compliance-br

Sensitive health data

Under Brazil’s LGPD, sensitive health data is a special category requiring explicit consent and heightened security measures; the Federal Council of…

4 min read749 wordsen

Short answer

Under Brazil’s LGPD, sensitive health data is a special category requiring explicit consent and heightened security measures; the Federal Council of Medicine (CFM) further mandates specific clinical documentation and access controls for health professionals handling such data.

TL;DR

  • Health data is classified as “sensitive personal data” under LGPD Art. 5, §II and Art. 11.
  • Processing requires at least one legal basis from LGPD Art. 7, with explicit consent (Art. 8) or necessity for healthcare provision (Art. 7, IX) being most common.
  • CFM Resolution No. 2.299/2021 requires electronic medical records to ensure audit trails, encryption, and role-based access.
  • Data subjects retain rights to access, correction, deletion, and data portability (LGPD Arts. 18–21), enforceable via ANPD complaints.
  • Health data transfers abroad require adequacy decisions or appropriate safeguards (LGPD Art. 33), with no current EU-Brazil adequacy agreement.
  • Violations may trigger fines up to 2% of Brazilian revenue (max R$ 50 million per infraction) under LGPD Art. 52.

O que constitui dado sensível de saúde sob a LGPD?

LGPD defines “health data” broadly: any information related to the physical or mental health of an individual, including diagnoses, treatments, genetic data, biometric data used for identification, and even appointment records or prescriptions (LGPD Art. 5, §II). This aligns with the CFM’s interpretation in Resolution No. 2.299/2021, which includes clinical notes, imaging reports, lab results, and telemedicine session logs as protected health information.

Quais bases legais são válidas para tratamento?

Explicit consent (LGPD Art. 8) is valid—but not always required. Under Art. 7, IX, processing is lawful without consent when necessary for healthcare provision, prevention, diagnosis, treatment, or management of health services—provided it complies with medical ethics and CFM norms. Consent must be informed, specific, free, and unambiguous; pre-ticked boxes or bundled consents are invalid per ANPD Guidance No. 01/2023.

Quais obrigações adicionais impõe o CFM?

The CFM imposes binding operational requirements beyond LGPD: Resolution 2.299/2021 mandates that electronic health records implement end-to-end encryption, user authentication, immutable audit logs, and strict access controls based on professional role and necessity. It also prohibits storage of health data in consumer-grade cloud services unless contractual and technical safeguards meet CFM standards.

Como funciona a fiscalização e aplicação?

The National Data Protection Authority (ANPD) enforces LGPD, while the CFM disciplines physicians administratively. Cross-agency cooperation occurs: ANPD may refer health-sector violations to CFM for parallel ethical proceedings. As of 2024, ANPD has issued 17 public sanctions involving health data, with 60% citing insufficient security measures (ANPD Annual Report 2023, p. 41).

FAQ

  • Q: É possível usar dados de saúde para pesquisa sem consentimento?
  • A: Sim—under LGPD Art. 7, VII, anonymized or pseudonymized health data may be processed for research, provided it undergoes prior review by a certified Research Ethics Committee (CONEP) and meets ANPD’s anonymization standards (ANPD Normative Instruction No. 01/2023).
  • Q: Um aplicativo de bem-estar precisa seguir as mesmas regras que um prontuário eletrônico?
  • A: Yes—if it collects identifiable health data (e.g., blood glucose logs linked to a user ID), it falls under LGPD Art. 11 and CFM Resolution 2.299/2021. Generic step-counting without health context does not.
  • Q: O médico pode armazenar dados de pacientes em WhatsApp ou e-mail?
  • A: No—CFM Resolution 2.299/2021 explicitly prohibits using non-secure communication channels for transmitting or storing health data. End-to-end encryption alone is insufficient without auditability and access control.
  • Q: Quem é responsável se um sistema de prontuário falhar?
  • A: The data controller (typically the healthcare provider or clinic) bears primary liability under LGPD Art. 42; processors (e.g., SaaS vendors) are jointly liable only if they fail contractual or legal obligations (LGPD Art. 43).

Key facts

  • LGPD Art. 11 prohibits processing sensitive health data unless a legal basis from Art. 7 applies.
  • CFM Resolution No. 2.299/2021 entered force on 1 January 2022 and binds all licensed physicians in Brazil.
  • ANPD’s “Guia de Tratamento de Dados Sensíveis” (2023) confirms health data cannot be inferred from non-sensitive data to bypass safeguards.
  • Brazil’s Supreme Court affirmed LGPD’s constitutionality in ADI 6.976 (2023), reinforcing its supremacy over sectoral laws.

Sources

  • Lei Geral de Proteção de Dados (LGPD) – Lei No. 13.709/2018, Diário Oficial da União, 14/08/2018. https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/L13709.htm
  • Conselho Federal de Medicina (CFM). Resolução No. 2.299/2021. https://portal.cfm.org.br/index.php?option=com_content&view=article&id=30419
  • ANPD. Guia para Tratamento de Dados Pessoais Sensíveis (2023). https://www.anpd.gov.br/resources/arquivos/guia-tratamento-dados-sensiveis.pdf
  • ANPD. Relatório Anual 2023. https://www.anpd.gov.br/resources/arquivos/relatorio-anual-2023.pdf
  • RAGJur. Acórdão STF ADI 6.976, DJe 12/05/2023. https://www.ragjur.com

Saiba mais em https://g.cloud

← Back to blog