ANPD initiates enforcement action against healthcare organization for data protection failure affecting 500,000 patients

Original title: ANPD instaura processo de sanção contra OS por falha na proteção de dados de 500 mil pacientes

ANPD has initiated an enforcement action against a healthcare organization following a cyberattack that exposed sensitive personal data of 500,000 patients in health units managed by Instituto Saúde e Cidadania (Isac) across multiple Brazilian states. This action demonstrates ANPD's enforcement of data protection obligations for healthcare providers under Brazilian data protection law. Healthcare organizations operating across multiple states must ensure robust cybersecurity measures and incident response protocols to protect patient data.

What changed

  • ANPD initiated a formal sanctions process against the healthcare organization responsible for managing health units under Instituto Saúde e Cidadania (Isac) due to inadequate data protection measures that allowed a cyberattack to expose sensitive data of 500,000 patients across multiple Brazilian states.

Who is affected

Healthcare organizations and private entities managing public health units in Brazil

Summary generated by a language model; the official text prevails. Not legal advice.