DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Administrative fine imposed on psychotherapy centre Vastaamo for data protection violations

Posted on January 6, 2022 by Dissent

A hack and extortion attempt involving the psychotherapy center in Vastaamo, Finland was — and remains — one of the worst breaches ever covered on PogoWasRight.org and DataBreaches.net because it involved the sensitive mental health information of tens of thousands of patients and a coverup by an executive of the clinic. Now EDPB has posted an enforcement action by Finland:

Background information

Date of final decision: 7 December 2021
Cross-border case or national case: National case
Controller: Psychotherapy centre Vastaamo
Legal Reference: Notification of a personal data breach to the supervisory authority (Art. 33(1)), Communication of a personal data breach to the data subject (Art. 34(1)), Principles of integrity and confidentiality (Art. 5(1)(f)), Data protection impact assessment (Art. 35), Responsibility of the controller (Art. 24), Data protection by design and by default (Art. 25), Security of processing (Art. 32), Accountability (Art. 5(2))
Decision: Infringement of the GDPR, administrative fine and reprimand
Key words: personal data breach, patient data

Summary of the Decision

Origin of the case

The psychotherapy centre Vastaamo notified the Data Protection Ombudsman about an attack against its patient record database in September 2020. In October 2020, the Office of the Data Protection Ombudsman started an investigation into the legality of Vastaamo’s operations.

Key Findings

Vastaamo neglected its duties related to the safe processing of personal data as well as reporting a personal data breach.

Based on a technical investigation by the data security company Nixu in October 2020, the Deputy Data Protection Ombudsman finds that Vastaamo must have become aware that the patient data had disappeared and that it may have ended up in the possession of an external attacker already in March 2019. Vastaamo should have reported the breach both to the supervisory authority and its customers without delay.

The Deputy Data Protection Ombudsman finds that the personal data had not been appropriately protected against unauthorised and illegal processing or accidental disappearance, and Vastaamo had not implemented basic measures to ensure the safe processing of personal data. Due to insufficient documentation, Vastaamo was not able to prove that it would have complied with the appropriate safety requirements, either.

Decision

The Deputy Data Protection Ombudsman issued Vastaamo a reprimand on violating the GDPR. The sanctions board of the Office of the Data Protection Ombudsman imposed an administrative financial sanction of EUR 608 000 on Vastaamo. The sanctions board considers the acts of negligence extremely serious and Vastaamo’s actions in neglecting the duty to notify intentional. Furthermore, the violations were long-lasting.

Vastaamo was declared bankrupt in February 2021. An administrative fine is the lowest priority claim in a bankruptcy. Therefore, the financial sanction will not reduce the funds available for other claims in bankruptcy, such as potential compensation for damages.

For further information: Decision of the Deputy Data Protection Ombudsman and the sanctions board in Finlex (FI)
Press release: Administrative fine imposed on psychotherapy centre Vastaamo for data protection violations (EN)

The news published here does not constitute official EDPB communication, nor an EDPB endorsement. This news item was originally published by the national supervisory authority and was published here at the request of the SA for information purposes. Any questions regarding this news item should be directed to the supervisory authority concerned.

Category: Commentaries and AnalysesHackHealth DataNon-U.S.Of Note

Post navigation

← NZ: Vodafone accidentally sent a customer personal details of 18 other accounts
FTC Finalizes Order with Mortgage Analytics Firm, Requiring it to Strengthen Security Safeguards, Increase Oversight of Vendors →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes
  • Cocospy stalkerware apps go offline after data breach
  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse
  • Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy
  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy
  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.