Particle.news
Download on the App Store

ANPD Opens Sanction Process Against Isac Over 2025 Ransomware Leak

Regulators say the operator failed to prove the breach was limited and did not individually notify affected patients which could lead to fines or limits on its health-data activities.

Overview

  • The Agência Nacional de Proteção de Dados (ANPD) instituted a Processo Administrativo Sancionador against Instituto Saúde e Cidadania to investigate a 2025 ransomware attack that exposed roughly 500,000 patient records.
  • The leaked files included names, dates of birth and sensitive health information such as exam histories, medical records, prescriptions, outpatient care, hospitalizations, diagnoses and procedures.
  • Of the affected records, about 78,772 belong to children and adolescents and 47,921 to elderly patients, raising heightened privacy and harm concerns for vulnerable groups.
  • The ANPD found Isac published a site notice instead of sending individual notifications and said Isac’s claim that only administrative or closed-contract data were accessed was not substantiated, and Isac has 10 business days to present its defense.
  • If the agency finds LGPD violations the penalties range from warning and fines up to statutory limits to suspension or prohibition of data-processing activities which could disrupt the operator’s management of public-health units and affect patient trust.