Brazil ANPD probes Goiás patient data leak
Brazil’s data authority opened a sanctioning case over a ransomware attack on Isac in Goiás involving about 500,000 patients.
Brazil’s National Data Protection Authority, the ANPD, has opened an administrative sanctioning proceeding to investigate alleged data protection failures affecting about 500,000 patients hit by a ransomware attack on the Instituto de Saúde de Anápolis (Isac), in Goiás.
Brazil’s National Data Protection Authority, the ANPD, has opened an administrative sanctioning proceeding to investigate alleged data protection failures affecting about 500,000 patients hit by a ransomware attack on the Instituto de Saúde de Anápolis (Isac), in Goiás. The case also involves a possible leak of sensitive medical information.
Ongoing investigation
Based on the information available, the ANPD is acting as the investigative authority in a case that remains open. The institute will be able to present its defense within the proceeding. If LGPD violations are confirmed, possible penalties include warnings, fines, or suspension of data processing.
The announcement puts back in focus the obligations set out in Brazil’s LGPD for the handling of sensitive personal data, especially in healthcare, where clinical information requires specific safeguards.
Data subjects’ rights and the LGPD framework
On its LGPD page, BNDES lists data subjects’ rights, including confirming whether processing exists, accessing information, correcting it, blocking or deleting it, requesting portability, and knowing how data is shared. That framework offers a practical reference for understanding what tools a person has when they believe their information was handled improperly.
Other regulatory moves in the region
In Peru, the National Authority for Personal Data Protection, part of the Ministry of Justice, sets out a formal process for reporting misuse of personal data. The complaint can be filed online, with a form and tracking through the Document Management System or by email, or in person at the ministry’s Mesa de Partes. According to the available material, the sanctioning procedure can take up to 160 business days in total, with separate deadlines for the investigation and final decision.
In Brazil, specialized press reports say the ANPD’s top priority for the next period will be regulating online age verification models, with enforcement scheduled to begin in January 2027 as part of the implementation of the Digital ECA.
In Mexico, the federal government fined the Mexican Football Federation 42.8 million pesos for violations of personal data protection law in the operation of the Fan ID system, a case that shows the effective use of multimillion-peso sanctions in sports privacy enforcement.
Sources
- Governança de IA não espera a lei: o que a ANPD já cobra da sua empresa ...facilita.etc.br· facilita.etc.br
- ¿Es legal que retengan o fotografíen tu DNI al ingresar a un local? Esto dice la ANPD y así puedes denunciarinfobae.com· Infobae Perú
- Lei Geral de Proteção de Dados (LGPD) - BNDESbndes.gov.br· BNDES
- ANPD lista potenciais prioridades regulatórias para próximo biêniorpnasredes.com.br· RPN as Redes
- ANPD abre processo por vazamento de dados de 500 mil pacientes: o que a LGPD exige de empresas e instituições públicasadvnobrasil.com.br· Advogados no Brasil
- Federación Mexicana de Futbol es multada por violaciones en uso del Fan ID889noticias.mx· 889 Noticias
- ANPD em 2026: principais regulamentos, consultas públicas e tendênciaslhlaw.com.br· LHLaw
- A ANPD virou agência reguladora. O que muda para ...piersec.com.br· PierSec
- Ataque hacker expõe dados de 500 mil pacientes e leva ANPD a investigar falhas na proteçãoohoje.com· O Hoje
- Brasile: nuove regole per le piattaforme digitali – la LGPD si fa più severanakedpact.com· NakedPact
- Comunicado de Prensa No. 084 – Nuevo Régimen Sancionatorio Aduanerodian.gov.co· DIAN



