Imagem de fallback

ANPD Initiates Administrative Sanction Proceedings Against Brazilian Social Organization Following Security Incident Affecting Data of 500,000 Patients

The National Data Protection Agency (ANPD) has opened an Administrative Sanctioning Proceeding against the Instituto Saúde e Cidadania (Isac), a social organization responsible for managing public health facilities in states such as Goiás, Rio Grande do Sul, Bahia, Alagoas, Piauí, and Tocantins. The case originated from a ransomware attack that occurred in 2025 and was reported by Isac itself to the ANPD, which triggered the investigation. According to Isac, the incident affected approximately 500,000 records, of which 78,772 reportedly belonged to children and adolescents and 47,921 to the elderly. The affected data included identification information, such as name and date of birth, and sensitive personal health data, such as test histories, medical records, prescriptions, outpatient care, hospital admissions, diagnoses, and procedures performed — a category that receives heightened protection under the LGPD.

The ANPD’s investigation focuses not only on the attack itself, but also on the way Isac responded to the incident in light of the LGPD and of the Agency. The communication of security incidents is governed by Resolution CD/ANPD No. 15 of April 24, 2024, which approved the Security Incident Communication Regulation (CIS) and sets a deadline of three business days — counted from the moment the controller becomes aware that the incident affected personal data — for reporting to the ANPD. According to the Agency this and other procedures were allegedly not properly observed by Isac, which merely published a generic notice on its institutional website, without stating the date of the incident, the nature of the data and of the individuals affected, or the measures adopted before and after the attack — items required both by the LGPD and by the CIS Regulation.

In addition to the communication deemed insufficient, the Agency points out that Isac allegedly failed to present technical evidence to support its claim that the attackers had accessed only administrative data and already-terminated contracts — an argument used by the institution to minimize the risk to data subjects, but which, according to the ANPD, was not substantiated even after repeated requests. The infraction notice further records that Isac does not make available, on its portal, information about the officer in charge of personal data processing (also referred to as the DPO, by its English acronym), the person responsible for serving as a channel between the institution, the data subjects, and the ANPD — an absence that, according to the Agency, would in itself constitute a breach of the LGPD.

From the date of notification, the entity will have ten business days to present its defense. Should the proceeding result in a conviction, the ANPD will not only apply the appropriate penalty but also indicate to Isac the measures needed to bring its operations into compliance. The range of sanctions provided for in Article 52 of the LGPD is broad, ranging from a warning to a fine of up to 2% of the entity’s revenue, and may extend to the suspension or prohibition of personal data processing activities.

Learn more.