Patient Data Breach in Pietarsaari Exposes Records of 166 Individuals

Share

A serious data breach at the Malmi hospital area in Pietarsaari has compromised the personal information of 166 clients and patients, after their records were mistakenly discarded in a regular waste container instead of a secure destruction bin. The incident occurred in early July during a relocation of units within the wellbeing services county of Ostrobothnia.

The wellbeing services county confirmed that the documents, which included patient names and personal identity codes, were left in the waste container for approximately two weeks before an external individual discovered them on July 9 and reported the matter. The records were promptly retrieved the same evening, but officials have not ruled out the possibility of unauthorized access during that period. Yle reports that surveillance cameras near the container did not capture the waste area, leaving no visual evidence of who may have accessed the documents.

How the Breach Happened

According to Data Protection Manager Tuija Viitala, the breach occurred due to a failure to follow established data protection protocols. An employee intended to place the records in a container designated for secure destruction but instead disposed of them in a regular waste bin. Iltalehti cites Viitala as stating that the error took place during the unit’s relocation, a process that should have adhered to strict data handling guidelines.

Viitala described the incident as "extremely serious" and acknowledged that existing procedures were not followed. In response, the wellbeing services county will review and update its data protection practices across all units. Yle reports that the affected records pertained to clients of a competence center, which coordinates services for children and adults with severe functional impairments. The documents included visit records and entries, though not the full medical histories of the individuals.

Notification and Next Steps

The wellbeing services county will send letters this week to all 166 individuals whose data may have been compromised. Those who do not receive a letter within two weeks can assume their information was not exposed. While there is currently no evidence of data misuse, Viitala emphasized that the county would take full responsibility if any misuse were to occur (Iltalehti).

The incident has raised concerns about the handling of sensitive patient data, particularly during transitions such as relocations. The wellbeing services county has pledged to intensify training and oversight to prevent similar breaches in the future.

Sources:

Read more