Notice of data breach affecting clients of the Kauniainen health station
A data breach has occurred in the Western Uusimaa Wellbeing Services County, impacting 820 clients of the Kauniainen health station. Due to human error, the personal and health information of these clients may have been accessible to employees of the Hospital District of Helsinki and Uusimaa (HUS). A notice has been mailed to individuals affected by the breach at the beginning of September.
What happened
On 13 August 2024, a healthcare professional began working at the Kauniainen health station. This employee had previously worked for the Hospital District of Helsinki and Uusimaa (HUS). Both HUS and the Kauniainen health station use the Apotti client and patient information system.
Due to human error, the employee retained valid access rights to the client and patient information system at the start of their employment. As a result, the personal data of 820 clients of the Kauniainen health station may have been unnecessarily visible from 13 to 14 August 2024, to three (3) healthcare professionals employed by HUS. The data were not visible to anyone other than these three HUS employees.
After discovering the data breach, the Western Uusimaa Wellbeing Services County immediately contacted HUS and requested the removal of the employee’s access rights.
The following personal information was subject to the data breach:
- Identity (name, date of birth, contact details)
- Personal identity code
- Health-related information
Most likely no consequences to clients
It is unlikely that the data breach will have any consequences for clients. Thus, clients do not need to take any action regarding this notice nor contact the Wellbeing Services County or HUS.
For more information about the incident, you can contact the Western Uusimaa Wellbeing Services County Customer Service at tel. 029 151 2000, or email info@luvn.fi. Customer service is available Monday to Friday from 8:00 to 16:00. For the deaf and hard of hearing, we have a text messaging service at 045 739 59250.
If you wish, you may request log data from the Western Uusimaa Wellbeing Services County under the Act on the Processing of Client Data in Healthcare and Social Welfare. You can request log data when you wish to know who has accessed or to whom your data has been disclosed and the reason for such access or disclosure.
To request log data, follow the instructions provided by the Western Uusimaa Wellbeing Services County. These instructions are available online athttps://www.luvn.fi/en/our-client/right-access-and-other-clients-rights/log-data-request-accordance-client-data-act