When you use health and social services, the doctor, nurse or other health and social service professional records the details of the visit in Kanta Services. Pharmacies also save prescription information in Kanta. You can view this information yourself in MyKanta.
Health and social service providers are responsible for ensuring that the information they store in Kanta is correct and that it is processed appropriately. Your is used only when it is necessary for your treatment or service. Your permission is also required for the use of your data.
What do data protection and data security mean?
Data protection refers to protection of personal data. It is based on legislation and is a fundamental right for everyone. The purpose of data protection is to ensure that your personal data is processed lawfully, transparently and only for the purpose for which it was collected.
Personal data includes all data that can be used to identify a person. Everyone has the right to know how their personal data is processed.
In Kanta Services, data protection guides all processing of personal information, and it helps us ensure the confidentiality and protection of data.
Data security refers to practical methods of protecting confidential information. These methods include technical protection and testing.
This is how Kanta data security is ensured
We ensure the data security of Kanta Services in several ways and test Kanta systems regularly. We also cooperate with other authorities, such as the National Cyber Security Centre.
We only process personal information when it is necessary, for example, in the investigation of disruptions or in the maintenance of systems.
How data security is monitored
We require a high level of data security from the health and social service providers using Kanta. When a new service provider joins Kanta, it must submit a certificate from an independent assessment body to Kela, proving that the system used by the service provider is secure. The certificate must be approved by the Finnish Transport and Communications Agency (Traficom).
Kela, health and social service providers and pharmacies monitor the implementation of their own data security. Kela, service providers and pharmacies have their own data security plans. Each is responsible for implementing the data security plan and keeping it up to date.
Accessing of data always generates a record
Viewing and disclosing customer data requires strong identification and a care relationship from the professional. Your permission is required for the disclosure of customer information. Each time a professional views or discloses your data, a log entry is recorded. The log data allows you to find out who has viewed or disclosed your data and on what grounds.
Health and social services and pharmacies monitor the use of data with the help of log data.
You can receive guidance from the data protection officer
Kanta Services, health and social service providers and pharmacies all have data protection officers (DPOs). They monitor the implementation of data protection and guide the organisation in matters related to data protection.
The data protection officer also provides guidance on questions related to the rights of the data subject.
Frequently asked questions about data protection and data security
The names of the individuals who have processed your data are not shown in MyKanta due to social welfare and healthcare professionals’ protection of privacy in working life. This restriction is based on the Electronic Prescription Act and the Client Data Act.
The data in Kanta is not stored in cloud services. The system reform of Kela’s benefit processing – the Eepos programme – and the related cloud service transition do not apply to Kanta Services.
The privacy policies are available on the kanta.fi website.