Re: Having your privacy surgically removed without consent or anesthetic
Software engineers generally don't have a security background to worry about the implications of pasting unreviewed JavaScript code provided by a famous company like Google.
Certainly it's unreasonable to expect everyone to be a security expert.
However: Every organization of any decent size that develops software should have mandatory secure-development training for all developers, and general-security training for all IT personnel. Every organization of decent size that develops software should have an SDL in place that includes threat analysis, penetration testing, third-party component monitoring, and so on. And all of that goes double for any organization handling any of the categories of data that have special regulatory requirements, such as PII, financial information, and health information.
So KP very much does not get a pass here. This is completely unacceptable. And it doesn't matter that most health-care organizations offend similarly.
And "it came from Google" is by no means a satisfactory excuse.