Remix.run Logo
louthy 3 hours ago

Maybe I wasn’t clear in my message. But the buck stopping with the executives is when ‘the company’ breaks law. Usually because of gross negligence or corporate manslaughter.

With my last company, managing medical records, I was always conscious that if we didn’t take our responsibility of managing medical data correctly it could lead to the death of one of my customer’s patients; or some other extreme circumstance that the executives could be held liable for.

That was my point about being professional, if you have proper processes in place and audits to prove it, you have protection. And only the most egregious cases would land.

It’s good business to protect yourself from a gross negligence or corporate manslaughter claim. It just so happens that it’s good for your customer too.

Presumably, the reason you don’t hear much about executives in the dock for these crimes is because most professional organisations put these processes in place.

Again, I was just stating that it isn’t just data-breach fines that should encourage executives to professionalise.

fn-mote 2 hours ago | parent [-]

Wondering where the accountability was in the hack of this Finish psychotherapy organization (Vastaamo).[1]

As far as I know, it was considered an act of god not something that resulted in punishment. Oh sure, they punished the hacker, but how about the people who were supposed to keep the data secure?

I’m not sure where I stand on punishing companies for getting hacked. I guess like the thread says, was it gross negligence? Back to searching the internet to find out…

Edit: definitely gross negligence.

> one of the first things he noticed was how lax security had been. “It was definitely unfit for purpose for storing this kind of information,” he says. He tells me that the patient records database was accessible via the internet; there was no firewall and, perhaps most egregiously, it was secured with a blank password, so anyone could just press enter and open it [2]

Edit: accountability? Maybe.

> the board announced that it had let the CEO, Ville Tapio, go. In April 2023, Tapio was found guilty of criminal negligence in his handling of patient data. His conviction was overturned on appeal in December 2025 [2]

[1]: https://www.bbc.com/news/articles/c62nzxqw45eo [2]: https://www.theguardian.com/technology/2026/jan/17/vastaamo-...