JustCyber Notícias
News Ransomware

Isac breach exposes 500,000 patients and triggers Brazil's ANPD

JustCyber Newsroom 2 min read ransomware · saude · lgpd

A ransomware attack on the Instituto Saúde e Cidadania (Isac), a social organization that runs public health facilities in Brazil, compromised records belonging to roughly 500,000 patients. Isac operates across six states — Goiás, Rio Grande do Sul, Bahia, Alagoas, Piauí, and Tocantins. According to reporting, the exposed data spans personal identifiers (such as name and date of birth) and sensitive health information: exam histories, medical records, prescriptions, outpatient visits, hospitalizations, diagnoses, and procedures. Tens of thousands of the affected records belong to children and adolescents, and tens of thousands more to elderly patients. Brazil’s National Data Protection Authority (ANPD) has opened a sanction process against the institution.

Why it matters

This case combines the three factors that make a healthcare incident especially serious: scale, sensitivity, and legal accountability. Health data is a special category under the LGPD — its exposure enables fraud, extortion, and discrimination, and the harm cannot be undone by resetting a password. When many of the victims are children, adolescents, or the elderly, both the risk and the duty of care rise.

Beyond harm to individuals, the ANPD process signals where the regulator is looking: not only at the technical failure that enabled the attack, but at post-incident conduct. Points under investigation reportedly include the absence of adequate security measures, poor notification of affected people, and the lack of clear information about the data protection officer. The lesson for any operator handling sensitive data is direct: prevention and response are judged together, and a weak communication plan widens legal exposure even after the attack is contained.

What to do

  • Map and classify sensitive data (health and vulnerable groups first) and minimize what you collect, retain, and replicate across systems.
  • Treat ransomware as a likely scenario: isolated and tested backups, network segmentation, phishing-resistant MFA, and monitoring for anomalous access.
  • Prepare an incident response plan with the notification flow to the regulator and to data subjects already defined — deadlines, owners, and message templates included.
  • Publish the data protection officer (DPO) contact prominently and rehearse the playbook through periodic exercises, not only on paper.

Source: TI Inside — read the original report.