Brazil ANPD sanctions case involving 500,000 patients
Brazil’s ANPD opened a sanctions case over data protection failures affecting 500,000 public health patients. ISAC cited ransomware and denied a leak.
Brazil’s National Data Protection Authority has opened a sanctions proceeding against a social organization over a data protection failure affecting 500,000 patients treated in public health units. The case involves information tied to at least six states and, according to local coverage, remains under review with no penalties imposed so far.
Brazil’s National Data Protection Authority has opened a sanctions proceeding against a social organization over a data protection failure affecting 500,000 patients treated in public health units. The case involves records linked to at least six states, and it has opened a dispute between the regulator’s account and the health operator’s response.
Scope of the incident
Agência Brasil reported that the attack affected public health units in Goiás, Rio Grande do Sul, Bahia, Alagoas, Piauí and Tocantins. According to that coverage, the exposure reached about 500,000 patients, including roughly 78,000 minors and 47,000 older adults. That mix increases the sensitivity of the case under Brazil’s LGPD, given the populations involved and the nature of the information at issue.
Also according to Agência Brasil, the records included names, dates of birth, exam history, medical charts, prescriptions, appointments, hospitalizations and diagnoses. That data set places the incident in the category of sensitive personal data under the LGPD and broadens the regulatory exposure for Instituto Saúde e Cidadania, as well as other health operators that handle data from Brazilian residents.
The operator’s version
Poder360 reported the position of Instituto Saúde e Cidadania, which described the episode as a ransomware attack that took place in January 2025. The organization said the attack caused temporary unavailability of administrative systems through file encryption, but denied that there had been any patient data leak.
In the same report, ISAC said the ANPD case is still in the analysis phase and that, so far, the authority had not imposed any penalty or sanction. That procedural status leaves the case in the administrative fact-finding stage.
The statement cited by Poder360 added that the organization restored its systems from backups after the ransomware attack. That technical detail is likely to be one of the elements ANPD weighs as it assesses whether continuity and security measures were sufficient in light of the incident.
What ANPD is looking at now
The proceeding comes amid a broader push by ANPD to enforce rules around incidents involving sensitive data processing, especially in health. The combination of scale, data type, and the presence of minors and older adults makes this a relevant reference point for operators with activities in Brazil and regional operations tied to LGPD compliance.
Sources
- Brazil's Data Protection Lawcsis.org· CSIS
- What Are the LGPD Cookie Consent Requirements?cookiechimp.com· CookieChimp
- Organização social é investigada por vazamento de dados de pacientesagenciabrasil.ebc.com.br· Agência Brasil
- ANPD instaura processo de sanção contra organização social por falha na proteção de dados de 500 mil pacientes de unidades públicas de saúdegov.br· Autoridade Nacional de Proteção de Dados (ANPD)
- ANPD apura vazamento de dados de 500 mil pacientespoder360.com.br· Poder360
- Multas LGPD 2026: quem a ANPD já sancionou e por quêturivius.com· Turivius
- NEWSLETTER PRIVACY & TECH (JUN/26)viseu.com.br· Viseu Advogados
- Brazil LGPD Compliance Guide for Organizationsampcuscyber.com· Ampcus Cyber



