ANPD initiates enforcement action against healthcare organization for data protection failure affecting 500,000 patients
Original title: ANPD instaura processo de sanção contra OS por falha na proteção de dados de 500 mil pacientes
ANPD has initiated an enforcement action against a healthcare organization following a cyberattack that exposed sensitive personal data of 500,000 patients in health units managed by Instituto Saúde e Cidadania (Isac) across multiple Brazilian states. This action demonstrates ANPD's enforcement of data protection obligations for healthcare providers under Brazilian data protection law. Healthcare organizations operating across multiple states must ensure robust cybersecurity measures and incident response protocols to protect patient data.
What changed
- ANPD initiated a formal sanctions process against the healthcare organization responsible for managing health units under Instituto Saúde e Cidadania (Isac) due to inadequate data protection measures that allowed a cyberattack to expose sensitive data of 500,000 patients across multiple Brazilian states.
Who is affected
Healthcare organizations and private entities managing public health units in Brazil
Summary generated by a language model; the official text prevails. Not legal advice.