Brazil ANPD probes Isac ransomware attack
Brazil's ANPD opened a case against Isac Tecnologia em Saúde over a ransomware attack that exposed data on about 500,000 patients.
Brazil's data protection authority has opened an administrative sanctions case to examine possible failures in protecting information tied to roughly 500,000 patients affected by a ransomware attack on Isac Tecnologia em Saúde, the system provider used by clinics and hospitals in Brazil.
Brazil's Autoridade Nacional de Proteção de Dados has opened an administrative sanctions case to examine possible failures in protecting information tied to about 500,000 patients affected by a ransomware attack against Isac Tecnologia em Saúde's clinic and hospital management system.
What the ANPD is investigating
According to O Hoje, the attack exposed personal and sensitive patient data, including health information stored in electronic medical records used by Brazilian clinics and hospitals that contract for the system. The ANPD launched the proceeding under Brazil's Lei Geral de Proteção de Dados, and it is considering possible shared responsibility between the technology company and healthcare institutions for the security failures that allowed the incident.
The administrative sanctions process is still underway. The same report says Isac Tecnologia em Saúde will still be able to present its defense over the attack that affected patient data at clinics and hospitals in different parts of the country.
Regional scope and investigative tension
The case also drew attention in Alagoas. O Jornal Extra reported that the ANPD is investigating a hacker attack that affected patient data at clinics in that state, suggesting a specific impact there and a local review alongside the national administrative case already under way.
That coverage added an important wrinkle. According to the health institute cited by the outlet, internal technical analyses found no evidence of extraction, exfiltration, or improper disclosure of personal data. That account contrasts with earlier reports that described information exposure and shows that, at least at that point, there was a gap between the local technical assessment and the ANPD's suspicion of a possible leak.
Part of a wider wave
The incident comes amid growing pressure on the healthcare sector. A sector report cited by Tom's Hardware Italia said there were 410 ransomware attacks against organizations and companies tied to healthcare in the first half of 2026. The same source said the median ransom demand reached $310,000 for care providers, close to the $300,000 seen for other companies.
That figure does not confirm any ransom demand in the Isac Tecnologia em Saúde case, but it does place the episode within a broader pattern of attacks on the supply chain of hospital software, with hospitals and clinics depending on external systems to manage medical records and internal operations.
Sources
- Ataque hacker expõe dados de 500 mil pacientes e leva ANPD a investigar falhas na proteçãoohoje.com· O Hoje
- ANPD investiga ataque hacker que atingiu dados de pacientes em Alagoasojornalextra.com.br· O Jornal Extra (Alagoas)
- Il ransomware cambia bersaglio e assedia la filiera sanitariatomshw.it· Tom's Hardware Italia
- Cibersegurança: como proteger hospitais sem parar a operaçãodatasigh.com.br· Datasigh



