Brazil ANPD Moves Against Isac Over 500,000 Patients
Brazil’s ANPD opened a sanctioning case against Isac over a security incident that may have exposed data from 500,000 patients.
In July 2026, Brazil’s National Data Protection Authority, the ANPD, opened an administrative sanctioning proceeding against Instituto Saúde e Cidadania (Isac) over a security incident that may have compromised data from about 500,000 patients. The agency gave the company ten business days to submit its defense and, so far, has not imposed any effective penalty.
In July 2026, Brazil’s National Data Protection Authority, the ANPD, opened an administrative sanctioning proceeding against Instituto Saúde e Cidadania (Isac) over a security incident that may have compromised data from about 500,000 patients. The agency gave ten business days for the company to file its defense and, so far, has not imposed any effective penalty.
What Isac said
Instituto Saúde e Cidadania denied that the cyberattack led to a data breach involving patients’ records. At the same time, it acknowledged that the incident affected the availability of its systems. According to the information released, the organization said it had strengthened its information security controls and expanded its protection, monitoring, and incident response measures.
Possible penalties
The case falls under Article 52 of Brazil’s LGPD, which sets out nine types of administrative sanctions. Those include a warning, a simple fine of up to 2% of revenue in Brazil, capped at R$50 million per violation, a daily fine with the same ceiling, public disclosure of the violation, and the blocking or deletion of data tied to the infringement.
Turivius includes those provisions in its LGPD fines guide for 2026, while in Isac’s case the ANPD says the matter remains under review. No sanction has been confirmed so far.
Enforcement capacity
The case comes as the ANPD has been stepping up its focus on security incidents and the processing of personal data. At the same time, references to authorized hiring for the agency point to an expansion of institutional capacity for oversight and compliance, in a context where practical guidance on LGPD alignment is also growing around artificial intelligence, cookies, and data breach management.
Taken together with the proceeding against Isac, those materials point to more active oversight of incidents involving personal information in Brazil, although in this specific case the authority has not yet decided on a penalty.
Sources
- Brazil LGPD Compliance Guide for Organizationsampcuscyber.com· Ampcus Cyber
- ANPD apura vazamento de dados de 500 mil pacientespoder360.com.br· Poder360
- Multas LGPD 2026: quem a ANPD já sancionou e por quêturivius.com· Turivius
- ANPD processa Isac após vazamento de dados de 500 mil pacientesboca.com.br· Boca Jornalismo
- IA e LGPD: o que muda para empresas que usam inteligência artificialscansource.com.br· ScanSource Brasil
- Brazil LGPD + ANPD AI Guidance in 2026callsphere.ai· CallSphere
- Concurso ANPD: autorizado com 50 vagas para Especialistaestrategiaconcursos.com.br· Estratégia Concursos
- What Are the LGPD Cookie Consent Requirements?cookiechimp.com· CookieChimp
- Vazamento de dados: como saber se você foi atingidoserasa.com.br· Serasa
- Proteção de Dados no Brasil: A maturidade que se constrói em redemigalhas.com.br· Migalhas



