Data Broker Files Expose Sales to Insurers, Banks
Consumer Reports' project reveals Acxiom's 58-page dossiers and more than 100 buyers, raising privacy-law gaps.
Tracey Reed, a nonprofit worker in Oregon, requested her personal data from a broker and received a 58-page dossier. It charted her income, employment, education, and spending, including online shopping and charitable giving — much of it wrong. The file also listed dozens of companies that had bought data or inferences about her.
“I think it’s pretty gross that people are treated like sources of wealth to be mined,” she said. “And that’s what these data profiles are, like, ‘Here’s a guide for how to squeeze this person and get money out of them.’”
Reed’s file came from Acxiom, an Arkansas-based data broker that says it holds information on billions of people worldwide.
What Acxiom claims to know
Acxiom says it can deduce political leanings, weight, and interest in medical procedures. The reports reviewed by CalMatters and The Markup show the company uses collected data to make predictions in more than 3,000 distinct categories about financial lives and behavior.
Those categories range from the ages and genders of children to estimated “alcohol usage” to how likely someone is, on a scale of 1 to 100, to be in the market for a new Tesla Cyber Truck.
Some inferences are clearly aimed at retailers. Acxiom estimated, on a zero to 100 point scale, the likelihood a person would spend money at businesses from Nike to Buffalo Wild Wings to PlayStation. It also rated the likelihood they owned any of dozens of car models.
Other inferences went further: how likely someone would respond to a student loan consolidation offer, give to charity, or fall into a particular body mass index percentile. Reports also rated chances of food insecurity, having a primary care physician, getting a mammogram, paying for medical expenses, or showing online interest in the Army.
The list of buyers stands out
Privacy experts said the most revelatory finding was the list of specific companies that bought consumer data — more than 100 in total. New state privacy laws, including those in Minnesota and Oregon, require companies to disclose not only the types of information they collect but also the other companies to which it is ultimately sold.
Among the buyers in the Acxiom files: MLB.com, GEICO, State Farm, Citi, JPMorgan Chase, US Bank, and Janssen Pharmaceuticals. Big online sellers were frequent customers too, including General Motors, Hilton, Kohl’s, Southwest Airlines, T-Mobile, and the Walt Disney Corporation.
Several smaller companies repeatedly fined and sued by federal and state regulators also appeared, including direct-mail companies Affinion Benefits Group (now called CXLoyalty/Tenerity), Endurance Warranty Services, and Mailers Haven.
Of the more than 100 businesses identified, only a few large companies responded to requests for comment. Those that did broadly defended their use of the data as a marketing tool.
“We leverage consumer data to help improve the efficiency and effectiveness of our marketing outreach,” said Farmers Insurance spokesperson Luis Sahagun, “and are committed to responsible use of any consumer information we may obtain from third parties.”
Health data and risk scores
Companies often use personal data like Acxiom reports to identify potential new customers and learn about household finances and key life events, such as the birth of a child or the death of a spouse. Banks, insurers, and pharmaceutical companies can then group, or “segment,” customers into small buckets — a new parent or widower, for example — and tailor offers down to just a handful of people.
HealthVerity, a Philadelphia-based venture capital-backed startup that markets itself as the nation’s “largest healthcare data ecosystem,” was listed as a buyer in every Acxiom report reviewed. It sells deidentified patient data to companies and government agencies, including the Centers for Disease Control and Prevention, and in several case studies posted on its website, insurers and pharmaceutical companies buy HealthVerity’s patient data to find medical research participants, build marketing lists, and link patient health records across different data sources.
HealthVerity also markets an insurance underwriting product that helps produce “risk scores” and predictions for health, life, disability, and workers’ compensation insurers. And as part of its product list, HealthVerity offers another marketing product with more than “1,000 attributes from providers typically not available, such as Acxiom, Epsilon, Adstra and others. With these sources, you gain more granular demographics, including race data, consumer behavior, online activity, socio-economic profiles, lifestyle and digital media preferences.”
Acxiom’s privacy disclosures state its data can’t be used for insurance underwriting under the federal Fair Credit Reporting Act, but HealthVerity’s products could fall outside that legal definition, as it’s billed as a “healthcare analytics” company, not a credit reporting agency, experts say. HealthVerity didn’t respond to a request for comment.
Gaps in privacy law
“There are a lot of holes in this Swiss cheese of privacy law,” said Ari Ezra Waldman, a professor of law at the University of California, Irvine, who studies the data economy.
U.S. privacy law can protect personal data in some contexts — for instance, when a FICO score and current debts are used for a credit check. But for certain kinds of health data, those laws can fall short. While the federal Health Insurance Portability and Accountability Act of 1996, or HIPAA, protects most kinds of patient health information, daily measurements of someone’s heart rate, step count, and sleep held by a tech company like Apple or Garmin don’t have the same restrictions.
Other companies with spotty track records in handling consumer data show up repeatedly in the Acxiom and Epsilon files. OneMain Financial, a subprime personal lender, appears as a buyer in several reports; in March, OneMain was sued by 13 state attorneys general for allegedly packing its loans with an estimated $826 in hidden fees and interest per borrower.
Centene Corporation, the largest Medicaid managed care company in the world, has been sued by California and several other states for allegedly inflating its pharmacy costs and then overcharging state Medicaid plans.
Janssen Pharmaceuticals, the Johnson & Johnson subsidiary listed in every Acxiom report reviewed, has paid out billions of dollars in settlements for allegedly violating federal laws regarding off-label drug marketing and physician kickbacks.
Inaccurate files and coded language
When personal data is used to market costly financial products, the effects on vulnerable consumers can be disastrous, such as when personal, home, or auto loans are targeted to those in financial trouble, often with onerous terms, said Lena Cohen, a staff technologist at the nonprofit Electronic Frontier Foundation who has studied the data broker industry.
“The extremely personal data we see in these files doesn’t appear out of nowhere,” Cohen said. “There is a network of companies and tech that have to share this data for a data broker to collect it. And it can have real harms.”
The reports also contain dozens of examples of inaccurate information gleaned from public records. Those errors “poke a hole in the argument that we need these surveillance systems for advertising to work,” Cohen said.
Many early participants in the Consumer Reports effort are particularly mindful about protecting their privacy, and Reed is no exception. She still uses a flip phone. “I hate marketing and advertising,” she said. “I always have ad-block and I try to be conscious of my own data privacy.”
That didn’t stop Acxiom from attempting to catalog her habits. Some information was wrong — her listed addresses seemed to mix her up with her parents — but the company was correct about her spending habits.
The Acxiom reports also include what critics call artful examples of coded language to describe racial, ethnic, and health information that would otherwise be protected from disclosure and use by federal and state laws. One report scores a consumer’s “assimilation level” as “3+ generations in the US.” Others rate “health conscientiousness,” the “likelihood to be a smoker,” and “social setting behavior.”
“We don’t actually know what goes into these kind of vague terms,” Waldman said. The assimilation score is likely “getting at things like race, ethnicity, immigration status, things that we don’t normally like to discriminate on.” But the vague terms used by data brokers “are there to hide the true nature of what’s going on — and to sanitize it, to legitimize it.”
Why it matters for consumers
The files reviewed show how detailed data broker profiles can become, and how many companies can end up with them. The disclosures also show that the accuracy of these profiles is not guaranteed, which could affect the offers people receive and the terms attached to them.
For consumers, the practical takeaway from the Consumer Reports project is that new state privacy laws give people in some states a way to request their own files. The reports can reveal what brokers think they know and which companies bought the data. That information can be used to correct errors or to understand how personal data may be used in marketing and underwriting decisions.
The gaps in privacy law mean that not all data receives the same protections. Health information held by a tech company, for example, may not be covered by HIPAA in the same way as data held by a doctor. That leaves consumers to navigate a patchwork of rules depending on where they live and what kind of data is involved.
For businesses, the files raise questions about reliance on third-party data that can be inaccurate or that may include sensitive inferences. The list of buyers shows that data flows through a network of companies, and that the original source of information may not be clear.
Sources
- The Markup Original source
- MLB.com Also reporting
Continue Reading
ScreenConnect Flaw Under Attack, Patch Urged
CISA orders federal agencies to fix a critical ConnectWise ScreenConnect flaw exploited in the wild, with over 1,000 instances still exposed.
WooCommerce Plugin Flaw Fuels Web Shell Attacks
Attackers are exploiting a critical WooCommerce Wholesale Lead Capture vulnerability to upload PHP web shells and achieve remote code execution.
Pixel Zero-Day Patched After Targeted Attacks
Google's September 2026 Pixel update fixes 110 flaws, including a modem zero-day exploited in limited, targeted attacks.