Pith. sign in

REVIEW 2 major objections 6 minor 32 references

Secondary Use of Health Data: Centralized Structure and Information Security Frameworks in Finland

T0 review · 2 major / 6 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read Finland claims the world's first national framework for reusing health data, built on one permit authority and ten audited processing environments.

desk verdict Useful, honestly-labeled description of Finland's health data framework; security claims are self-reported and unverified, but the architectural and institutional detail makes it worth reading. read the letter →

arxiv 2412.06800 v1 pith:ITSOKYNJ submitted 2024-11-23 cs.CY cs.SE

classification cs.CYcs.SE
keywords secondaryuseofhealthdataFindataSecureProcessingEnvironmentKapseligovernanceinformationsecurityFinland
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper claims that Finland has built the first national-scale framework for the secondary use of health and social data: a single law governs it, a single permit authority (Findata) decides access, and ten audited Secure Processing Environments give researchers a locked place to work. It reports that these environments currently host about 1,075 active project workspaces and roughly 5,016 users, with Findata's own Kapseli environment as the reference implementation. The claim matters because the EU is now constructing the European Health Data Space, and Finland is the only member state that already has all the legal, institutional, and technical pieces assembled as one working system.

What carries the argument

The central object is the Secure Processing Environment (SPE), a locked-down virtual research platform where permitted health data can be analyzed. The argument is carried by the design of Kapseli, Findata's own SPE, whose zone architecture separates user authentication (via national identity federations plus multifactor authentication), project-specific virtual machines that have no internet access and no user administrator rights, and internal support and data-preparation services. The audit regulation issued by Findata, derived from the KATAKRI national security criteria, is the mechanism that certifies each SPE and keeps the framework verifiable.

What would settle it

A single documented breach or a failed penetration test inside an audited SPE—for example, one project environment accessing another project's data or reaching the internet—would overturn the paper's claim that the framework ensures data isolation and security as described.

Watch

Extended reading notes

Core claim

On its own terms, the paper's central claim is that a centralized permit authority combined with audited, isolated data-processing environments makes secondary use of health data both possible and safe at a national level. The concrete discovery is descriptive: Finland operates ten audited Secure Processing Environments, the first such set in the world, overseen by Valvira and regulated by Findata, and researchers use them at scale. The paper further describes the Kapseli environment, which realizes the framework with four zones—access control, the secure processing area, support services, and an internal area for pseudonymization and harmonization—so that research projects are fully isolated from one another and from the internet.

Load-bearing premise

The whole security argument assumes that the audits of the ten Secure Processing Environments are genuinely enforced and that certified organizations continue to follow the rules after the audit is over; the paper presents no audit results, penetration tests, or incident records to back that up.

Editorial extensions

If this is right

  • Other EU member states can copy the structure: a single data-permit authority plus regulated, audited processing environments.
  • The Kapseli zone architecture is a concrete blueprint for building compliant environments under the European Health Data Space.
  • The reported volumes (about 1,075 active environments, roughly 5,000 users) indicate that researchers actually use the system, not just that it exists on paper.
  • The audit-based approach converts information-security requirements into a checklist that third parties can enforce.
  • A country adopting Finland's model can avoid building one centralized data warehouse; it can instead connect multiple audited enclaves to a single permit authority.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The paper's 'first in the world' claim is about institutional design, not technology; the same outcome could be reached elsewhere with different technical choices.
  • If the audit process is as strong as described, the same framework could be extended cross-border under EHDS, with one country's permit authority recognizing another country's audited environments.
  • The paper gives no evidence on research outcomes, so an open question is whether the centralized permission model slows, speeds, or leaves unchanged the production of research findings.
  • A testable extension would be comparing researcher waiting times and data-error rates in Finland's model with countries using distributed or contractual access models.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 6 minor

Summary. The paper describes Finland's centralized framework for the secondary use of health and social data, covering the Act on Secondary Use of Health and Social Data, the permit authority Findata, the regulation of Secure Processing Environments (SPEs), and the Kapseli environment operated by CSC. It reports the existence of ten audited SPEs, gives approximate usage volumes in Table 2, and presents Kapseli's zone architecture (Access Control Zone, SPE-Secure Zone, Support Zone, Internal SPE) as the paper's technical contribution. The stated aim is to provide an overview and implementation aspects useful for researchers and for countries building similar infrastructure in the context of the European Health Data Space.

Significance. If the description is accurate, the paper is a useful reference for other European data-access bodies implementing EHDS, because it documents a working national permit-and-SPE model with concrete scale (about 1,075 active environments and 5,000 active users) and a named architecture connected to KATAKRI, eIDAS, Suomi.fi, Haka, and Virtu. The paper's strengths are the concreteness of Table 2, the clear institutional and legislative chain, and the catalogue of related European projects in Table 1. Its main weakness is that the security claims are self-reported by authors affiliated with Findata and CSC, and the paper supplies no independent verification, audit outcomes, or runtime evidence for the most load-bearing technical assertion, namely that Kapseli provides full data isolation. As an experience report the paper is plausible and potentially valuable, but the gap between the strength of the claims and the evidence provided needs to be addressed.

major comments (2)
  1. [Section 4, 'Kapseli Architecture' and 'Kapseli Security'] The paper's central security claim -- that each Kapseli environment is isolated from other environments and from the internet, and that all data and software must pass through Findata's inspection -- is supported only by a high-level architecture diagram and by the statement that Kapseli is audited by an external auditor. The text does not describe the data egress path (how researchers export results out of Kapseli), the enforcement mechanism for blocking outbound connections, the monitoring or logging evidence, or the scope and outcome of the external audit. Since two authors are affiliated with Findata and one with CSC, the operator of Kapseli, the claim is a self-report that cannot be checked from the paper alone. Please either add a concrete description of egress control and isolation enforcement (for example, network filtering, proxy inspection, result-review procedures, and administrative privilege separation) or qualify the claim as describing the intended design, and explicitly state that audit reports are confidential and not reviewed in the paper.
  2. [Section 3, 'Data Usage Environments'] The sentence that states Finland has 'ten audited SPEs, whose compliance with the law is overseen by Valvira' conflates inclusion on Valvira's register with an ongoing operational assurance mechanism. No audit outcomes, audit frequency, remediation requirements, or consequences of failed audits are provided anywhere in the paper. Because this oversight is later used to support the framework's security value, please clarify the actual assurance model -- for instance, whether Valvira performs continuous supervision, periodic re-audits, or only receives and registers audit reports -- and state what the audit criterion in Findata's regulation [3] actually verifies.
minor comments (6)
  1. [Table 2] The 'Total' row gives 5,016 active users, but the listed row values sum to 5,011 (1300+354+2+816+1000+1204+65+10+260). Please correct the total or explain the discrepancy (for example, approximate values, rounding, or a user counted in more than one environment).
  2. [References and citation numbers] Reference [32] is cited twice with different meanings: in Section 2 it denotes the VTT report on the Act's impact on AI research, while in Section 4 it denotes the Virtu identification system. Only the Virtu URL appears in the reference list. The VTT report should be added and renumbered, or the in-text citations should be corrected.
  3. [Table 2] The SPE named 'SPESiOR' in Table 2 is written as 'SPECIOR' in reference 14; please make the spelling consistent.
  4. [Abstract and Section 1] The claim that Finland's specialized institutions are 'the first of their kind in the world' is asserted without a comparative survey. I suggest softening this to 'one of the first' or substantiating it with a broader comparison, because Table 1 only lists a few recent European initiatives and does not rule out earlier similar models elsewhere.
  5. [Section 4, 'Kapseli Security'] The description of security frameworks is too vague to be informative: listing 'Microsoft Admin Tier model, MFA and other well-known security frameworks, such as CIS Benchmarks' does not explain how they are applied in Kapseli. Please state the concrete mechanisms used (for example, how the tier model is used to partition administrative roles, which MFA methods are supported, and which CIS benchmark profiles are applied) or explicitly mark this as a reference list rather than a design specification.
  6. [General] The paper should include an explicit conflict-of-interest or acknowledgment statement noting that the authors are directly involved in the operation of Findata and Kapseli and that the technical description is based on institutional knowledge of these systems.

Circularity Check

0 steps flagged · score 0.0 of 10

No circular reasoning identified; the paper is a descriptive overview with no derivation chain to reduce.

full rationale

This paper does not attempt to derive a result from assumptions or equations; it is an institutional description of Finland's secondary-use health data framework, Findata, and the Kapseli secure processing environment. There are no fitted parameters, no predictive claims built from fitted inputs, and no equations that could reduce to their own inputs. The load-bearing statements are empirical descriptions: the existence of the Act, Findata as permit authority, ten audited SPEs, and Kapseli's zone architecture. These are supported by references to legislation, external audit criteria (KATAKRI), the Valvira registry, and external security frameworks (CIS Benchmarks, Microsoft Admin Tier model). The authors' affiliations with Findata and CSC create a clear self-report or conflict-of-interest concern, but that is not circular reasoning under the analysis rules: no internal argument is being justified by itself, and no cited 'uniqueness theorem' or prior same-author result is used to force a conclusion. The claim that Kapseli is audited by an external auditor is an assertion about an external process, not a derivation from the paper's own output. Similarly, the statement that SPE compliance is overseen by Valvira references an independent supervisory authority. Whether those external assurances are sufficient evidence of actual security is a correctness or verification concern, not a circularity concern. Therefore the appropriate circularity score is 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The paper introduces no new entities and fits no parameters. Its claims depend on background institutional facts: that the Finnish law creates the described powers, that the ten named environments are actually running and audited, and that the Kapseli architecture works as drawn. These are domain assumptions about the real-world system. They are checked against public sources, but the paper provides no independent evidence for their truth.

assumptions (3)
  • domain assumption The lists of SPEs and approximate user counts in Table 2 are complete and current as of late 2024.
    Section 3 states there are currently ten audited SPEs in Finland, overseen by Valvira, and Table 2 reports approximate active environments and users. The paper gives no collection date, no source for the counts, and two cells are n/a, so the completeness and freshness of this table is assumed.
  • domain assumption The external security audits of SPEs, based on Findata's regulation and KATAKRI, are competent and enforced.
    Section 3 says the SPE regulation is used as an audit criterion and that Valvira oversees compliance. The security claims of the framework rely on these audits being meaningful, but no audit results or enforcement history are presented.
  • domain assumption Data within Kapseli is actually isolated between projects and from the internet, as described in Section 4.
    The architecture description in Section 4 is asserted without test results, configuration excerpts, or independent verification. If isolation is weaker than described, the central security claim fails.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Secondary Use of Health Data: Centralized Structure and Information Security Frameworks in Finland." pith.science (2026). https://pith.science/paper/ITSOKYNJ

@misc{pith2026241206800,
  author       = {Pith},
  title        = {Pith review of: Secondary Use of Health Data: Centralized Structure and Information Security Frameworks in Finland},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/ITSOKYNJ}},
  note         = {Machine review of arXiv:2412.06800}
}
read the original abstract

The utilization of health data for secondary purposes, such as research, sta-tistics, and development, has become increasingly significant in advancing healthcare systems. To foster the above, Finland has established a framework for the secondary use of health and social data through legislative measures and the creation of specialized institutions, which are the first of their kind in the world. In this paper, we give an overview of our implementation for using secondary health and social data in a centralized fashion. As a technical contribution, we also address key implementation aspects related to implementing the framework.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

32 extracted references · 32 canonical work pages

  1. [3]

    Accessed 30 Oct 2024

    Regulations for SPE Regulations, https://findata.fi/en/services -and-instructions/regula- tions/. Accessed 30 Oct 2024. 8

  2. [1]

    Accessed 30 Oct 2024

    The Act on the Secondary Use of Health and Social Data , https://www.finlex.fi/fi/laki/ajantasa/2019/20190552. Accessed 30 Oct 2024

  3. [2]

    Accessed 30 Oct 2024

    Findata - Finnish Social and Health Data Permit Authority , https://findata.fi/en/. Accessed 30 Oct 2024

  4. [4]

    Accessed 30 Oct 2024

    Database of secondary -use environments Database of secondary -use environments , https://valvira.fi/en/healthcare-and-social-welfare/astori-register. Accessed 30 Oct 2024

  5. [5]

    Ac- cessed 30 Oct 2024

    European Health Data Space (EHDS), https://www.european -health-data-space.com/. Ac- cessed 30 Oct 2024

  6. [6]

    Ac- cessed 30 Oct 2024

    EU Parliament , https://ec.europa.eu/commission/presscorner/detail/en/IP_24_2250. Ac- cessed 30 Oct 2024

  7. [7]

    Kristina Laugesen, Jonas F Ludvigsson, Morten Schmidt, Mika Gissler, Unnur Anna Val- dimarsdottir, Astrid Lunde & Henrik Toft Sørensen (2021) Nordic Health Registry -Based Research: A Review of Health Care Systems and Key Registries, Clinical Epidemiology, 533-554, DOI: 10.2147/CLEP.S31495

  8. [8]

    Accessed 30 Oct 2024

    Operationalizing Research Access in Platform Governance What to learn from other indus- tries?, https://algorithmwatch.org/en/wp-content/uploads/2020/06/GoverningPlat- forms_IViR_study_June2020-AlgorithmWatch-2020-06-24.pdf. Accessed 30 Oct 2024

Show all 32 references
  1. [9]

    Accessed 30 Oct 2024

    How the EU Can Unlock the Private Sector’s Human -Mobility Data for Social Good , https://datainnovation.org/2022/03/how-the-eu-can-unlock-the-private-sectors-human-mo- bility-data-for-social-good/. Accessed 30 Oct 2024

  2. [10]

    Accessed 30 Oct 2024

    Hutchings R, Scobie S and Edwards N (2021) Fit for the future: International learning on digital health care Research report, Nuffield Trust Fit for the future: What can the NHS learn about digital health care from other European countries? , https://www.nuf- fieldtrust.org.uk...

  3. [11]

    Accessed 30 Oct 2024

    Scenarios for a data -driven healthcare system, https://www.sanitas.com/content/dam/sani- tas-internet/Dokumente/2021_EN_Studie_Entsolidarisiert_die_Smartwatch.pdf. Accessed 30 Oct 2024

  4. [12]

    Accessed 30 Oct 2024

    HUS Acamedic HUS Acamedic - secure operating environment, https://www.hus.fi/en/re- search-and-education/hus-acamedic-secure-operating-environment. Accessed 30 Oct 2024

  5. [13]

    Accessed 30 Oct 2024

    T3 researchers workspace https://www.pirha.fi/ammattilaiselle/tutkimus/tutkimus-ja-opin- naytetyoluvat/rekisteritutkimukset/rekisteritutkimukseen-liittyvat-hinnat. Accessed 30 Oct 2024

  6. [14]

    Accessed 30 Oct 2024

    SPECIOR SPESiOR - Secure Processing Environment, https://esior.fi/spesior/. Accessed 30 Oct 2024

  7. [15]

    Accessed 30 Oct 2024

    Fimm SandBox, https://www.helsinki.fi/en/infrastructures/fimm-technology-centre/fimm- it. Accessed 30 Oct 2024

  8. [16]

    Accessed 30 Oct 2024

    FinnGen SandBox, https://sandbox.finngen.fi/. Accessed 30 Oct 2024

  9. [17]

    Accessed 30 Oct 2024

    Findata Kapseli, https://findata.fi/en/kapseli/. Accessed 30 Oct 2024

  10. [18]

    Accessed 30 Oct 2024

    Fiona FIONA remote access system, https://stat.fi/tup/tutkijapalvelut/fiona-etakayttojarjest- elma_en.html. Accessed 30 Oct 2024

  11. [19]

    Accessed 30 Oct 2024

    SD Sesktop SD Desktop, https://sd-desktop.csc.fi/guacamole/#/. Accessed 30 Oct 2024

  12. [20]

    Accessed 30 Oct 2024

    SECDATA Secure operating environment for sensitive data , https://www.aalto.fi/en/ser- vices/secure-operating-environment-for-sensitive-data. Accessed 30 Oct 2024

  13. [21]

    Ac- cessed 30 Oct 2024

    Auria’s Atolli Auria Tietopalvelu, https://www.auria.fi/tietopalvelu/atolli/index.html. Ac- cessed 30 Oct 2024

  14. [22]

    Accessed 30 Oct 2024

    Microsoft Admin Tier model , https://learn.microsoft.com/en-us/microsoft-identity-mana- ger/pam/tier-model-for-partitioning-administrative-privileges. Accessed 30 Oct 2024

  15. [23]

    Accessed 30 Oct 2024

    CIS Security, https://www.cisecurity.org/. Accessed 30 Oct 2024

  16. [24]

    Accessed 30 Oct 2024

    EOSC ENTRUST, https://eosc-entrust.eu/. Accessed 30 Oct 2024

  17. [25]

    Accessed 30 Oct 2024

    Tehdas 2, https://tehdas.eu/. Accessed 30 Oct 2024

  18. [26]

    Accessed 30 Oct 2024

    TRE UK, https://www.uktre.org/en/latest/. Accessed 30 Oct 2024. 9

  19. [27]

    Ac- cessed 30 Oct 2024

    EHDS Community of practice , https://health.ec.europa.eu/ehealth-digital-health-and- care/eu-cooperation/health-data-access-bodies-community-practice_en?prefLang=et. Ac- cessed 30 Oct 2024

  20. [28]

    Accessed 30 Oct 2024

    HealthData@EU Pilot, https://ehds2pilot.eu/. Accessed 30 Oct 2024

  21. [29]

    Accessed 30 Oct 2024

    eIDAS, https://digital-strategy.ec.europa.eu/en/policies/eidas-regulation. Accessed 30 Oct 2024

  22. [30]

    Accessed 30 Oct 2024

    Suomi.fi identification, https://www.suomi.fi/e-authorizations. Accessed 30 Oct 2024

  23. [31]

    Accessed 30 Oct 2024

    Haka identification, https://wiki.eduuni.fi/x/NYigAQ. Accessed 30 Oct 2024

  24. [32]

    Accessed 30 Oct 2024

    Virtu identification, https://wiki.eduuni.fi/x/6ISwAQ. Accessed 30 Oct 2024

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.