DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Administrative fine imposed on psychotherapy centre Vastaamo for data protection violations

Posted on January 6, 2022 by Dissent

A hack and extortion attempt involving the psychotherapy center in Vastaamo, Finland was — and remains — one of the worst breaches ever covered on PogoWasRight.org and DataBreaches.net because it involved the sensitive mental health information of tens of thousands of patients and a coverup by an executive of the clinic. Now EDPB has posted an enforcement action by Finland:

Background information

Date of final decision: 7 December 2021
Cross-border case or national case: National case
Controller: Psychotherapy centre Vastaamo
Legal Reference: Notification of a personal data breach to the supervisory authority (Art. 33(1)), Communication of a personal data breach to the data subject (Art. 34(1)), Principles of integrity and confidentiality (Art. 5(1)(f)), Data protection impact assessment (Art. 35), Responsibility of the controller (Art. 24), Data protection by design and by default (Art. 25), Security of processing (Art. 32), Accountability (Art. 5(2))
Decision: Infringement of the GDPR, administrative fine and reprimand
Key words: personal data breach, patient data

Summary of the Decision

Origin of the case

The psychotherapy centre Vastaamo notified the Data Protection Ombudsman about an attack against its patient record database in September 2020. In October 2020, the Office of the Data Protection Ombudsman started an investigation into the legality of Vastaamo’s operations.

Key Findings

Vastaamo neglected its duties related to the safe processing of personal data as well as reporting a personal data breach.

Based on a technical investigation by the data security company Nixu in October 2020, the Deputy Data Protection Ombudsman finds that Vastaamo must have become aware that the patient data had disappeared and that it may have ended up in the possession of an external attacker already in March 2019. Vastaamo should have reported the breach both to the supervisory authority and its customers without delay.

The Deputy Data Protection Ombudsman finds that the personal data had not been appropriately protected against unauthorised and illegal processing or accidental disappearance, and Vastaamo had not implemented basic measures to ensure the safe processing of personal data. Due to insufficient documentation, Vastaamo was not able to prove that it would have complied with the appropriate safety requirements, either.

Decision

The Deputy Data Protection Ombudsman issued Vastaamo a reprimand on violating the GDPR. The sanctions board of the Office of the Data Protection Ombudsman imposed an administrative financial sanction of EUR 608 000 on Vastaamo. The sanctions board considers the acts of negligence extremely serious and Vastaamo’s actions in neglecting the duty to notify intentional. Furthermore, the violations were long-lasting.

Vastaamo was declared bankrupt in February 2021. An administrative fine is the lowest priority claim in a bankruptcy. Therefore, the financial sanction will not reduce the funds available for other claims in bankruptcy, such as potential compensation for damages.

For further information: Decision of the Deputy Data Protection Ombudsman and the sanctions board in Finlex (FI)
Press release: Administrative fine imposed on psychotherapy centre Vastaamo for data protection violations (EN)

The news published here does not constitute official EDPB communication, nor an EDPB endorsement. This news item was originally published by the national supervisory authority and was published here at the request of the SA for information purposes. Any questions regarding this news item should be directed to the supervisory authority concerned.

Category: Commentaries and AnalysesHackHealth DataNon-U.S.Of Note

Post navigation

← NZ: Vodafone accidentally sent a customer personal details of 18 other accounts
FTC Finalizes Order with Mortgage Analytics Firm, Requiring it to Strengthen Security Safeguards, Increase Oversight of Vendors →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • AMI Group – Travel & Tours notice of ransomware attack
  • Resource: Insider Threat reports
  • Za: Cyber extortionist sentenced to eight years in jail
  • ICE takes steps to deport the Australian hacker known as “DR32”
  • Hearing on the Federal Government and AI
  • Nigerian National Sentenced To More Than Five Years For Hacking, Fraud, And Identity Theft Scheme
  • Data breach of patient info ends in firing of Miami hospital employee
  • Texas DOT investigates breach of crash report records, sends notification letters
  • PowerSchool hacker pleads guilty, released on personal recognizance bond
  • Rewards for Justice offers $10M reward for info on RedLine developer or RedLine’s use by foreign governments

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Decision That Murdered Privacy
  • Hearing on the Federal Government and AI
  • California county accused of using drones to spy on residents
  • How the FBI Sought a Warrant to Search Instagram of Columbia Student Protesters
  • Germany fines Vodafone $51 million for privacy, security breaches
  • Malaysia enacts data sharing rules for public sector
  • U.S. Enacts Take It Down Act

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.