CiberLATAMbywhalemate

Brazil ANPD probes Goiás patient data leak

Brazil’s data authority opened a sanctioning case over a ransomware attack on Isac in Goiás involving about 500,000 patients.

Whalemate Labs · AI-assisted researchJul 18, 20263 min read

Brazil’s National Data Protection Authority, the ANPD, has opened an administrative sanctioning proceeding to investigate alleged data protection failures affecting about 500,000 patients hit by a ransomware attack on the Instituto de Saúde de Anápolis (Isac), in Goiás.

Brazil’s National Data Protection Authority, the ANPD, has opened an administrative sanctioning proceeding to investigate alleged data protection failures affecting about 500,000 patients hit by a ransomware attack on the Instituto de Saúde de Anápolis (Isac), in Goiás. The case also involves a possible leak of sensitive medical information.

Ongoing investigation

Based on the information available, the ANPD is acting as the investigative authority in a case that remains open. The institute will be able to present its defense within the proceeding. If LGPD violations are confirmed, possible penalties include warnings, fines, or suspension of data processing.

The announcement puts back in focus the obligations set out in Brazil’s LGPD for the handling of sensitive personal data, especially in healthcare, where clinical information requires specific safeguards.

Data subjects’ rights and the LGPD framework

On its LGPD page, BNDES lists data subjects’ rights, including confirming whether processing exists, accessing information, correcting it, blocking or deleting it, requesting portability, and knowing how data is shared. That framework offers a practical reference for understanding what tools a person has when they believe their information was handled improperly.

Other regulatory moves in the region

In Peru, the National Authority for Personal Data Protection, part of the Ministry of Justice, sets out a formal process for reporting misuse of personal data. The complaint can be filed online, with a form and tracking through the Document Management System or by email, or in person at the ministry’s Mesa de Partes. According to the available material, the sanctioning procedure can take up to 160 business days in total, with separate deadlines for the investigation and final decision.

In Brazil, specialized press reports say the ANPD’s top priority for the next period will be regulating online age verification models, with enforcement scheduled to begin in January 2027 as part of the implementation of the Digital ECA.

In Mexico, the federal government fined the Mexican Football Federation 42.8 million pesos for violations of personal data protection law in the operation of the Fan ID system, a case that shows the effective use of multimillion-peso sanctions in sports privacy enforcement.

Sources

View all