Finland Issues Wanted Notice for Hacker Behind Vastaamo Psychotherapy Data Breach
What Happened — Finnish authorities have issued a wanted notice for convicted hacker Aleksanteri Kivimäki after the Supreme Court declined to hear his appeal. Kivimäki was sentenced for hacking the psychotherapy provider Vastaamo, stealing a database of ~33 000 patients, and extorting both the company and its clients. The stolen records were later published online, exposing highly sensitive mental‑health notes.
Why It Matters for Compliance & Audit Readiness
- The incident illustrates the catastrophic impact of a data‑exposure breach on privacy obligations (GDPR, CCPA) and the need for documented consent, data‑minimisation, and breach‑response controls.
- Continuous evidence of privacy‑policy enforcement and DSAR readiness is a core SOC 2 CC5 (Privacy) requirement; gaps become audit findings after a breach of this magnitude.
- Verisq’s CookiePLUS privacy capability helps organisations map consent flows, maintain audit‑ready records, and demonstrate compliance with privacy‑focused controls.
Who Is Affected – Health‑care & mental‑health providers, especially those storing psychotherapy notes and other highly sensitive personal data.
Recommended Actions
- Review and update privacy policies, consent mechanisms, and data‑retention schedules to align with SOC 2 CC5.
- Conduct a privacy‑impact assessment (PIA) on all patient‑record systems and document remediation steps as audit evidence.
- Test breach‑notification procedures and DSAR workflows; ensure logs and evidence are retained for the statutory period.
Technical Notes – The breach stemmed from a targeted intrusion into Vastaamo’s internal systems (exact exploit not disclosed). Stolen data included therapy notes, personal identifiers, and contact information. The attacker later published the data on underground forums. Source: The Record