episode.ascii — live render
● episode

The Place Where You Get Answers From

TL;DRA Finnish digital therapy startup called Vastamo had unencrypted therapy session records for thousands of patients stolen by a hacker, who then extorted patients directly after the CEO refused to pay a 40 Bitcoin ransom.

Jordan Bloemen & Scott Francis Winder discuss the saga of Vastaamo, and what happens when some of the most sensitive data imaginable finds its way into the wrong hands.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: An update now on the Colonial Pipeline ransomware attack.

Speaker 2: The Colonial Pipeline experienced a cyberattack.

Speaker 3: NBC News has learned Colonial Pipeline paid nearly 5,000,000 in ransom to hackers who infiltrated their sys- This is about a ransomware attack, and not the one you've been hearing about. And it concerns a Finnish startup called Vastamo. On September 28, a guy named Ville Tapio, CEO of Vastamo, Vistamo, gets a ransomware demand, 40 Bitcoin, which at the time was roughly half $1,000,000 US for the hacker to delete the data that they had stolen from Vistamo. You see, some ransomware extracts money by encrypting the victim's data, and they'll only unlock it once the ransom is paid. Some ransomware extracts money by crippling an essential system that they'll only unlock once the ransom is paid. We heard about one of those this month. But this was the other kind of ransomware attack. They had stolen a copy of the victim's data, Vostamo's data, and they were gonna leak it unless the ransom was paid. The only way that a ransomware attack like this works is if that data is really private or incriminating or sensitive in some way. Which brings us to what this company, Bostamo, did and what information had been stolen. Tapio ultimately declined to pay the ransom. It's always this devil's bargain whenever you pay any kind of ransom that you really got no proof that the person's gonna do what they said they're gonna do once they get the money. And when Tapio refused to pay, the hacker decided to move on to a new victim, to the users of Vastamo, whose data was contained inside that leak. Vastamo is Finnish for the place where you get answers from, and those answers had to do with some of the biggest questions that people ask. Because Vastamo was a digital therapy company, and the data that was stolen was records from thousands of therapy sessions. Not just patient names, but actual notes from the sessions, transcriptions of people's most vulnerable secrets and personal confessions and innermost thoughts. And now this hacker was reaching out to them directly with a much more personal threat. This is what happened to the place where you get answers from, here on Hacked.

Speaker 1: Yo. That's scary as fuck.

Speaker 3: It's Oh. The story is actually like spooky as shit.

Speaker 1: Like like low key, like high key, maybe the shittiest thing about like personal health services going online.

Speaker 3: Yeah. It's been an interesting year for health services going online. Yeah.

Speaker 1: For sure.

Speaker 3: There's been a lot of it. If you were doing IT or security in digital health, like, 10,000 foot view, like, how

Speaker 1: would you be thinking about it? Like, what would your top level priorities be? Security would be the I I don't even know how you would like, I I would probably be encrypting all data locally.

Speaker 3: Mhmm.

Speaker 1: Mhmm. Because any of those like, you wouldn't be saving anything in unencrypted form, and you'd have relatively comprehensive encryption measures to get access to it because it's like those are bloody health records. You know? And not even health records. They're mental health records, which I'd actually argue are probably more sensitive. When you when I was listening to the intro, all I was thinking about was how in God's name did the insurance company that insures this company not pay the ransom? Because I can't can't see how this doesn't just end in the most ridiculous amount of lawsuits if if if this stuff does start leaking.

Speaker 3: Yeah. A ridiculous amount of lawsuits is, some good foreshadowing. So in Finland, they've used this system since 2014 when the Finnish parliament decided to break medical information systems into two different categories. Class a systems would connect with the National Health Data Repository, the system called CANTA. And if you wanted to connect to CANTA, you had to meet these really, really strict security and compatibility standards. If you're gonna be keeping patient records digitally for any amount of time, you had to use the class a system. And I imagine just from, like, a cybersecurity perspective that there's a lot of benefits to a centralized system like that. Like, you could maintain standards across the whole system just by changing Canta. It becomes kind of a bottleneck for how ever secure or unsecure the whole system is. Right? Right. So, that's class A. Smaller organizations like a little like acupressure clinic that keeps filing cabinets full of like literal paperwork, they got to use this other system. This much less intense smaller system for any digital records that they had called the class B system. And the class B system isn't really tightly regulated because it's kind of like small fish. It's not a big target for hackers. Which is the context for digital health when this company, Vostamo, comes onto the scene. In 2009, the Finnish Innovation Fund decides to give 12,000 to a guy named Ville Tapio to start this company. Tapio grew up in Helsinki during the recession, starts learning a company, he's like 10 years old and his parents give him a Commodore 64, starts a couple of businesses, and eventually finds himself at the Finnish Innovation Fund working on a project that has him touring around Western Europe, doing analysis of different health care systems around the continent, which is when he starts thinking about this idea of mental health. In Finland at the time, mental health services weren't very good. There were some whole areas where there was just blackouts of coverage. You couldn't find a provider. And then he goes on this tour and he sees other countries, The Netherlands in particular represent, just absolutely crushing it when it comes to mental health. So he starts to wonder, is this something where, like, a digital service could help? Telehealth, as it's sort of been known for a long time, has been around in some way or another for quite a bit. It's actually pretty well established here in Canada where we're from. But modern digital telehealth is a pretty new idea in 2009. And it seems like a pretty good fit for an area of medicine where, like, you don't need to physically interact with the patient as much. It's a it's a pretty good thing to digitize first. Mhmm. So in 2009, he secures a grant from this innovation fund, raises, like, another 13 k from his parents, and he boots up this social enterprise. And he calls it Vostamo, Finnish for the place where you get answers from. And the idea is pretty simple. Clients can send a message to Vostamo and in less than twenty four hours, a real therapist reaches out and starts a session with them. But the thing about therapy is that there are parts of it and certain patients for whom like a Zoom call is just insufficient.

Speaker 1: Mhmm. And it

Speaker 3: pretty quickly became clear that this wasn't gonna be comprehensive for a big operation. For everyone that was happy with telehealth, there's a lot of people that want an in person experience. So Vostamo starts expanding into physical locations, but all built on that, like, tech forward infrastructure they designed for the digital service. Essentially, Vostamo was gonna digitize whatever they could about therapy from booking an appointment, making invoices, and really importantly, the medical records from the sessions. Everything but the appointment itself was gonna be on this central Vostamo database. The idea is that independent therapists join Vostamo to get access to this great platform and to avoid dealing with all of the junk involved in, like, running a clinic. All the automation means they spend more time with clients, and they bill way more hours. But in order for all of that to work, Vostamo needed an electronic medical record system. A classic kind of tech startup, he didn't like any of the ones that existed. To his mind, the absence of good digital software for therapists was probably why most therapists were still using paper. And that kind of a big hole in the market represents a really good business opportunity. So he cooks up his own. It launched in late twenty twelve, right around the same time as Vostoma's first in person clinic opened in the Malmo district of Helsinki. Court documents filed later in this whole story during the smorgasbord of lawsuits you mentioned earlier suggests that the system was browser based and store patient's records on something called an an SQL server.

Speaker 1: Yep. What's an SQL server? SQL is a simple query language. It's pretty much the foundation for most modern database systems. So all your big Oracles, Microsoft SQL Server, MySQL, Post gres, tons of the big databasing servers all use SQL implementations. And it's it's essentially just a big just think of, like, a bunch of Excel spreadsheets that computers know how to, like, dig through quickly.

Speaker 3: If there was one feature that you would build into a system that does that, but most importantly stores patient files, and we talked about this a little bit, but what would that one single feature be?

Speaker 1: If I was storing confidential patient records, I would Yeah. Be doing something to obfuscate the the the values inside of those records, be it encrypting them, hashing them, something to make sure that they're not just plain text, which I have a gut feeling is where we're going.

Speaker 3: Bustamo's system did not do two things. It did not anonymize records, and it did not encrypt them. So the only thing standing between you and the patient files, again, like therapy session files, was a server login screen and a handful of firewalls. I have never designed a system to try and protect medical files, but from just like a bird's eye design level, that feels really, really wanting to me.

Speaker 1: Wanting? Well, I'd say you'd be surprised at what is stored in in unobfuscated SQL tables around the Internet. This is just this isn't surprising to me, I guess, was is what I'll say is pretty much anything you've ever put into any kind of form anywhere on the Internet is probably saved in an SQL file somewhere. And

Speaker 3: the

Speaker 1: gaining access to SQL data like, we've talked about this in previous episodes with, like, Ashley Madison and stuff.

Speaker 3: Mhmm.

Speaker 1: You know, there's an entire subset of of hackers who kind of know and go after figuring out ways to essentially extract extra information out of SQL, servers through web applications. So you can figure out ways to put in false codes, figure out how it's pulling, you know, AJAX calls from the website so the website's loading data in real time, things like that. So you can try and intercept those and try and extract out as much stuff as you can from these SQL tables. And and often, the tables are relatively commonly named, you know, users, etcetera. So so the yeah. It's it's, I would say a common security problem these days is having a lot of very sensitive information stored inside of an SQL server that is then connected to a server that is on the open World Wide Web and accessible from anywhere in

Speaker 3: the world.

Speaker 1: Not not many not many places have comprehensive, DMZs, so demilitarized zones. So you had can have multiple firewall structures so that you can actually bury your SQL servers behind layers of firewalls, only allowing specific connections to be authorized coming through from specific computers. And, you know, there's there's lots of ways to try to secure it, but at the end of the day, the web application still needs access to that SQL server. And if you can hack the web application or hack the APIs that it's using to call the the the data from those servers, you can get access to that data.

Speaker 3: So if you remember back at the start, there are those two medical file class systems in Finland. Right? There's class a and class b. Class a plugs into that centralized system called Kanta, and class b doesn't.

Speaker 1: Mhmm.

Speaker 3: And I got curious about how class b worked. And the way it works is class b operators would essentially self certify to the government that their setup met certain requirements. And the government would say, thanks for letting us know. And the government who is overseeing this class b system was, at the time, one man named Antti Harkonnen, whose dominion includes every single class b system in Finland, over 280 individual systems. And that seems like too many for one guy. But class b is for small paper based operations, right, not a pretty big network of digital healthcare providers. And in the fallout of all this, there's been some dispute as to why Vostamo, who operated a bunch of different therapy clinics, never switched over to class a. In what is in retrospect a very ironic argument, Tapio, the CEO, has argued that class a was not secure enough for therapy records, and that other physicians could easily access those sensitive session records. Kanta, that class a system has replied that's not true. But the way this all shakes out is that by 2018, when this kind of starts to fall apart, Vistamo was still registered as a class b operation that is eager to be upgraded to class a once the spec for psychotherapy comes out, which it did, and Bustamo continued to not adapt. They just kept shrugging along with their firewalls and their server login page, and allegedly not a drip of encryption on their side. During this rise, he's quoted as saying that Finland's supervisor authority signed off on Vostomo's security system, quote, numerous times. That supervising authority was the one guy, Harkonnen, overseeing 280 systems, who has said since then that it would be functionally impossible to sign off on all of these things in a meaningful way. He's also unpacked what that sign off process actually looks like, and it's well, it's what I said. It's basically Vistamo submits a self certification that their SQL server is secure, our Conan signs off on it, rinse and repeat for every single new clinic. Is it secure? Yeah. Cool. Is self certification, like like, have you heard of anything like this? Is that common for some sort of overseeing board to just ask if something is secure and accept the argument that it is sort of carte blanche?

Speaker 1: I don't think I know of any major certification board that allows you to just vouch for yourself, especially something as sensitive as as as health records, but I could I've I've heard of things like this in other categories where you kind of just self proclaim that you adhere to rules. Like, I feel like you I don't know. I feel like we do this a ton these days in COVID. We're always telling everybody that we don't have fevers and headaches and stuff, and we're kind of not not being tested for it. But I've never heard about it on, like, a large security scale.

Speaker 3: By 2018, Vistama had grown to the point where they were drawing interest from, like, private equity firms. One of which would go on to buy the company, making the CEO Tapio very, very wealthy. And the name of the company that bought Vostamo is called Interra. And you should remember that name because they come up again later. At this point, Vassama was operating nearly 20 clinics, employing around 200 therapists and staff. By the end of twenty nineteen, their annual revenue had risen to more than $18,000,000. And with each new clinic came more patients whose data was flooding into this system, this unencrypted, unanonymized system. Global note, the words alleged must now precede everything that follows from this point. And who is alleging is not always the same. Tapio claims he first heard from the hacker on 09/28/2020, when the 40 Bitcoin demand came in. The message came to him and a pair of developers that he'd hired in 2015. The last two big characters in this saga, Elari Lind and Sami Koskinen. Lind and Koskinen were responsible for data protection and maintaining the company's IT systems, including those servers and firewalls. So 09/28/2020, this ransomware demand comes in, and according to a statement made to the Helsinki District Court, Tapio immediately notifies the cops and the government. Lind, one of those two security professionals, starts sifting through Vostamo's network traffic logs, but reports finding no evidence of a hack. And it's here that we, kind of the public, hear from our hacker for the first time. When they write, quote, we have attempted to negotiate with Ville Tapio, the CEO of Vistamo, but he has stopped responding to our emails. That's a post that appears on the morning of October 21 on an anonymous discussion board. So their plan, states the hacker, is to leak 100 patient records a day until they get their 40 Bitcoin. The first of such leaks was already available for anyone to read on a linked Tor server. 100 patient files from therapy sessions.

Speaker 1: Can we I just wanna I just wanna pause for two seconds. 40 Bitcoins was their demand.

Speaker 3: Yes. But half $1,000,000 at the time, US.

Speaker 1: That seems pretty negligible for what I assume the greater liability value is.

Speaker 3: And for the amount of money that ends up being unraveled by this, I would agree. So, the hacker then reaches out to a journalist. They email this journalist and the hacker says they have this database. They've had it for eighteen months before they realized what they found. Eighteen months. He also passes on Vostamo for storing this information the way that he had that they had. He called them the real criminal, which Damn. I don't know. There there can be more than one, but I take his point. Up until this point, the flow of money and information is like, it's relatively simple, right? The hacker stole the database. He's asking Vostamo for the money. And according to his correspondence with the journalist Tapio, the CEO of the company refuses. So, the hacker is sitting on all this data and he's promised to leak it a 100 files at a time, but the company doesn't really seem to give a shit. So, like, what's his next move? He keeps leaking it, but if they don't care, they don't care. I think your moral code would probably preclude you from finding yourself in a situation that this hacker is in. But if it didn't, what would your next move be, Scott? All gas, no breaks,

Speaker 1: I guess.

Speaker 3: And at some point, the hacker comes up with his new idea, a very gas, no brakes kind of idea. And I think they know when he comes up with it. After the conversation had migrated over to a forum on the dark web, there's this post where a person, one of the patients whose information is inside this database makes an offer to the hacker. The patient offers to pay the entire ransom. Woah. 40 Bitcoin, half a mil. I know. Just to keep his therapy sessions private. The company of Estammo, they're not budging, but a bunch of patients start flooding in with offers to pay the ransom.

Speaker 1: Sure. One

Speaker 3: of them wrote, and he's finished writing in English, so I'm gonna auto fill the sentence for him. Quote, I have discussed very private things with my therapist, and I will literally kill myself if they are released. I can send it in minutes. I'm constantly refreshing this page.

Speaker 1: Could you imagine the level of anxiety?

Speaker 3: No. It's hard to wrap your brain around it. Knowing what some people would be discussing with a therapist, and that comes up a bit later, no. I have no idea what these people were going through.

Speaker 1: That's, like, honestly scary.

Speaker 3: Over the days and weeks that follow, if we refer to the hacker's Bitcoin wallet, all in about 30 payments were made from different patients. There's no evidence in either direction to suggest that the hacker, who at this point is now going by the name Ransom Man, ever deleted any of the data. But I think here, seeing the sensitivity of this information, the value that it had to people, and the desperation they felt that Ransom Man comes up with this idea to start contacting individual patients. First, Ransom Man drops another 100 patient records just like they promised. And this batch includes politicians, some famous Finnish people, and it covered subjects like adultery and suicidal ideation and pedophilia. Shortly after, right after giving a taste of how nasty some of this stuff was, Ransom Man starts reaching out to patients themselves. And, I was curious about this. Apparently, this doesn't happen very often in ransomware attacks at all where the hacker will delve into the dataset and start contacting individual people implicated in the data dump. It's pretty rare. In 2019, there was a similar incident at a plastic surgery clinic. But since Vistamo, it's happened twice, and that's overall only four data points, but it feels like it's accelerating a little bit. Mhmm. And I imagine that's the kind of thing where the more it works, the more it's gonna

Speaker 1: happen. Totally.

Speaker 3: Like ransomware itself. If you were in Vistamo's position and you've said, no, I will not pay, and now the hacker is going to individual patients, what is your move?

Speaker 1: I the I don't know if anybody really has a move. Right? They've essentially ceded all the power to the hacker at this point. Like, people are throwing money at him to patch the problem, which is only probably, you know, supporting his argument that he has something of value that somebody should be paying him for. But the other problem is is that there's no way that you can ever know that he's deleted it and won't just do this again. Mhmm.

Speaker 3: So

Speaker 1: there's nobody has any forms of protection. Like, you know, in the classic ransom, you know, there is a child involved. You know? There's a a a real human that gets passed around in the in the traditional, you know, quintessential ransom case. But in a data case, you can make duplicates and copies. Mhmm. Like, there's no way to guarantee that there's a there's not, you know, a million other copies of this stuff sitting in the cloud somewhere. So you have no certainty. Like, really, the only certainty would be full blown busting the person who's doing it and everyone they're associated with and and hoping that you get as much of the data locked down and, like, you know, kind of resecured. Like, you find as many of the data stores that that he's probably or they are probably keeping it on as possible. So I I I think that, really, your best move is probably just to lean into a a Mhmm. Like, a criminal police solution because I don't think that there's really anything that's gonna protect you otherwise.

Speaker 3: Vostamo's big PR play in response to all of this was to offer patients one free counseling session. According to William Ralston's coverage on this, one patient says that their therapist advised her to consider that not everything being said in the news was true. Some patients got nervous and started trying to get physical copies of their records to figure out, like, what had been leaked or what might be leaked. Victim support Facebook groups started popping up. But the Monday that follows, a couple of things happen all at once. Tapio, the man who founded the company back in 2009 with, you know, $20,000, was fired as CEO. A few hours later, the equity firm, Interra, that bought the company filed a motion, seizing just shy of 12,000,000 from the Tapio family, roughly what they paired for their share in the company, which is when the question of who was really responsible for all of this came to the forefront. And we are gonna get to that right after the break.

Speaker 1: So wait, before we before we go, everybody's immediate thing was to pull as much money as they humanly could out of the company before it eventually shut down? That's what everybody kinda did?

Speaker 3: Mhmm.

Speaker 1: That's, that is some risk mitigation right there.

Speaker 3: Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked one more time. That's shopify.com/hacked.

Speaker 4: No one goes to Hank's for his spreadsheets. They go for a darn good pizza. Lately though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar slice work. Now Hanks has a line out the door. Hank makes the pizza. Copilot handles the spreadsheets. Learn more at m365copilot.com/work.

Speaker 3: I wanna go back a little bit to those two security professionals who worked at Vistamo, Lind and Koskinen.

Speaker 1: Mhmm.

Speaker 3: Last year, I watched the Chernobyl HBO miniseries. Did you watch that?

Speaker 1: Of course, I did. Who didn't watch that?

Speaker 3: It's really, really good. And it taught me that when something explodes, literally or figuratively, the very first thing that happens is everyone takes out their pointer finger

Speaker 1: Yeah.

Speaker 3: And they start frantically aiming it at everyone that isn't them. And the three players in this drama all do that. They are Interra, the big company that bought Vistamo, who is pointing the blame at Tapio, the founder and now ex CEO, who is himself pointing the blame at Lind and Koskinen, the two security professionals. And if shit runs downhill, Lind and Koskinen are at the very bottom of that hill. Interra's argument is that their entire purchase of Vistamo is null and void, and they want their money back. Because, as they outlined in their filings, by the time they bought Vostamo, the breach had actually already occurred, and they hadn't been told. They say in the filing, quote, based on the information received so far, it is reasonable to assume that Vile Tapio was aware of the breach. They also claimed that, quote, he sought to conceal those alleged attacks, which is the foundation of Vintero's argument that they should be able to dissolve the transaction and get their money back. To remind you of our timelines, the story seems to kick off in 2020 when that ransomware message first comes in. But at this point, the hacker claims they've already had these files for eighteen months. This is what they told that journalist. And Tara, who is suing Tapio, claims that therefore, there must have been a breach that they were not aware of in 2018 and 2019. This would line up with the hacker's claim that he'd had the patient files for eighteen months. If Tapio knew about the breach, knew that patient files had been stolen for eighteen months, but kept it a secret, this is what Interra's lawsuit alleges. But according to Tapio, that first breach, when the files were probably stolen, he says he didn't know about it, and he points the blame firmly at Lind and Koskinen. And the reason why, he claims, is because Lind and Koskinen did not tell him. The security firm, Niksu, that Vistamo hired to investigate found that that first breach in 2018, where the files got taken, was accompanied by a blackmail message. Some piece of text that made very explicit that the crash was the result of a hacker and that some data had been compromised. And according to that research firm, someone with an administrator account deleted that message. The question is who controlled the account that deleted the post? The post that would have blown up this multimillion dollar deal with Entera. At the time, Tapio claims that Lindy Koskinen told him the crash could have been caused by some small network adjustments. Tapio claims that Lindy Koskinen controlled that account, and that if someone deleted this blackmail message, the one that came in eighteen months earlier, it must have been them. Mhmm. And the reason he argues that they did this was to conceal a vulnerability that they had created, one that left Vistamo's patient databases without firewall protection for over a year. That is Tapio's story, and he is sticking to it. And so far in all of this, Lind and Kaskinen are kind of a blank slate. Right? We don't really know much about them. There are two security professionals getting blamed for this massive failing of security. Kinda makes sense. But there's this one important detail about them that may or may not be relevant to all this, which is that just before they joined Vistamo, they'd been arrested as part of a giant security breach at the Finnish Funding Agency for Technology and Innovation. They'd figured out that they could download this database of all these companies by changing a URL on a funding application. They downloaded it. They got they got caught. There was a pretrial investigation for aggravated fraud, breach of confidentiality, and burglary. The prosecution couldn't totally figure out that they'd done it for financial gain or just because they realized they could. So it all kinda faded away. And now, this pair finds themselves again in a room full of people, all pointing fingers at each other, with a lot of those fingers pointed squarely at them. So we're left here. And Tara says Tapio knew. Tapio says he didn't know and that Linden Koskinen, two pretty good fall guys as fall guys go, had covered it up, and Linden Koskinen have said nothing. A $12,000,000 fortune remains frozen until this lawsuit is resolved, and all of those patients, their information is still out there.

Speaker 1: I'm captivated, Jordan. I need I need to know what happens to these poor people's information.

Speaker 3: Oh, man. You're not gonna like it. Yeah. I figured. On January 28, Vostom was put into liquidation, and it filed for bankruptcy two weeks later. In early March, its staff and services were transferred over to this other company called Verve, who provides, like, occupational welfare services. Verve did not acquire Vostomo's consumer data, and Verve is going to be using a class a system. The scandal sparks a couple of changes in Finland, some of them really tangible and some of them more abstract. Finnish parliament passed legislation basically overnight that would allow victims to change their Social Security numbers in the event of a major breach, which Wow. I don't know if we have that over here, but that seems like a very good idea. There are debates about whether, even in the class a system, if therapy records should be stored on any kind of a central database, if that data has any reason at all to ever leave a consultation room. But I think that until some kind of a scalable, secure platform exists, more enterprising individuals are going to keep cooking up their own, and more stuff like this is going to keep happening. Because forty eight hours before the final nail was put in the coffin of Vostomo, a compressed, more easily shareable version of the entire Vistamo patient database appeared on a dozen file sharing sites. It is still out there, floating around like every other leak ever, but somehow also very, very

Speaker 1: different. That's a pretty broad question there about digitization of health records at all, especially mental health records. You know, I think that's something that we're I think we're giving a pass to how insecure paper records are because they're physically bound where the Internet, you know, the Internet is the Internet. It's the reason why ecommerce is such a big business is because you can have a purchaser from anywhere in the world. And, you know, there might not be a local burglar who's gonna break in and steal your paper patient records. But, when you look at 7,000,000,000 people versus, you know, how many you ever live in the tiny Finnish town you're from, there's there's bound to be a hacker in the 7,000,000,000 that will, will burgle burgle your your private data. I think that's where we need to go is we need better encryption systems at a mass level. Like, when a doctor needs to access, a patient health record, that health record should be completely key encrypted until unlocked by the doctor's key. And I think that we need I think we need better solutions like that to further and, kind of figure this out.

Speaker 3: You brought up Ashley Madison earlier, and I was intrigued by this because I remember when Ashley Madison happened, and it felt like a website about infidelity having a data breach would be about the most vulnerable thing a person could have come out about them. And this just blew that out of the water. Yeah. Like, the contents of a therapy session are such an order of magnitude more sensitive than anything in my email or my social media or probably like my camera roll. And the trouble is that people don't need a site for finding people to have affairs with. But a lot of people need therapy. Yeah. People need medical treatment however they can get it and if digital is how they can get it right now, then we have some stuff to figure out very very quickly. I now know more about how this is legislated in Finland than I do in my own country and I imagine that's probably true for most listeners. And that's worth changing because people are always gonna need that place to go get answers. They're always gonna need a Vastamo, but Vastamo ain't how to do it. Thanks for listening, everybody. Attention, all Michelle Kysers and David Gidleys. Thanks for becoming our newest patrons on Patreon. It's cool as hell of you. It's the best way to support the show, and it means a lot to us. If you haven't, you can also ring subscribe on your podcast app of choice. It also goes an incredibly long way towards getting the show in front of new folks so we can keep making more. Our main source for this episode was William Ralston's fantastic reporting on the subject. There's a lot that's been written about this, most of it in Finnish, but Ralston's writing really synthesized all of it beautifully.

Speaker 1: I guess, the other thing I wanna end with is just, maybe a shout out to randomly bumping into one of our fans IRL at the sandwich shop the other day. So, you know, good looks, and, thanks for being a fan.

Speaker 3: Thanks for listening. Catch you on the next one.

Speaker 5: If you're a lineman in charge of keeping the lights on, Grainger understands that you go to great lengths and sometimes heights to ensure the power is always flowing, which is why you can count on Grainger for professional grade products and next day delivery so you have everything you need to get the job done. Call 1800, click grainger.com, or just stop by. Granger, for the ones who get it done.

Speaker 2: Still waiting in line? Again? That's time you'll never get back. Save time and money with stamps.com. Over 4,000,000 businesses have skipped the line with stamps.com. Join them to save up to 90% off carrier rates from your computer or phone right now. Print postage for certified mail, registered mail, and packages in seconds, then schedule a pickup right from your home or office. For a limited time, go to stamps.com and use code podcast for a free welcome gift. Taxes and fees apply.