Opens in a new tab

Staff explanations raise wider concerns over patient data privacy

Sunday 4th October 2026 on 17:45 in Finland

data privacy, Finland, health care

Doctors and nurses accused of accessing a colleague’s medical records say they may have been left open on computers, raising concerns about how widely patient information was exposed, Yle analyst Henna Mäkikallio writes.

The colleague underwent surgery at Oulu University Hospital in 2023. Prosecutors say dozens of doctors and nurses viewed the patient’s records without a legitimate reason.

Several defendants have told the court that it was common practice at the hospital to leave open the patient system used for surgical operations. Some also said they did not know that all the information visible in the system counted as patient data.

Particular concern has focused on Lesu, the system used in surgical care. According to the defendants’ written response to the court, its main screen shows the names and personal identity codes of all patients scheduled in a procedure unit, along with their planned procedures. An individual doctor typically has a care relationship with patients in one to three operating rooms, but can see information about all patients listed.

The defendants say the system makes it easy to see patient information accidentally. Their accounts raise questions about whether it has safeguards to limit access. The North Ostrobothnia wellbeing services county, known as Pohde, is responsible for statutory health services for about 416,000 residents and is required by law to ensure its systems support data protection.

Pohde received a reprimand in March from the deputy data protection ombudsman over its handling of patient information following the mass access case. The authority found that the county’s use of patient data was unlawful and had shortcomings. Its investigation found that some unlawful processing stemmed from incorrect practices, inadequate staff guidance and insufficient oversight. Pohde also told the authority that some employees had been unclear about how to handle patient data lawfully.

The county was ordered to address the shortcomings. Defendants have said that many guidelines changed after the case, but patient privacy may have been at risk before they were updated.

Yle asked Pohde to comment on patient privacy. The county declined, citing the ongoing court case, but said in a general statement that patient data may be handled only to the extent required for work duties and that there is no acceptable reason to view it without authorisation.

Source 
(via Yle)