REVIEW 2 major objections 6 minor 32 references
Secondary Use of Health Data: Centralized Structure and Information Security Frameworks in Finland
T0 review · 2 major / 6 minor · reviewed 2026-08-12 · deepseek-v4-flash
Pith's one-line read Finland claims the world's first national framework for reusing health data, built on one permit authority and ten audited processing environments.
desk verdict Useful, honestly-labeled description of Finland's health data framework; security claims are self-reported and unverified, but the architectural and institutional detail makes it worth reading. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the Secure Processing Environment (SPE), a locked-down virtual research platform where permitted health data can be analyzed. The argument is carried by the design of Kapseli, Findata's own SPE, whose zone architecture separates user authentication (via national identity federations plus multifactor authentication), project-specific virtual machines that have no internet access and no user administrator rights, and internal support and data-preparation services. The audit regulation issued by Findata, derived from the KATAKRI national security criteria, is the mechanism that certifies each SPE and keeps the framework verifiable.
What would settle it
A single documented breach or a failed penetration test inside an audited SPE—for example, one project environment accessing another project's data or reaching the internet—would overturn the paper's claim that the framework ensures data isolation and security as described.
Extended reading notes
Core claim
On its own terms, the paper's central claim is that a centralized permit authority combined with audited, isolated data-processing environments makes secondary use of health data both possible and safe at a national level. The concrete discovery is descriptive: Finland operates ten audited Secure Processing Environments, the first such set in the world, overseen by Valvira and regulated by Findata, and researchers use them at scale. The paper further describes the Kapseli environment, which realizes the framework with four zones—access control, the secure processing area, support services, and an internal area for pseudonymization and harmonization—so that research projects are fully isolated from one another and from the internet.
Load-bearing premise
The whole security argument assumes that the audits of the ten Secure Processing Environments are genuinely enforced and that certified organizations continue to follow the rules after the audit is over; the paper presents no audit results, penetration tests, or incident records to back that up.
Editorial extensions
If this is right
- Other EU member states can copy the structure: a single data-permit authority plus regulated, audited processing environments.
- The Kapseli zone architecture is a concrete blueprint for building compliant environments under the European Health Data Space.
- The reported volumes (about 1,075 active environments, roughly 5,000 users) indicate that researchers actually use the system, not just that it exists on paper.
- The audit-based approach converts information-security requirements into a checklist that third parties can enforce.
- A country adopting Finland's model can avoid building one centralized data warehouse; it can instead connect multiple audited enclaves to a single permit authority.
Reading between the lines
- The paper's 'first in the world' claim is about institutional design, not technology; the same outcome could be reached elsewhere with different technical choices.
- If the audit process is as strong as described, the same framework could be extended cross-border under EHDS, with one country's permit authority recognizing another country's audited environments.
- The paper gives no evidence on research outcomes, so an open question is whether the centralized permission model slows, speeds, or leaves unchanged the production of research findings.
- A testable extension would be comparing researcher waiting times and data-error rates in Finland's model with countries using distributed or contractual access models.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper describes Finland's centralized framework for the secondary use of health and social data, covering the Act on Secondary Use of Health and Social Data, the permit authority Findata, the regulation of Secure Processing Environments (SPEs), and the Kapseli environment operated by CSC. It reports the existence of ten audited SPEs, gives approximate usage volumes in Table 2, and presents Kapseli's zone architecture (Access Control Zone, SPE-Secure Zone, Support Zone, Internal SPE) as the paper's technical contribution. The stated aim is to provide an overview and implementation aspects useful for researchers and for countries building similar infrastructure in the context of the European Health Data Space.
Significance. If the description is accurate, the paper is a useful reference for other European data-access bodies implementing EHDS, because it documents a working national permit-and-SPE model with concrete scale (about 1,075 active environments and 5,000 active users) and a named architecture connected to KATAKRI, eIDAS, Suomi.fi, Haka, and Virtu. The paper's strengths are the concreteness of Table 2, the clear institutional and legislative chain, and the catalogue of related European projects in Table 1. Its main weakness is that the security claims are self-reported by authors affiliated with Findata and CSC, and the paper supplies no independent verification, audit outcomes, or runtime evidence for the most load-bearing technical assertion, namely that Kapseli provides full data isolation. As an experience report the paper is plausible and potentially valuable, but the gap between the strength of the claims and the evidence provided needs to be addressed.
major comments (2)
- [Section 4, 'Kapseli Architecture' and 'Kapseli Security'] The paper's central security claim -- that each Kapseli environment is isolated from other environments and from the internet, and that all data and software must pass through Findata's inspection -- is supported only by a high-level architecture diagram and by the statement that Kapseli is audited by an external auditor. The text does not describe the data egress path (how researchers export results out of Kapseli), the enforcement mechanism for blocking outbound connections, the monitoring or logging evidence, or the scope and outcome of the external audit. Since two authors are affiliated with Findata and one with CSC, the operator of Kapseli, the claim is a self-report that cannot be checked from the paper alone. Please either add a concrete description of egress control and isolation enforcement (for example, network filtering, proxy inspection, result-review procedures, and administrative privilege separation) or qualify the claim as describing the intended design, and explicitly state that audit reports are confidential and not reviewed in the paper.
- [Section 3, 'Data Usage Environments'] The sentence that states Finland has 'ten audited SPEs, whose compliance with the law is overseen by Valvira' conflates inclusion on Valvira's register with an ongoing operational assurance mechanism. No audit outcomes, audit frequency, remediation requirements, or consequences of failed audits are provided anywhere in the paper. Because this oversight is later used to support the framework's security value, please clarify the actual assurance model -- for instance, whether Valvira performs continuous supervision, periodic re-audits, or only receives and registers audit reports -- and state what the audit criterion in Findata's regulation [3] actually verifies.
minor comments (6)
- [Table 2] The 'Total' row gives 5,016 active users, but the listed row values sum to 5,011 (1300+354+2+816+1000+1204+65+10+260). Please correct the total or explain the discrepancy (for example, approximate values, rounding, or a user counted in more than one environment).
- [References and citation numbers] Reference [32] is cited twice with different meanings: in Section 2 it denotes the VTT report on the Act's impact on AI research, while in Section 4 it denotes the Virtu identification system. Only the Virtu URL appears in the reference list. The VTT report should be added and renumbered, or the in-text citations should be corrected.
- [Table 2] The SPE named 'SPESiOR' in Table 2 is written as 'SPECIOR' in reference 14; please make the spelling consistent.
- [Abstract and Section 1] The claim that Finland's specialized institutions are 'the first of their kind in the world' is asserted without a comparative survey. I suggest softening this to 'one of the first' or substantiating it with a broader comparison, because Table 1 only lists a few recent European initiatives and does not rule out earlier similar models elsewhere.
- [Section 4, 'Kapseli Security'] The description of security frameworks is too vague to be informative: listing 'Microsoft Admin Tier model, MFA and other well-known security frameworks, such as CIS Benchmarks' does not explain how they are applied in Kapseli. Please state the concrete mechanisms used (for example, how the tier model is used to partition administrative roles, which MFA methods are supported, and which CIS benchmark profiles are applied) or explicitly mark this as a reference list rather than a design specification.
- [General] The paper should include an explicit conflict-of-interest or acknowledgment statement noting that the authors are directly involved in the operation of Findata and Kapseli and that the technical description is based on institutional knowledge of these systems.
Circularity Check
No circular reasoning identified; the paper is a descriptive overview with no derivation chain to reduce.
full rationale
This paper does not attempt to derive a result from assumptions or equations; it is an institutional description of Finland's secondary-use health data framework, Findata, and the Kapseli secure processing environment. There are no fitted parameters, no predictive claims built from fitted inputs, and no equations that could reduce to their own inputs. The load-bearing statements are empirical descriptions: the existence of the Act, Findata as permit authority, ten audited SPEs, and Kapseli's zone architecture. These are supported by references to legislation, external audit criteria (KATAKRI), the Valvira registry, and external security frameworks (CIS Benchmarks, Microsoft Admin Tier model). The authors' affiliations with Findata and CSC create a clear self-report or conflict-of-interest concern, but that is not circular reasoning under the analysis rules: no internal argument is being justified by itself, and no cited 'uniqueness theorem' or prior same-author result is used to force a conclusion. The claim that Kapseli is audited by an external auditor is an assertion about an external process, not a derivation from the paper's own output. Similarly, the statement that SPE compliance is overseen by Valvira references an independent supervisory authority. Whether those external assurances are sufficient evidence of actual security is a correctness or verification concern, not a circularity concern. Therefore the appropriate circularity score is 0.
Assumptions & free parameters
assumptions (3)
- domain assumption The lists of SPEs and approximate user counts in Table 2 are complete and current as of late 2024.
- domain assumption The external security audits of SPEs, based on Findata's regulation and KATAKRI, are competent and enforced.
- domain assumption Data within Kapseli is actually isolated between projects and from the internet, as described in Section 4.
Cite this review
Pith. "Pith review of Secondary Use of Health Data: Centralized Structure and Information Security Frameworks in Finland." pith.science (2026). https://pith.science/paper/ITSOKYNJ
@misc{pith2026241206800,
author = {Pith},
title = {Pith review of: Secondary Use of Health Data: Centralized Structure and Information Security Frameworks in Finland},
year = {2026},
howpublished = {\url{https://pith.science/paper/ITSOKYNJ}},
note = {Machine review of arXiv:2412.06800}
}
read the original abstract
The utilization of health data for secondary purposes, such as research, sta-tistics, and development, has become increasingly significant in advancing healthcare systems. To foster the above, Finland has established a framework for the secondary use of health and social data through legislative measures and the creation of specialized institutions, which are the first of their kind in the world. In this paper, we give an overview of our implementation for using secondary health and social data in a centralized fashion. As a technical contribution, we also address key implementation aspects related to implementing the framework.
Reference graph
Works this paper leans on
-
[3]
Regulations for SPE Regulations, https://findata.fi/en/services -and-instructions/regula- tions/. Accessed 30 Oct 2024. 8
work page 2024
-
[1]
The Act on the Secondary Use of Health and Social Data , https://www.finlex.fi/fi/laki/ajantasa/2019/20190552. Accessed 30 Oct 2024
work page 2019
-
[2]
Findata - Finnish Social and Health Data Permit Authority , https://findata.fi/en/. Accessed 30 Oct 2024
work page 2024
-
[4]
Database of secondary -use environments Database of secondary -use environments , https://valvira.fi/en/healthcare-and-social-welfare/astori-register. Accessed 30 Oct 2024
work page 2024
-
[5]
European Health Data Space (EHDS), https://www.european -health-data-space.com/. Ac- cessed 30 Oct 2024
work page 2024
-
[6]
EU Parliament , https://ec.europa.eu/commission/presscorner/detail/en/IP_24_2250. Ac- cessed 30 Oct 2024
work page 2024
-
[7]
Kristina Laugesen, Jonas F Ludvigsson, Morten Schmidt, Mika Gissler, Unnur Anna Val- dimarsdottir, Astrid Lunde & Henrik Toft Sørensen (2021) Nordic Health Registry -Based Research: A Review of Health Care Systems and Key Registries, Clinical Epidemiology, 533-554, DOI: 10.2147/CLEP.S31495
-
[8]
Operationalizing Research Access in Platform Governance What to learn from other indus- tries?, https://algorithmwatch.org/en/wp-content/uploads/2020/06/GoverningPlat- forms_IViR_study_June2020-AlgorithmWatch-2020-06-24.pdf. Accessed 30 Oct 2024
work page 2020
Show all 32 references
-
[9]
Accessed 30 Oct 2024
How the EU Can Unlock the Private Sector’s Human -Mobility Data for Social Good , https://datainnovation.org/2022/03/how-the-eu-can-unlock-the-private-sectors-human-mo- bility-data-for-social-good/. Accessed 30 Oct 2024
2022
-
[10]
Accessed 30 Oct 2024
Hutchings R, Scobie S and Edwards N (2021) Fit for the future: International learning on digital health care Research report, Nuffield Trust Fit for the future: What can the NHS learn about digital health care from other European countries? , https://www.nuf- fieldtrust.org.uk...
2021
-
[11]
Accessed 30 Oct 2024
Scenarios for a data -driven healthcare system, https://www.sanitas.com/content/dam/sani- tas-internet/Dokumente/2021_EN_Studie_Entsolidarisiert_die_Smartwatch.pdf. Accessed 30 Oct 2024
2024
-
[12]
Accessed 30 Oct 2024
HUS Acamedic HUS Acamedic - secure operating environment, https://www.hus.fi/en/re- search-and-education/hus-acamedic-secure-operating-environment. Accessed 30 Oct 2024
2024
-
[13]
Accessed 30 Oct 2024
T3 researchers workspace https://www.pirha.fi/ammattilaiselle/tutkimus/tutkimus-ja-opin- naytetyoluvat/rekisteritutkimukset/rekisteritutkimukseen-liittyvat-hinnat. Accessed 30 Oct 2024
2024
-
[14]
Accessed 30 Oct 2024
SPECIOR SPESiOR - Secure Processing Environment, https://esior.fi/spesior/. Accessed 30 Oct 2024
2024
-
[15]
Accessed 30 Oct 2024
Fimm SandBox, https://www.helsinki.fi/en/infrastructures/fimm-technology-centre/fimm- it. Accessed 30 Oct 2024
2024
-
[16]
Accessed 30 Oct 2024
FinnGen SandBox, https://sandbox.finngen.fi/. Accessed 30 Oct 2024
2024
-
[17]
Accessed 30 Oct 2024
Findata Kapseli, https://findata.fi/en/kapseli/. Accessed 30 Oct 2024
2024
-
[18]
Accessed 30 Oct 2024
Fiona FIONA remote access system, https://stat.fi/tup/tutkijapalvelut/fiona-etakayttojarjest- elma_en.html. Accessed 30 Oct 2024
2024
-
[19]
Accessed 30 Oct 2024
SD Sesktop SD Desktop, https://sd-desktop.csc.fi/guacamole/#/. Accessed 30 Oct 2024
2024
-
[20]
Accessed 30 Oct 2024
SECDATA Secure operating environment for sensitive data , https://www.aalto.fi/en/ser- vices/secure-operating-environment-for-sensitive-data. Accessed 30 Oct 2024
2024
-
[21]
Ac- cessed 30 Oct 2024
Auria’s Atolli Auria Tietopalvelu, https://www.auria.fi/tietopalvelu/atolli/index.html. Ac- cessed 30 Oct 2024
2024
-
[22]
Accessed 30 Oct 2024
Microsoft Admin Tier model , https://learn.microsoft.com/en-us/microsoft-identity-mana- ger/pam/tier-model-for-partitioning-administrative-privileges. Accessed 30 Oct 2024
2024
-
[23]
Accessed 30 Oct 2024
CIS Security, https://www.cisecurity.org/. Accessed 30 Oct 2024
2024
-
[24]
Accessed 30 Oct 2024
EOSC ENTRUST, https://eosc-entrust.eu/. Accessed 30 Oct 2024
2024
-
[25]
Accessed 30 Oct 2024
Tehdas 2, https://tehdas.eu/. Accessed 30 Oct 2024
2024
-
[26]
Accessed 30 Oct 2024
TRE UK, https://www.uktre.org/en/latest/. Accessed 30 Oct 2024. 9
2024
-
[27]
Ac- cessed 30 Oct 2024
EHDS Community of practice , https://health.ec.europa.eu/ehealth-digital-health-and- care/eu-cooperation/health-data-access-bodies-community-practice_en?prefLang=et. Ac- cessed 30 Oct 2024
2024
-
[28]
Accessed 30 Oct 2024
HealthData@EU Pilot, https://ehds2pilot.eu/. Accessed 30 Oct 2024
2024
-
[29]
Accessed 30 Oct 2024
eIDAS, https://digital-strategy.ec.europa.eu/en/policies/eidas-regulation. Accessed 30 Oct 2024
2024
-
[30]
Accessed 30 Oct 2024
Suomi.fi identification, https://www.suomi.fi/e-authorizations. Accessed 30 Oct 2024
2024
-
[31]
Accessed 30 Oct 2024
Haka identification, https://wiki.eduuni.fi/x/NYigAQ. Accessed 30 Oct 2024
2024
-
[32]
Accessed 30 Oct 2024
Virtu identification, https://wiki.eduuni.fi/x/6ISwAQ. Accessed 30 Oct 2024
2024
Reviewed August 12, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.