Looking for an at-home HIV test on CVSā website is not as private an experience as one might think. An investigation by The Markup and Ńī¹óåś“«Ć½Ņīl Health News found trackers on CVS.com telling some of the biggest social media and advertising platforms the products customers viewed.
And CVS is not the only pharmacy sharing this kind of sensitive data.
We found trackers collecting browsing- and purchase-related data on websites of 12 of the U.S.ā biggest drugstores, including grocery store chains with pharmacies, and sharing the sensitive information with companies like Meta (formerly Facebook); Google, through its advertising and analytics products; and Microsoft, through its search engine, Bing.

12 drug store websites had trackers
Type of tracker: šāURLs user visited šāWhat shopper added to cart (also includes the URL of the page)
The Markup conducted tests from December 2022 to May 2023. In some cases trackers present on websites changed over time. ā Similar results were found on the websites of ACME and Safeway, which are also owned by Albertsons Companies, Inc.
The Markup analysis
The tracking tools, popularly called āpixels,ā collect information while a website runs. That information is often sent to social media firms and used to target ads, either to you personally or to groups of people that resemble you in demographics or habits. In previous investigations, The Markup found pixels transmitting information from the , , , and .
Pharmacy retailer websitesā pixels send a shopperās IP address ā a sort of mailing address for a personās computer or household internet ā to social media giants and other firms. They also send cookies, a way of storing information in a userās browser that in this case helps track a user from page to page as the user browses a retailerās site. Cookies can sometimes also associate individuals on a site with their account on a social media platform. In addition to the IP address and cookies, the pixels often send information about what youāve clicked or bought, including sensitive items, such as HIV tests.
āHIV testing is the gateway to HIV prevention and treatment services,ā said Oni Blackstock, the founder of Health Justice and a former assistant commissioner for the New York City Bureau of HIV/AIDS Prevention and Control, in an interview.
āPeople living with HIV should have control over whether someone knows their status,ā she said.
Many retailers shared other detailed interaction data with advertising platforms as well. Ten of the retailers we examined alerted at least one tech platform when shoppers clicked āadd to cartā as they shopped for retail goods, a capacious category that included sensitive products like prenatal vitamins, pregnancy tests, and Plan B emergency contraception.
Supermarket giant Kroger, for instance, informed Meta, Bing, Twitter, Snapchat, and Pinterest when a shopper added Plan B to the cart, and informed Google and Nextdoor, a social media platform on which people from the same neighborhood gather in forums, that a shopper had visited the page for the item. Walmart informed Googleās advertising service when a shopper browsed the page of an HIV test, and Pinterest when that shopper added it to the cart.
A previous investigation from The Markup found that Kroger to track, analyze, and sell an array of data about customers to advertisers.
Using Chrome DevTools, a tool built into Googleās Chrome browser, The Markup and Ńī¹óåś“«Ć½Ņīl Health News visited the websites of 12 of the U.S.ā biggest drugstores and examined their network traffic. This monitoring tool allowed us to see what information about shopping habits and, in some cases, prescriptions, were sent to third parties.
Over the course of the investigation, retailers frequently changed their trackers ā sometimes activating them, sometimes removing them. Some retailers appeared to be taking steps to limit tracking on sensitive items.
For example, Walgreensā website prevented some trackers from activating on the pages of some products, which included Plan B and HIV tests. This code didnāt prevent all tracking, though: Walgreensā site continued sending Pinterest information about those sensitive items a user added to the cart.
Walgreens shared a new policy after learning of The Markup and Ńī¹óåś“«Ć½Ņīl Health Newsā findings. Spokesperson Fraser Engerman said that while the chain already had a ārobust privacy program,ā it would no longer share browsing data related to reproductive health and HIV testing. Engerman also told us that āPinterest confirmed that the data will be deleted and that it has not been used for advertising purposes.ā Crystal Espinosa, a spokesperson for Pinterest, said the company ācan confirm that we will be deleting the data Walgreens requested.ā
The Pharmacy vs. the Pharmacy Aisle
In the U.S., drugstores and grocery stores with associated pharmacies are only partially covered by the Health Insurance Portability and Accountability Act, or HIPAA. The prescriptions picked up from the pharmacy counter do have this protection.
But in a separate section, sometimes confusingly called the pharmacy aisle, stores also often sell over-the-counter medications, tests, and other health-related products. Consumers might think such purchases have similar protections to their prescriptions, but HIPAA only covers the pharmacy counterās clinical operations, such as dispensing prescriptions and answering patientsā questions about medication.
This distinction can be confusing enough inside the brick-and-mortar location of a retailer. But the line can become even harder to make out on a website, which lacks the clarifying delineations of physical space.
Whatās more, descriptions about what will happen with retail data are generally in retailers' privacy policies, which can usually be found in a link at the bottom of their webpages. The Markup and Ńī¹óåś“«Ć½Ņīl Health News found them murky at best, and none of them were specific about the parts of the site that were covered by HIPAA and the parts that werenāt.
In the āPrivacy Notice for California Residentsā part of its , Kroger says it processes āpersonal information collected and analyzed concerning a consumerās health.ā But, the policy continues, the company does not āsell or shareā that information. Other information is sold: According to the policy, in the last 12 months, the company sold or shared āprotected classification characteristicsā to outside entities like data brokers.
Kroger spokesperson Erin Rolfes said the company strives to be transparent and that, āin many cases, we have provided more information to our customers in our privacy notices than our peers.ā
Brokering of general retail data is widespread. Our investigation found, though, that some websites shared sensitive clinical data with third parties even when that information would be protected at a HIPAA-covered pharmacy counter. Users attempting to schedule a vaccine appointment at Rite Aid, for example, must answer a survey first to gauge eligibility.
This investigation found that Rite Aid has sent Facebook responses to questions such as:
- Do you have a neurological disorder such as seizures or other disorders that affect the brain or have had a disorder that resulted from a vaccine?
- Do you have cancer, leukemia, AIDS, or any other immune system problem?
- Are you pregnant or could you become pregnant in the next three months?
The Markup and Ńī¹óåś“«Ć½Ņīl Health News documented Rite Aid sharing this data with Facebook in December 2022. In February of this year, a based on similar findings was filed against the drugstore chain in California, alleging code on Rite Aidās website sent Facebook the time of an appointment and an identifier for the appointment location, demographic information, and answers to questions about vaccination history and health conditions. Rite Aid has moved to dismiss the suit.
After the lawsuit was filed, The Markup and Ńī¹óåś“«Ć½Ņīl Health News tested Rite Aidās website again, and it was no longer sending answers to vaccination questions to Facebook.
Rite Aid isnāt the only company that sent answers to eligibility questionnaires to social media firms. Supermarkets Albertsons, Acme, and Safeway, which are owned by the same parent company, also sent answers to questions in their vaccination intake form ā albeit in a format that requires cross-referencing the questionnaireās source code to reveal the meaning of the data.
Using the Firefox web browserās tool, and with the help of a patient with an active prescription at Rite Aid, Ńī¹óåś“«Ć½Ņīl Health News and The Markup also found Rite Aid sending the names of patientsā specific prescriptions to Facebook. Rite Aid kept sharing prescription names even after the company stopped sharing answers to vaccination questions in response to the proposed class action (which did not mention the sharing of prescription information). Rite Aid did not respond to requests for comment, and as of June 23, the pixel was still present and sending the names of prescriptions to Facebook.
Other companies shared data about medications from other parts of their sites. Customers of Samās Club and Costco, for example, can search names of prescriptions on each retailerās website to find the local pharmacy with the cheapest prices. But the two websites also sent the name of the medication the user searched for, along with the userās IP address, to social media companies.
Many of the retailers The Markup and Ńī¹óåś“«Ć½Ņīl Health News looked at did not respond to questions or declined to comment, including Costco and Samās Club. Albertsons said the company ācontinuallyā evaluates its privacy practices. CVS said it was compliant with āapplicable laws.ā
Krogerās Rolfes wrote that the companyās ātrackers disclose product information, which is not sensitive health information unless one or more inferences are made. Kroger does not make any inferences linking the product information collected or disclosed by trackers to an individualās health condition.ā
A Huge Regulatory Challenge
Pharmacies are just one facet of a huge health care sector. But the industry as a whole has been roiled by disclosures of tracking pixels picking up sensitive clinical data.
After an investigation by The Markup in June 2022 on hospital websites, regulatory and legal attention has homed in on the practice.
In December, the Department of Health and Human Servicesā Office for Civil Rights advising health providers and insurers how pixel trackersā use can be consistent with HIPAA. āRegulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosuresā of protected health information to tracking technology or other third-party vendors, according to the official bulletin. If implemented, the guidance would provide a path for the agency to regulate hospitals and other providers and fine those who donāt follow it. In an interview with an industry publication in late April, the director of the Office for Civil Rights said it would be for pixel use āhopefully soon.ā
Lobbying groups are seeking to confine any regulatory fallout: The American Hospital Association, for example, sent a letter on May 22 to the Office for Civil Rights āsuspend or amendā its guidance. The office, it claimed, was seeking to protect too much data.
This year the Federal Trade Commission has pursued action against , which offers prescription price comparisons, and , which offers online therapy, for alleged misuse of data from questionnaires and searches. The companies settled with the agency.
Health care providers have disclosed to the federal government the potential leakage of nearly 10 million patientsā data to various advertising partners, according to a review by The Markup and Ńī¹óåś“«Ć½Ņīl Health News of breach notification letters and the Office for Civil Rightsā online database of breaches. That figure could be a low estimate: A new study in the journal Health Affairs found that, as of 2021, almost contained tracking technologies.
One prominent law firm, BakerHostetler, is defending hospitals in 26 legal actions related to the use of tracking technologies, lawyer Paul Karlsgodt, a partner at the firm, said this year. āWeāve seen an absolute eruption of cases,ā he said.
Abortion- and pregnancy-related data is particularly sensitive and driving regulatory scrutiny. In the same webinar, Lynn Sessions, also with BakerHostetler, said the California attorney generalās office had made specific investigative requests to one of the firmās clients about whether the client was sharing reproductive health data.
Itās unclear whether big tech companies have much interest in helping secure health data. Sessions said BakerHostetler had been trying to get Google and Meta to sign so-called business associate agreements. These agreements would bring the companies under the HIPAA regulatory umbrella, at least when handling data on behalf of hospital clients. āBoth of them, at least at this juncture, have not been accommodating in doing that,ā Sessions said. Google Analyticsā instructs customers to ārefrain from using Google Analytics in any way that may create obligations under HIPAA for Google.ā
Meta says it has tools that attempt to prevent the transfer of sensitive information like health data. In a to Sen. Mark Warner (D-Va.) obtained by Ńī¹óåś“«Ć½Ņīl Health News and The Markup, Meta wrote that āthe filtering mechanism is designed to prevent that data from being ingested into our ads.ā Whatās more, the letter noted, the social media giant reaches out to companies transferring potentially sensitive data and asks them to āevaluate their implementation.ā
āI remain concerned the company is too passive in allowing individual developers to determine what is considered sensitive health data that should remain private,ā Warner told The Markup and Ńī¹óåś“«Ć½Ņīl Health News.
Metaās claims in its letter to Warner have been repeatedly questioned. In 2020, the company itself that the filtering system was ānot yet operating with complete accuracy.ā
To test the filtering system, Sven Carlsson and Sascha Granberg, reporters for SR Ekot in Sweden, in Swedish, which sent fake, but plausible, health data to Facebook to see whether the companyās filtering systems worked as stated. āWe werenāt warnedā by Facebook, Carlsson said in an interview with Ńī¹óåś“«Ć½Ņīl Health News and The Markup.
Carlsson and Granbergās work also found European pharmacies engaged in activities similar to what The Markup and Ńī¹óåś“«Ć½Ņīl Health News have found. The reporters caught a Swedish state-owned pharmacy . And a with The Guardian found the U.K.-based pharmacy chain LloydsPharmacy was sending sensitive data ā including information about symptoms ā to TikTok and Facebook.
In response to questions from Ńī¹óåś“«Ć½Ņīl Health News and The Markup, Meta spokesperson Emil Vazquez said, āAdvertisers should not send sensitive information about people through our Business Tools. Doing so is against our policies and we educate advertisers on properly setting up Business Tools to prevent this from occurring. Our system is designed to filter out potentially sensitive data it is able to detect.ā
Meta did not respond to questions about whether it considered any of the information Ńī¹óåś“«Ć½Ņīl Health News and The Markup found retailers sending to be āsensitive information,ā whether any was actually filtered by the system, or whether Meta could provide metrics demonstrating the current accuracy of the system.
In response to our inquiries, Twitter sent a poop emoji, while TikTok and Pinterest said they had policies instructing advertisers not to pass on sensitive information. LinkedIn and Nextdoor did not respond.
Google spokesperson Jackie BertĆ© said the companyās policies āprohibit businesses from using sensitive health information to target and serve adsā and that it worked to prevent such information from being used in advertising, using a ācombination of algorithmic and human reviewā to remedy violations of its policy.
Ńī¹óåś“«Ć½Ņīl Health News and The Markup presented Google with screenshots of its pixel sending the search company our browsing information when we landed on the retailersā pages where we could purchase an HIV test and prenatal vitamins, and data showing when we added an HIV test to the cart. In response, BertĆ© said the company had ānot uncovered any evidence that the businesses in the screenshots are violating our policies.ā
Ńī¹óåś“«Ć½Ņīl Health News uses the Meta Pixel to collect information. The pixel may be used by third-party websites to measure web traffic and performance data and to target ads on social platforms. Ńī¹óåś“«Ć½Ņīl Health News collects page usage data from news partners that opt to include our pixel tracker when they republish our articles. This data is not shared with third-party sites or social platforms and users' personally identifiable information is notĀ recorded or tracked, per . The Markup does not use a pixel tracker. You can read its full privacy policy .
This article was co-published withĀ , a nonprofit newsroom that investigates how powerful institutions are using technology to change our society. Sign up forĀ .
Ńī¹óåś“«Ć½Ņīl Health News is a national newsroom that produces in-depth journalism about health issues and is one of the core operating programs at KFFāan independent source of health policy research, polling, and journalism. Learn more about .