CiberLATAMbywhalemate

Brazil ANPD Moves Against Isac Over 500,000 Patients

Brazil’s ANPD opened a sanctioning case against Isac over a security incident that may have exposed data from 500,000 patients.

Whalemate Labs · AI-assisted researchJul 14, 20262 min read

In July 2026, Brazil’s National Data Protection Authority, the ANPD, opened an administrative sanctioning proceeding against Instituto Saúde e Cidadania (Isac) over a security incident that may have compromised data from about 500,000 patients. The agency gave the company ten business days to submit its defense and, so far, has not imposed any effective penalty.

In July 2026, Brazil’s National Data Protection Authority, the ANPD, opened an administrative sanctioning proceeding against Instituto Saúde e Cidadania (Isac) over a security incident that may have compromised data from about 500,000 patients. The agency gave ten business days for the company to file its defense and, so far, has not imposed any effective penalty.

What Isac said

Instituto Saúde e Cidadania denied that the cyberattack led to a data breach involving patients’ records. At the same time, it acknowledged that the incident affected the availability of its systems. According to the information released, the organization said it had strengthened its information security controls and expanded its protection, monitoring, and incident response measures.

Possible penalties

The case falls under Article 52 of Brazil’s LGPD, which sets out nine types of administrative sanctions. Those include a warning, a simple fine of up to 2% of revenue in Brazil, capped at R$50 million per violation, a daily fine with the same ceiling, public disclosure of the violation, and the blocking or deletion of data tied to the infringement.

Turivius includes those provisions in its LGPD fines guide for 2026, while in Isac’s case the ANPD says the matter remains under review. No sanction has been confirmed so far.

Enforcement capacity

The case comes as the ANPD has been stepping up its focus on security incidents and the processing of personal data. At the same time, references to authorized hiring for the agency point to an expansion of institutional capacity for oversight and compliance, in a context where practical guidance on LGPD alignment is also growing around artificial intelligence, cookies, and data breach management.

Taken together with the proceeding against Isac, those materials point to more active oversight of incidents involving personal information in Brazil, although in this specific case the authority has not yet decided on a penalty.

Sources

View all