Hospitals, clinics, laboratories, health plan operators, and healthtechs work with data the LGPD classifies as sensitive and with systems that cannot go down. We help the sector prevent, detect, and respond to attacks and demonstrate compliance.
Digitization brought electronic medical records, integrated diagnostics, and network-connected equipment. Each advance expanded the attack surface, and attackers know a healthcare institution has little room to stay offline.
LGPD. Health data is sensitive personal data (art. 5, II) and may only be processed in the cases set out in art. 11, such as health protection by health professionals and services. Art. 11 also restricts sharing such data for economic gain and prohibits health insurance operators from using health data for risk selection. Art. 46 requires processing agents to adopt technical and administrative security measures against unauthorized access and incidents.
Lei 13.787/2018. The digitization of medical records must ensure integrity, authenticity, and confidentiality, using an ICP-Brasil digital certificate or another legally accepted standard. Storage media must protect documents against unauthorized access, use, alteration, reproduction, and destruction, and the minimum retention period is 20 years from the last entry.
Resolution CD/ANPD No. 15/2024. Incidents that may pose a relevant risk or harm must be reported to the ANPD and to data subjects within three business days of learning that the incident affected personal data. Sensitive data is among the relevance criteria, and every incident, reported or not, must be recorded and kept for at least five years. Learn how the ANPD calculates sanctions.
Continuous monitoring and threat response, including outside business hours, when on-call shifts and emergency rooms keep running.
Containment, investigation, and recovery after an attack, including gathering the information the ANPD notification requires.
Traffic behavior analysis to reveal lateral movement and suspicious communications, including in segments where no agent is installed.
Privileged access control, multi-factor authentication, and credential management for clinicians, administrators, and vendors.
Identification and prioritization of flaws in clinical systems, servers, and exposed applications, with remediation tracking.
Mapping of health data processing, policies, third-party assessment, and organization of evidence for audits and the ANPD.
In healthcare, the question is not just whether data was exposed, but how long the hospital can operate without its systems. Isolated and tested backups, segmentation between the administrative network and the medical equipment network, contingency plans for medical records and diagnostics, and a response plan rehearsed with clinical teams reduce the impact of ransomware.
Penetration testing and Red and Purple Team exercises show how an attacker would reach critical systems before they do. Read how to prepare your company against ransomware and the role of backup in resilience.
Yes. Art. 5, II, of the LGPD expressly includes health data among sensitive personal data, which may only be processed in the cases set out in art. 11. An incident involving this type of data tends to be assessed more strictly by the ANPD.
Under Resolution CD/ANPD No. 15/2024, within three business days of learning that the incident affected personal data, when there is relevant risk or harm to data subjects. Incidents involving sensitive data meet one of the regulation's criteria. Data subjects must also be notified within the same period.
That digitization ensure integrity, authenticity and confidentiality, using an ICP-Brasil digital certificate or another legally accepted standard, and that storage media protect documents against unauthorized access, use, alteration, reproduction and destruction. The minimum retention period is 20 years from the last entry.
It depends on the assessment of the case. The ANPD regulation considers, among other situations, incidents that may prevent the use of a service. When an attack makes patient data unavailable, a risk analysis must be carried out and documented, and the incident record must be kept for at least five years, even if it is not reported.
Talk to a specialist and see where the gaps are between the LGPD, Lei 13.787, and your institution's controls.