Brazilian government health surveillance platform exposed 79GB of sensitive data online
Recently, I discovered a publicly exposed database that was neither password-protected nor encrypted. The database contained 102,215 documents totaling approximately 79GB. In a limited sampling of the exposed files, I observed a wide range of sensitive information, including PII, identification records such as names and CPF/CNPJ numbers, contact details, physical addresses, licensing and permit applications, and supporting documentation related to health and sanitary compliance. Additional records included inspection reports, compliance documentation, complaints, two compressed backup files, and other materials associated with public health surveillance and regulatory enforcement.
Based on the name of the database and the information contained in the exposed files, the records appeared to belong to Brazil’s Health Surveillance Information System (Sistema de Informação da Vigilância Sanitária), known as SISVISA. Although the records appeared to be associated with SISVISA, it is not known whether the database was owned and managed directly by the organization or by a third-party contractor.
This government platform is used by health authorities to manage sanitary surveillance activities, including inspections of businesses such as restaurants, hospitals, and pharmacies, processing licenses and permits,and tracking compliance with public health regulations.
I immediately sent a responsible disclosure notice to multiple agencies, and public access was restricted shortly afterward and is no longer available. I did not receive any reply to my disclosure notice. This exposure is a wake-up call for agencies around the world that use digital platforms to provide services to citizens and businesses.
According to a report published in 2025, the SISVISA platform was developed primarily to address inefficiencies and limitations in public health surveillance management by leveraging information technology. Public organizations needed tools to streamline administrative processes, reduce costs, and improve overall efficiency. SISVISA was intended to support operations, management, analysis, and decision-making, expanding the organization’s strategic capabilities and creating better alignment between technology and public health objectives.
This screenshot shows an example of a federal doctor’s identity document that appeared in the publicly exposed database.
This screenshot shows a national driver’s license with PII.
This screenshot shows a business inspection report.
This screenshot shows a document with the face and fingerprint of an individual.
This screenshot shows how the exposed folders appeared in the database, indicating backups, documents, imports, and uploads.
There is a real need for government agencies to modernize the way they collect, store, and manage service-related documents. In the past, regulatory agencies relied heavily on paper-based processes, which made operations extremely slow. Documents had to be physically submitted, reviewed, stored, and transported between departments, creating bottlenecks and long processing times for approvals such as licenses and inspections.
Switching to a digital system makes submissions, applications, and tracking faster and more efficient by eliminating paperwork and reducing delays. It improves transparency and accountability, allowing users and agencies to monitor progress in real time, and can reduce errors. While going digital brings major efficiency and transparency benefits, it also introduces a wide range of new risks that did not exist in physical paper-based systems. Sensitive data stored and transmitted online can become vulnerable to data breaches, unauthorized access, or cyberattacks if proper security measures are not implemented.
Most government agencies around the world moved to digital platforms years ago, but many are still in the process of transitioning to digital systems. This is why it is very important to build apps and platforms with security in mind. In this case, there are numerous potential risks associated with exposing documents and files that contain PII and may not be intended to be public. These potential threats can range from simple fraud to targeted phishing attempts or even identity theft.
Additionally, the platform or database itself could be targeted by malicious code or ransomware. For example, files could be downloaded, embedded with malicious scripts, and re-uploaded, putting anyone who opens them at risk. Ransomware, on the other hand, could encrypt and lock those files. I am not claiming that the SISVISA or its users are at risk of these types of threats; I am only highlighting the real-world threats associated with exposing these documents or database misconfigurations.
This publicly available image shows how the SISVISA platform operates.
Duarte, T. (2015, Jan 10). SISVISA Work Breakdown Structure. Retrieved May 15, 2026, from https://www.revistaespacios.com/a16v37n02/16370207.html
When government agencies or organizations transition from paper-based processes to digital platforms, the first priority should be building security into system processes. My advice would be to implement role-based access controls and multi-factor authentication (MFA) on internal systems and any data storage repositories. Documents that contain PII or other sensitive data should be encrypted. It is also necessary to conduct regular security audits, vulnerability assessments, and patch management. Testing, auditing, and patching can identify known threats or other issues before they can be exploited.
In addition to data security, it is important to establish data governance and protection policies. This can include limiting who can access what data, how long data is retained, and how to minimize unnecessary risks.
For citizens who believe or suspect that their data may have been exposed in a breach, I recommend taking a proactive approach. Monitor credit reports regularly using official credit bureaus available in your country to check for unfamiliar accounts, credit inquiries, or new accounts being opened. Be aware of how phishing attempts work and their basic signs. Criminals often use breached data to identify potential victims through methods such as sending realistic emails or making calls using real account numbers.
It is also a common tactic to ask for additional personal information or financial details, so citizens should verify any request through official channels before providing their information. Strengthen security by changing passwords for affected apps or services and enable MFA if available. Being aware of the methods and tactics criminals use can significantly reduce the impact of identity theft or financial fraud.
I am not implying that users of the SISVISA platform are at risk; I only recommend general awareness and best practices to help mitigate potential risks.
As an ethical security researcher, I do not download the data I find, bypass authentication mechanisms, or attempt to exploit vulnerabilities beyond identifying their existence for notification purposes. However, it is important to note that if such a database were discovered by individuals with malicious intent, the potential impact could be significant. It is not known how long the database was publicly accessible before its discovery or whether it may have been accessed by unauthorized parties. Only a detailed internal forensic investigation could determine the full scope of the exposure or any potential misuse.
I imply no wrongdoing by any specific organization or government entity, and I do not claim that any data was definitively accessed or misused. The scenarios outlined in this report are hypothetical and provided strictly for educational purposes to highlight potential risks. As an ethical researcher, I do not download or retain exposed data. I only review a limited sample of records to verify the nature of the exposure and report it responsibly.
My goal in publishing findings like these is to raise awareness about the importance of data security and encourage organizations to take proactive steps to safeguard sensitive information, networks, and systems.