Pular para o conteúdo principal
Close
Security

ANPD Infringement Notice: 500 Thousand Records, Ransomware, and the ISAC Case That Redefined Healthcare Data Enforcement

Gabriel Ferraresi· CEO | Tech86July 19, 20265 min
securitylgpdanpdransomwareisachealthcaredpoincident-responsebackupprivacy

The infringement notice opens with a sentence that changes the tone of data enforcement in Brazil. According to the ANPD infringement notice, there are "indications of minimizing the gravity of the incident." The Administrative Sanctioning Proceeding was instituted on July 8, 2026 against ISAC, Instituto Saúde e Cidadania, for a ransomware attack in January 2025 that affected approximately 500 thousand records — including 78,772 children and adolescents and 47,921 elderly. We have followed the case and the signal is clear: the ANPD has stopped being a warning body and started demanding technical evidence, a formal DPO, and real communication to data subjects.

The scale of the incident and the defendant's profile

According to the ANPD infringement notice, ISAC is a private non-profit social organization headquartered in Brasília that operates in 6 states: Goiás, Rio Grande do Sul, Bahia, Alagoas, Piauí, and Tocantins. The incident occurred in January 2025 and affected approximately 500 thousand records, reported by ISAC to the ANPD. The data scope is broad: name, date of birth, medical records, exams, prescriptions, consultations, and diagnoses — all sensitive data under the LGPD.

According to the infringement notice, the attackers accessed the cloud backups. ISAC did not pay the ransom and reported to the ANPD spontaneously in 2025. But what looked like a transparency posture became, according to the ANPD, a case of "serious failures in the protection of personal and sensitive data." The difference between reporting and proving is what separates a valid defense from an aggravating factor.

The LGPD articles cited and the literal quotations from the notice

According to the ANPD infringement notice, the cited articles are: Art. 46 (security), Art. 48 (incident communication), Art. 41 (DPO), and Art. 6º, items IV and VI (prevention and accountability). The literal quotations from the notice are harsh:

  • "there are indications of minimizing the gravity of the incident"
  • "serious failures in the protection of personal and sensitive data"
  • "insufficient communication to data subjects"
  • "absence of evidence regarding the adoption of corrective measures, despite repeated requests to prove them"

Each of these sentences points to a concrete operational failure: without formal IR, without a formal DPO, and without a communication plan to data subjects, the organization accumulates violations that the ANPD treats as aggravating — not mitigating — factors.

ISAC's defense thesis and why it failed

According to ISAC's defense, the organization denies data leak and exfiltration. It claims "temporary unavailability." It maintains that the attackers accessed "only administrative information and databases related to already-terminated contracts." The problem is that, according to the infringement notice, no technical proof was provided after repeated questioning.

Here is the central lesson for any DPO: a claim without evidence is not a defense. Without a formal incident response report, with chain-of-custody preservation, forensic logs, and exfiltration analysis, the ANPD treats the narrative as speculative. The prevention principle, cited by Fabrício Guimarães, superintendent of Enforcement at ANPD, is explicit: "In a logic of the prevention principle, I have to estimate the worst and prepare for the worst." In other words, the burden of technical proof falls on the controller.

The legal cap and the Telekall precedent

Under Art. 52 of the LGPD, the fine can reach 2% of the private legal entity's revenue, capped at 50 million reais per infraction. Other sanctions include warning, publication of the infraction, blocking or deletion of data, and partial suspension of operations for up to 6 months, per Resolução CD/ANPD nº 4/2023. ISAC's defense deadline is 10 business days. No fine has been applied so far — the proceeding is ongoing.

The precedent matters. The ANPD's first pecuniary fine was applied to Telekall in July 2023, in the amount of 14,400 reais. The ISAC case is a PAS of unprecedented scale against a private public-health organization. As a private legal entity, ISAC can receive a pecuniary fine, unlike public agencies. According to the ANPD, reported by Estadão, Folha, Valor, O Globo, G1, and CNN Brasil, the case redefined the standard for healthcare data enforcement in Brazil.

What Tech86 implements

We repeat: reporting to the ANPD is not enough. You have to prove. What Tech86 implements for healthcare and critical infrastructure clients:

  1. 24/7 SOC with MDR — the dwell time of a breach becomes detection in hours, not months. The ISAC incident occurred in January 2025 and the PAS was only instituted in July 2026 — an 18-month gap.
  2. Immutable and offline backup — cloud backups with the same credential are the second target of ransomware. The ISAC attackers accessed the cloud backups directly.
  3. Incident response with evidence preservation — without formal IR, there is no report for the ANPD. ISAC's defense failed because it provided no technical proof after repeated questioning.
  4. Incident communication to the ANPD within 3 business days, per Resolução CD/ANPD nº 15/2024 — a technical report with grounding, without speculative narrative.
  5. LGPD compliance with a formal DPO and a communication plan to data subjects — Art. 41 and Art. 48 charged in the notice are exactly the points where "insufficient communication to data subjects" was cited as a failure.

Conclusion: the burden of technical proof falls on the controller

The ISAC case is not just a ransomware incident — it is, primarily, an LGPD enforcement case about incident response failures. The ANPD is not judging the attack; it is judging the response. According to the infringement notice, "absence of evidence regarding the adoption of corrective measures" is what turns an incident into a sanction. We help organizations build exactly what was missing: a 24/7 SOC, immutable backup, IR with evidence, communication within 3 business days, and a formal DPO. Before the PAS — not after.

Need expert guidance?

Schedule a consultation with our specialists.

LGPD Compliance and Incident Response

Frequently Asked Questions

According to the ANPD infringement notice, the Administrative Sanctioning Proceeding was instituted on July 8, 2026 against ISAC, Instituto Saúde e Cidadania, a private non-profit social organization headquartered in Brasília that operates in 6 states (Goiás, Rio Grande do Sul, Bahia, Alagoas, Piauí, and Tocantins). The case involves a ransomware attack in January 2025 affecting approximately 500 thousand records — 78,772 children and adolescents and 47,921 elderly. It is unprecedented in scale and because it targets a private public-health organization, which, as a private legal entity, can receive a pecuniary fine, unlike public agencies.

According to the ANPD infringement notice, the cited articles were: Art. 46 (security), Art. 48 (incident communication), Art. 41 (DPO), and Art. 6º, items IV and VI (prevention and accountability). The notice points to serious failures in the protection of personal and sensitive data and absence of evidence regarding the adoption of corrective measures, despite repeated requests to prove them.

Under Art. 52 of the LGPD, the fine can reach 2% of the private legal entity's revenue, capped at 50 million reais per infraction. Other sanctions include warning, publication of the infraction, blocking or deletion of data, and partial suspension of operations for up to 6 months, per Resolução CD/ANPD nº 4/2023. The ANPD's first pecuniary fine was applied to Telekall in July 2023, in the amount of 14,400 reais.

According to ISAC's defense, the organization denies data leak and exfiltration, claims temporary unavailability, and maintains that attackers accessed only administrative information and databases related to already-terminated contracts. The problem, according to the infringement notice, is that no technical proof was provided after repeated questioning. The notice cites indications of minimizing the gravity of the incident and absence of evidence regarding the adoption of corrective measures. Without a formal IR report, there is no technical defense.

Per Resolução CD/ANPD nº 15/2024, the security incident communication must be made within 3 business days. The report must be technical and grounded, without speculative narrative. In the ISAC case, the communication was spontaneous in 2025, but the notice points to insufficient communication to data subjects as one of the failures — in other words, reporting to the ANPD is not enough if the data subjects are not properly informed.

Blog — Get in Touch

Have a question about our articles or services? Our team is ready to help.

Schedule a Meeting

Book a time slot.

Schedule Now

Email

Send us a message.

[email protected]

WhatsApp

Quick conversation.

Address

Avenida Paulista, 1636 - São Paulo - SP - 01310-200

Tech86 Specialist

Online now

Hello! How can we help scale your business today?

Tech86 Engineering

We Value Your Privacy

We use cookies and similar technologies to optimize your experience, analyze site traffic, and personalize content. By clicking "Accept All", you agree to the use of all cookies. Read our Privacy Policy.