| ▲ | fn-mote 2 hours ago | |
Wondering where the accountability was in the hack of this Finish psychotherapy organization (Vastaamo).[1] As far as I know, it was considered an act of god not something that resulted in punishment. Oh sure, they punished the hacker, but how about the people who were supposed to keep the data secure? I’m not sure where I stand on punishing companies for getting hacked. I guess like the thread says, was it gross negligence? Back to searching the internet to find out… Edit: definitely gross negligence. > one of the first things he noticed was how lax security had been. “It was definitely unfit for purpose for storing this kind of information,” he says. He tells me that the patient records database was accessible via the internet; there was no firewall and, perhaps most egregiously, it was secured with a blank password, so anyone could just press enter and open it [2] Edit: accountability? Maybe. > the board announced that it had let the CEO, Ville Tapio, go. In April 2023, Tapio was found guilty of criminal negligence in his handling of patient data. His conviction was overturned on appeal in December 2025 [2] [1]: https://www.bbc.com/news/articles/c62nzxqw45eo [2]: https://www.theguardian.com/technology/2026/jan/17/vastaamo-... | ||