NHS websites transmit data from sensitive pages after patients refuse cookies, research finds

EXCLUSIVE: Consent controls fail to stop information being sent to third parties when patients visit pages covering HIV, cancer and mental health.

Share
Patients are saying no to cookies. But is the message getting through? (Image: Unsplash)
Patients are saying no to cookies. But is the message getting through? (Image: Unsplash)

A “consent forensics” investigation by Silicon Valley RegTech startup Oughtview has found that cookie controls on sites relating to HIV, cancer, sexual health and other serious conditions are frequently “broken”.

Using a combination of AI agents, automated testing and manual assessment, Oughtview examined 213 English NHS trust and national-service websites to see what happens when a visitor refuses cookies.

“The public believes that when they say, ‘No, I don't want this to be sent to third parties,’ their request is honored. But we found that the data is being sent on anyway in some cases,” Oughtview founder David Stone-Resneck said.

The researchers classified sites in three broad groups. On a functioning site, researchers registered a cookie refusal and observed no subsequent transmission to tracking-class third parties.

Other sites continued transmitting data after a refusal, while in a third group no refusal could be verifiably registered. Out of the 213 NHS websites, 104 were classified as broken, meaning a refusal was performed, but third-party transmission was observed afterward.

On another 83 sites, no refusal was verifiably registered. Of those, 51 offered no reject control, while 32 displayed one but kept no readable record of the choice, meaning researchers could not establish whether the site had registered a refusal even where data was sent after the button was pressed.

Just 26 sites were found to offer and honor a refusal. Twenty-two of those results were confirmed by a human visit.

Oughtview also found that 57 sites sent an identifier “capable of singling out the visitor’s browser” to a third party from pages relating to deeply sensitive health issues.

Of those, 38 sent identifiers to at least one service beyond a translation tool, including analytics providers, advertising platforms or social-media embeds. On 39 of the 57 sites, Oughtview observed at least one of these identifier transmissions, including to the translation tool, after the visitor refused cookies.

The affected pages covered mental health crisis support, children’s mental health services, an under-18 eating-disorder self-referral service, sexual health and sexual assault services, HIV services and testing, fertility treatment, cancer psychology and support for transgender patients.

“The act of being on that page can itself reveal sensitive information about somebody,” Stone-Resneck said.

“That could be a self-referral page for a teenager with mental illness, somebody looking up dialysis, or somebody looking up cancer treatment.”

On the remaining 19 sites, the only identifier observed leaving a sensitive page was sent to Google’s translation service. Oughtview counted these separately because many NHS websites use the service to make information accessible to patients who do not read English, and the census does not treat offering translation as a failure.

The researchers found some of the most concerning examples when examining advertising technology.

Where does the data go?

Oughtview observed 13 NHS organizations sending requests to advertising endpoints, including Google Ads, DoubleClick and Meta Pixel.

Seven transmitted after users had refused cookies, while six did so on sites where no refusal was verifiably registered.

At nine of the 13 organizations, the requests carried an identifier capable of distinguishing the visitor's browser. The remaining four contacted advertising infrastructure without transmitting such an identifier.

Researchers excluded a fourteenth organization because the recorded evidence did not establish that the visitor had actually selected “refuse”. It’s being investigated separately.

READ MORE: ChatGPT conversations were briefly accessible on Google - including one called "NHS Future Reform Plan"

In one particularly striking case, Oughtview found Google’s advertising cookie IDE being sent to DoubleClick from an NHS primary care mental health referrals page 28 seconds after the visitor had rejected cookies.

The cookie had been created before the visitor interacted with the consent banner. Oughtview said it was the only example across the 213 sites in which an advertiser’s own cookie continued to be transmitted after a refusal.

At one NHS Foundation Trust, researchers observed requests to Google advertising services across six pages after cookies had been rejected, including an urgent mental health support page and a children’s crisis-support page.

On those two pages, requests went to a Google advertising conversion endpoint associated with an advertiser account and carried an identifier. The transmissions continued across subsequent pages after the refusal.

A chronic condition?

The research comes more than three years after an Observer investigation found that 20 NHS trusts were using Meta Pixel to send Facebook information about visitors’ activity on NHS websites without consent.

The information included pages viewed, buttons clicked and searches made on sites covering HIV, self-harm, sexual health, cancer and children’s treatment. Seventeen of the 20 trusts subsequently said they had removed or were removing Meta Pixel, while eight apologized to patients.

When Oughtview tested all 20 of those trusts' websites in 2026, it found third-party transmissions after a refusal on 11 of them, and no verifiable refusal registered on another eight. Only one was observed honoring a refusal. The Meta Pixel itself was not observed on any of the 20.

Stone-Resneck said the findings do not suggest the NHS is deliberately attempting to expose patients’ information.

“Most organizations don't do this on purpose,” he said. “There's ambivalence and blind spots.”

Instead, he said, responsibility can fall into the gaps between different parts of an organization.

“There are three different groups of people who probably should be checking this stuff, and sometimes they don’t,” he said.

“There's the governance and compliance folks that don't necessarily have the technical skills to be checking this. There's the engineers who maintain the websites, and they don't necessarily have a mandate to be monitoring this stuff. And then there's the marketers who ultimately benefit by getting this information.”

READ MORE: NHS warns of “significant” robotics dependency risk as it sets new tech buying rules

In some cases, he said, the explanation may be considerably more mundane than deliberate surveillance.

“There can be a misconfiguration at a technical level that no one is looking for or at,” Stone-Resneck said.

Stone-Resneck believes the pattern points to a systemic rather than deliberate failure. Tracking tools can become embedded in complex websites, responsibility can be divided between teams and, according to Oughtview’s tests, information can continue to be transmitted even after a visitor has explicitly said no.

For patients, the distinction may make little difference.

“You can't really choose not to use the NHS's services,” Stone-Resneck said.

“You're forced to interact with a system that is shunting, in some cases, embarrassing or private information, like the fact that you were reading about HIV or Parkinson's, to third parties.”

Machine has approached the NHS for comment. After publication, we also contacted the Information Commissioner's Office (ICO) and will update this article if it responds.

Follow Machine on LinkedIn