A tracking snippet installed on a clinic's booking page phones home to the same servers whether the patient is in Monterrey, São Paulo, Warsaw, or Dallas. The jurisdiction changes, but the code doesn't.
That's the finding underneath The Markup's newest Pixel Hunt investigation, reported with Agência Pública in Brazil and published yesterday. Doctoralia — an appointment-booking platform — sent information about people's medical appointments to TikTok, Google, and LinkedIn, according to a review of its sites. Not a breach, or a hack. Code doing exactly what it was installed to do.
And Doctoralia is not a regional footnote. It's a brand of Docplanner, a company that also operates ZnanyLekarz in Poland, MioDottore in Italy, and Jameda in Germany, and is a market leader in thirteen countries across Europe and Latin America. Roughly 100 million patients visit its sites every month.
One company, one codebase. Thirteen legal regimes, including several sitting inside GDPR.
How It Actually Works
Healthcare businesses want to know whether their ads work. So they install tracking pixels — snippets of ad-platform code — on their booking and scheduling pages. The pixel fires every time a page loads.
The pixel isn't counting anonymous traffic. It sends the platform an identifier tied to you or your device, along with an event: this person viewed this page, this person scheduled this visit. On a scheduling site, "this page" is the confirmation screen carrying a doctor's name and specialty.
Then there's the audience. The data flowed to TikTok, Google, and LinkedIn — companies whose business is advertising. Nobody at Doctoralia had to decide to send medical details anywhere. It just requires code.
You Don't Have to Book Anything
Here's the part that should change how you think about this.
The Markup found the tracking started before a user entered any name or email — visitors tied to unique identifiers from the moment they arrived. Searching for a specialty in São Paulo, like an oncologist, was enough for that search to reach Google through its marketing platform.
So the leak isn't "you booked an oncologist." The leak is "you were looking for one." The moment of private uncertainty, before any decision, before any appointment exists — that's already the data point.
A specialty name doesn't carry a diagnosis, but it narrows the possibilities to a small and deeply personal set. Attach that to an advertising identifier, and the platform on the other end knows this device (probably this person) is dealing with something cardiac, reproductive, or psychiatric, right now.
That's the inference chain we've traced throughout this series: the data point doesn't feel sensitive, the inference does. And ad platforms are inference engines. More on that machinery here.
The Policies Existed, They Just Didn't Matter
Here's the detail that makes this a systemic story instead of a corporate-misconduct story.
Google told The Markup it has "strict, long-standing policies against collecting private health information or advertising based on sensitive information." LinkedIn said its policies "prohibit installation" of its Insight Tag on pages collecting sensitive data. TikTok didn't respond.
Take Google and LinkedIn at their word. Assume the policies are sincere and the enforcement teams are real. The data still moved.
A policy is a party-level instrument. It governs who may do what, under what authority, with what consequences. A pixel is infrastructure. It executes in a browser on a device in a country none of those policies were drafted in, and it does so by default, silently, at page load.
This is where privacy law keeps missing. Mexico's federal data protection law, Brazil's LGPD, the EU's GDPR — all real, all enforceable, all regulating parties. The same machinery ran under all of them because no one is fixing it at the layer where it breaks. FTC actions against GoodRx and BetterHelp, Washington's My Health My Data Act, GDPR enforcement — these are all attempts to punish parties after the water has already run through the pipes.
The nationality of your privacy law matters less than the scheduling platform your doctor happens to use.
What This Means for Your Family
Most of this conversation is framed around adults protecting their own medical privacy. That framing misses what's actually happening in a household.
When you book the pediatric endocrinologist, the child psychiatrist, the developmental pediatrician — the identifier attached to that event is the family device. The inference lands on a profile, and the person that inference is about is eight years old.
They did not consent and they couldn't have. They have no idea a profile exists, no vocabulary to object, no mechanism to delete it, and no way to know — at fifteen, at twenty-two — that a commercial inference about their body or their mind was made years before they were capable of forming an opinion about it.
Ask your provider, your hospital, or your booking platform a single question:
"Do advertising or analytics trackers run on your booking or patient portal pages?"
It's platform-agnostic. Doctoralia, Zocdoc, your hospital's own portal — same question. It has a yes-or-no answer. And most front-desk staff won't know it, which is itself the point: ask enough times and it becomes a question institutions have to be able to answer.
And don't assume the US version is the mild one. This same category of tracking ran inside password-protected hospital patient portals here — The Markup documented it in 2022, Meta's pixel sitting behind the login at major health systems. Behind the login has never meant private.
The through-line: medical data moving through marketing plumbing is international architecture, not a local problem. Yesterday the Markup put a flashlight on it operating on another continent. Read their full investigation — it's worth your time.
Related reading: Metadata: The Invisible Envelope That Tells Your Child's Whole Story, Medical Data Series I: The Illusion of HIPAA, Medical Data Series II: Amazon Wants to Own Your Healthcare.