. Washington, D.C. Paused use of the TikTok tracker after the findings were reported. Virginia removed Meta's tag when it was found to be transmitting ZIP codes. Other states examined their tags and either tightened configurations or removed third-party scripts.

Those changes are concrete. They show that the presence of trackers isn't always deliberate malfeasance. Sometimes it comes from default analytics setups or vendor tools deployed without full review. Still, the adjustments underline how quickly a technical change can alter data flows when officials act on audit findings.

Ad tech companies generally say pixels are designed for analytics and advertising, not for collecting sensitive health information. The investigation didn't present evidence that the platforms used the specific health answers for targeted campaigns. It did, however, document the transmission of identifiable or sensitive fields from exchange applications to third-party domains.

That distinction matters. Transmitting data is a factual step.

Whether the receiving companies stored, processed or used those fields in particular ways would require further internal records. What's clear from the reporting is that the technical paths existed and that some states closed them after the flows were disclosed.

Lawmakers and privacy regulators in the US have in recent years tightened scrutiny of how health and demographic data are handled online. The new findings are likely to feed into those oversight discussions. They also raise practical questions for state IT teams about vendor vetting, default tag settings and who reviews code before it runs on pages that collect sensitive information.

Public-health advocates emphasise the trust element. Citizens expect government portals to protect their information.

When exchange forms carry fields such as race, sex, incarcerated relatives and citizenship indicators, the public expects strong controls on where that data travels. The investigation suggests those controls were not uniformly applied.

Several states adjusted their sites after the reporting. That response reduced immediate exposure. But the broader technical lesson is about the ease with which third-party scripts can be added and the difficulty of auditing every data path. State websites face the same speed and complexity pressures as private companies, yet they operate critical public services that handle sensitive records.

What this means

Pixel trackers on state-run health exchanges transmitted sensitive application fields to major ad and social platforms, and some states moved to remove or pause those tags after the data flows were uncovered. More than seven million people used a state exchange this year, so the issue affects a large pool of applicants. The disclosures show that routine web tools can create large-scale privacy exposures on government service sites.

Related Articles

Washington, D.C. Paused its TikTok pixel rollout and Virginia removed Meta's tracker after Bloomberg's investigation found state exchanges were sending sensitive application fields to ad-tech companies.

This article was created with AI assistance.