Vastaamo
When missing logs prevent a sensitive-data breach from being reconstructed
Finland's Data Protection Ombudsman reported at least two unauthorised logins to Vastaamo's patient database and said insufficient logs prevented investigators from determining the exact breach timing, network addresses or methods. The regulator imposed a EUR 608,000 sanction in a decision it stated was not yet final.
Documented impact
Authoritative findings
The documented event
Vastaamo notified Finland's Data Protection Ombudsman in September 2020 about an attack against its patient-record database. The authority's 2021 announcement states that an external party logged in without authorisation at least twice, in December 2018 and March 2019, but that insufficient logs and documentation prevented investigators from determining the exact timing, network addresses or methods. The most likely cause identified by the authority was an unprotected MySQL port: the database root account had no password, could log in from any IP address and the server was open to the internet without a firewall from at least 26 November 2017 to 13 March 2019. The authority found failures in data security, breach notification and accountability documentation and imposed a EUR 608,000 administrative sanction. Its announcement states that the decisions were not yet final. Vastaamo had been declared bankrupt in February 2021.
Hypothetical institutional scenario
How might the same control pattern appear?
An organisation holds highly sensitive records in a legacy database. Basic access-control and network restrictions are assumed rather than continuously evidenced, while logs are retained for less time than investigators would need to reconstruct an intrusion. A destructive database event is restored operationally, but no incident process joins restoration records, privileged-account activity and external-access logs. Months later, the organisation cannot establish when access occurred, how it happened or when the breach should have been notified.
Stress-test questions
Questions for challenge and assurance
-
Technology
Can you evidence that every privileged account holding sensitive data uses strong authentication and is unreachable from unapproved networks?
-
Audit
Would current logs establish who accessed sensitive records, from where and how, across the full period an investigation may need to reconstruct?
-
Operations
Does a destructive database event or unexplained restoration automatically trigger security investigation and breach-notification assessment?
-
Board
Who owns the controller-level notification decision when knowledge is fragmented across technology, legal, operations and third parties?
NFRisk practitioner interpretation
Control implication
For sensitive data, logging is part of the protective control, not only a forensic convenience. The control objective should specify privileged authentication, network exposure, log completeness, retention, tamper resistance and escalation from destructive or anomalous events. Notification governance must operate at controller level and cannot depend on which individual knew. Business failure or restructuring does not remove continuing responsibilities for retained personal data.
Framework relevance
Explicitly labelled analytical mappings
GDPR Article 32: security appropriate to risk
The Finnish authority found that Vastaamo had not implemented basic technical and organisational security measures appropriate to the sensitivity and risk of the processing.
General Data Protection Regulation - Article 32 · European UnionGDPR Article 33: breach notification without undue delay
The authority found that Vastaamo should have notified both the regulator and affected customers without delay once the March 2019 event indicated a high-risk personal-data breach.
General Data Protection Regulation - Article 33 · European UnionEvidence register
Primary and supporting sources
-
Data Protection Ombudsman's Office, Finland
Administrative fine imposed on psychotherapy centre Vastaamo for data protection violations (opens in a new tab) 16 December 2021 · Authoritative primary source -
European Union
Regulation (EU) 2016/679 - General Data Protection Regulation (opens in a new tab) 27 April 2016 · Authoritative primary source
Publication note
A documented external event—not an NFRisk client engagement.
The named organisations are included because authoritative sources document the event. Their inclusion does not imply that they are or were NFRisk clients, that they endorse this analysis, or that NFRisk participated in the event or response. Framework relevance and NFRisk practitioner interpretation are analytical layers applied after the event.
Return to the Risk Scenario LibraryFrom scenario to mandate
Test the equivalent control assumption in your environment.
NFRisk can use this scenario as a starting point for a focused structural diagnostic, risk-architecture review or delivery-assurance discussion.