In the world · Health · 8 July 2026
ANPD and 500,000 patients' data: what the LGPD requires
In July 2026, Brazil's ANPD opened sanction proceedings over an incident with health data of 500,000 patients. What the LGPD requires of record keepers.
bairogonzalez.com team, drawing on Bairo's story · Published
Health data is sensitive data, and whoever holds it is accountable for it. In July 2026, Brazil's National Data Protection Authority, the ANPD, opened administrative sanction proceedings against the Instituto Saúde e Cidadania (Isac), a social organization that manages public health facilities in several states, after an attack that affected about 500,000 patient records. The proceedings are ongoing, and the institute has the right to a defense.
What happened
According to the ANPD, the incident occurred in 2025 and was reported by Isac itself. It was a ransomware attack, in which data is hijacked and made inaccessible. The institute reported that about 500,000 records were affected, of which approximately 78,772 would belong to children and adolescents and 47,921 to older people. The records included identification data and health data: exam history, medical records, prescriptions, visits, hospitalizations, diagnoses and procedures.
The ANPD is investigating whether the General Data Protection Law (LGPD) was violated on four points: the lack of adequate security measures; insufficient communication to the people affected, since the institute limited itself to a notice on its website, without the date of the incident, the nature of the data or the measures taken; the absence of public information about the data protection officer; and failure to comply with the principles of prevention and accountability. Isac claimed that the attackers had accessed only administrative information and closed contracts, but, according to the agency, it provided no proof.
CNN Brasil reported the case on July 8, 2026. The institute had ten business days from the notice to present its defense. If it is found liable, the sanctions under Article 52 of the LGPD range from a warning to a fine of up to 2% of revenue, in addition to the suspension or prohibition of data processing.
Why it matters
The LGPD classifies health-related data as sensitive personal data, with stricter processing rules. The reason is simple: an exposed diagnosis can cost a job, credit, reputation and peace of mind. When the patient is a child or an older person, the vulnerability is greater.
The case also shows that the obligation does not end with the attack. The law requires that affected people be notified clearly, with what happened, which data were exposed and what was done. A generic notice on the website, according to the ANPD, is not enough. For those developing health technology, the lesson is that security and transparency are part of the product, not an appendix.
In Bairo's view
For Bairo Leandro Gonzalez Martinez, no gain in access makes up for a loss of trust. In his reading, people need to know who sees their data, for what purpose, where it is kept and how to withdraw consent. Without that, digital health cannot stand.
It is an idea that runs through the health ventures he founded. At Xperienc Global Labs, the clinical second opinion between countries only makes sense with an informed patient and private records in their dashboard. At Hospital Triage, the clinical assistant organizes the person's history for a professional who validates it, and every piece of data collected must have a clear purpose. Bairo sees access and protection as two halves of the same care.
He also recalls that exposure hurts. Those whose privacy has been revealed may need support, and the pages on pain, faith and reconnection include when to seek professional help.
Where this meets the ecosystem
qrqbits, another venture founded by Bairo, proposes protecting files, images, audio and text with layered post-quantum cryptography. In the Xperienc Global Labs proposal, clinical records stay private in the user's dashboard, with this layer of protection, and BTZ Chain serves as a record of authenticity. It is a proposal under development; each service's compliance with the LGPD depends on a legal assessment before it operates.
Sources
- ANPD, "ANPD instaura processo de sanção contra organização social por falha na proteção de dados de 500 mil pacientes de unidades públicas de saúde" (ANPD opens sanction proceedings against social organization over failure to protect data of 500,000 patients at public health facilities), Jul. 2026: gov.br/anpd
- CNN Brasil, "ANPD investiga ataque cibernético que vazou dados de 500 mil pacientes" (ANPD investigates cyberattack that leaked data of 500,000 patients), 7/8/2026: cnnbrasil.com.br
- Presidency of the Republic, Law 13,709/2018 (LGPD), Article 5, II, Article 11 and Article 52: planalto.gov.br
Read also
- AI triage in the emergency room: what the studies say
- WHO: the world will be short 11.1 million health workers
- Yellow September 2026: listening is being present
- Meu SUS Digital: mental health care through remote service
- Language barriers in the consultation: the unseen risk
- Grief in the pandemic: the risk to the heart, measured