Estonian man detained over suspected illegal downloading of patient data
Estonia's Central Criminal Police have detained a 45-year-old man suspected of illegally accessing a patient database and downloading personal and medical data. A quick response by the affected company likely prevented further spread of the leaked information.

Estonia's Central Criminal Police have detained a 45-year-old Estonian citizen suspected of illegally accessing a patient database and downloading patients' personal and medical information.
The possible leak was reported to police in late August by Innovaatik, a company that provides information systems to dental care providers. The State Prosecutor's Office and the Central Criminal Police said on Thursday, September 3, that the company's computer system had been repeatedly and unlawfully accessed, with patient data downloaded from it.
Over 300 providers affected
According to police's preliminary assessment, the leak affected data linked to more than 300 Estonian healthcare providers. The exact number of patients whose data reached the suspect is still being established as part of the criminal investigation.
Data downloaded from the database included patients' personal identification codes, email addresses and medical information. Most of the information concerned dental treatment, though other medical history data may also have been included.
Aim reportedly was to expose vulnerabilities
According to available information, the suspect had been illegally using the database since late June. Jete Luik, head of the Central Criminal Police's cybercrime unit, said the man had previously been connected to the company. Investigators' preliminary theory is that his goal was to draw attention to vulnerabilities in the information system.
State Prosecutor Vahur Verte said there is currently no reason to believe the suspect used the obtained data or passed it on to anyone. Investigators say police recovered the illegally downloaded data, and the man apparently did not manage to make copies of it.
Police noted that the company's swift response likely helped prevent further spread of the leaked information. Authorities nonetheless warned that other criminals could try to exploit the leak, urging residents to be cautious if contacted regarding the data breach — any demand for money in exchange for returning or not disclosing information is most likely fraud.
A criminal case has been opened under the article covering unlawful access to a computer system. The investigation is being led by the Central Criminal Police's cybercrime unit under the supervision of the State Prosecutor's Office.

