CiberLATAMbywhalemate

Brazil ANPD sanctions case involving 500,000 patients

Brazil’s ANPD opened a sanctions case over data protection failures affecting 500,000 public health patients. ISAC cited ransomware and denied a leak.

Whalemate Labs · AI-assisted researchJul 14, 20262 min read

Brazil’s National Data Protection Authority has opened a sanctions proceeding against a social organization over a data protection failure affecting 500,000 patients treated in public health units. The case involves information tied to at least six states and, according to local coverage, remains under review with no penalties imposed so far.

Brazil’s National Data Protection Authority has opened a sanctions proceeding against a social organization over a data protection failure affecting 500,000 patients treated in public health units. The case involves records linked to at least six states, and it has opened a dispute between the regulator’s account and the health operator’s response.

Scope of the incident

Agência Brasil reported that the attack affected public health units in Goiás, Rio Grande do Sul, Bahia, Alagoas, Piauí and Tocantins. According to that coverage, the exposure reached about 500,000 patients, including roughly 78,000 minors and 47,000 older adults. That mix increases the sensitivity of the case under Brazil’s LGPD, given the populations involved and the nature of the information at issue.

Also according to Agência Brasil, the records included names, dates of birth, exam history, medical charts, prescriptions, appointments, hospitalizations and diagnoses. That data set places the incident in the category of sensitive personal data under the LGPD and broadens the regulatory exposure for Instituto Saúde e Cidadania, as well as other health operators that handle data from Brazilian residents.

The operator’s version

Poder360 reported the position of Instituto Saúde e Cidadania, which described the episode as a ransomware attack that took place in January 2025. The organization said the attack caused temporary unavailability of administrative systems through file encryption, but denied that there had been any patient data leak.

In the same report, ISAC said the ANPD case is still in the analysis phase and that, so far, the authority had not imposed any penalty or sanction. That procedural status leaves the case in the administrative fact-finding stage.

The statement cited by Poder360 added that the organization restored its systems from backups after the ransomware attack. That technical detail is likely to be one of the elements ANPD weighs as it assesses whether continuity and security measures were sufficient in light of the incident.

What ANPD is looking at now

The proceeding comes amid a broader push by ANPD to enforce rules around incidents involving sensitive data processing, especially in health. The combination of scale, data type, and the presence of minors and older adults makes this a relevant reference point for operators with activities in Brazil and regional operations tied to LGPD compliance.

Sources

View all