Overview
- The Agência Nacional de Proteção de Dados (ANPD) instituted a Processo Administrativo Sancionador against Instituto Saúde e Cidadania to investigate a 2025 ransomware attack that exposed roughly 500,000 patient records.
- The leaked files included names, dates of birth and sensitive health information such as exam histories, medical records, prescriptions, outpatient care, hospitalizations, diagnoses and procedures.
- Of the affected records, about 78,772 belong to children and adolescents and 47,921 to elderly patients, raising heightened privacy and harm concerns for vulnerable groups.
- The ANPD found Isac published a site notice instead of sending individual notifications and said Isac’s claim that only administrative or closed-contract data were accessed was not substantiated, and Isac has 10 business days to present its defense.
- If the agency finds LGPD violations the penalties range from warning and fines up to statutory limits to suspension or prohibition of data-processing activities which could disrupt the operator’s management of public-health units and affect patient trust.