Psykoterapiakeskus Vastaamo – €608,000 Fine (Finland, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Finnish Data Protection Authority fined Vastaamo psychotherapy center €608,000 for failing to protect patient data. Hackers accessed their database due to weak security, and the center delayed reporting the breach. This case emphasizes the importance of strong data security and timely breach reporting.
What happened
Vastaamo was fined for not securing patient data and delaying breach notifications after hackers accessed their database.
Who was affected
Patients of Vastaamo psychotherapy center were affected, as their sensitive medical data was compromised.
What the authority found
The authority found that Vastaamo failed to protect personal data and did not report the breach promptly, violating GDPR requirements.
Why this matters
This case highlights the critical need for businesses to implement robust security measures and promptly report data breaches. It serves as a warning to other companies handling sensitive information.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Finnish DPA has fined Vastaamo psychotherapy center EUR 608,000. In September 2020, the psychotherapy center reported an attack on its patient database to the DPA. An unauthorized third party had gained access to Vastaamo's medical database on at least two occasions, in December 2018 and March 2019. The attacker had also siphoned off data and left a ransom note on the servers. Due to insufficient logging, neither the exact date of the breach nor the network addresses used by the attacker could be identified. The most likely cause of the medical database leak was an unprotected port on the database where the root user account of the database was not password protected. The patient database server was open to the Internet without firewall protection during the period between November 26, 2017, and March 13, 2019. For this reason, the DPA determined that the personal data were not adequately protected against unauthorized and unlawful processing or accidental loss, destruction, or damage, and that the controller had not implemented basic measures for the secure processing of personal data. As part of its investigation, the DPA also determined that the controller must have known as early as March 2019 that data in the patient information system had been lost and could have been compromised by an external attacker. Vastaamo should have immediately reported the security breach to both the DPA and its patients. However, Vastaamo was significantly late in meeting this obligation. The fine is composed proportionately of EUR 145, 600 for the breach of Art. 33 (1) GDPR, EUR 145, 600 for the breach of Art. 34 (1) GDPR and EUR 316, 800 for the breach of Art. 5 (1) f) GDPR.
Related Enforcement Actions (0)
No other enforcement actions found for Psykoterapiakeskus Vastaamo in FI
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
7 December 2021
Authority
Tietosuojavaltuutetun toimisto
Fine Amount
€608,000
Enforcement Tracker ID
ETid-952
About this data
Cite as: Cookie Fines. Psykoterapiakeskus Vastaamo - Finland (2021). Retrieved from cookiefines.eu
Last updated: