{"title":"When data breach hits a psychotherapy clinic: The Vastaamo case","authors":"Hadi Ghanbari, Kari Koskinen","doi":"10.1177/20438869241258235","DOIUrl":null,"url":null,"abstract":"This teaching case demonstrates the crucial role of information security and data protection in the digital era. To this end, we first discuss the importance of data protection and information security as essential business capabilities for modern organisations. We argue that approaching information security from a business model perspective, instead of a purely technical perspective, enables companies to better understand the value of data protection for ensuring business continuity and long-lasting business relationships with customers and partners. To support this viewpoint, we draw on the biggest data breach in the history of Finland that affected over 33,000 patients of Vastaamo Psychotherapy Centre. While the breach led to Vastaamo’s bankruptcy and financial and legal consequences for several stakeholders, the significance of the breach lies in its societal impact. The breadth and cruelty of the breach caused outrage across the country and led to raising consumer and industry awareness of cybersecurity. As such, this teaching case enables the audience to better understand the consequences of information security incidents on firms and their stakeholders.","PeriodicalId":37921,"journal":{"name":"Journal of Information Technology Teaching Cases","volume":"18 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-06-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Information Technology Teaching Cases","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1177/20438869241258235","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"Social Sciences","Score":null,"Total":0}
引用次数: 0
Abstract
This teaching case demonstrates the crucial role of information security and data protection in the digital era. To this end, we first discuss the importance of data protection and information security as essential business capabilities for modern organisations. We argue that approaching information security from a business model perspective, instead of a purely technical perspective, enables companies to better understand the value of data protection for ensuring business continuity and long-lasting business relationships with customers and partners. To support this viewpoint, we draw on the biggest data breach in the history of Finland that affected over 33,000 patients of Vastaamo Psychotherapy Centre. While the breach led to Vastaamo’s bankruptcy and financial and legal consequences for several stakeholders, the significance of the breach lies in its societal impact. The breadth and cruelty of the breach caused outrage across the country and led to raising consumer and industry awareness of cybersecurity. As such, this teaching case enables the audience to better understand the consequences of information security incidents on firms and their stakeholders.
期刊介绍:
The Journal of Information Technology Teaching Cases (JITTC) provides contemporary practical case materials for teaching topics in business and government about uses and effectiveness of technology, the organisation and management of information systems and the impacts and consequences of information technology. JITTC is designed to assist academics, scholars, and teachers in universities and other institutions of executive education, as well as instructors of organizational training courses. Case topics include but are not restricted to: alignment with the organization, innovative uses of technology, emerging technologies, the management of IT, including strategy, business models, change, infrastructure, organization, human resources, sourcing, system development and implementation, communications, technology developments, technology impacts and outcomes, technology futures, national policies and standards.