Brazil’s SISVISA Health Surveillance System Exposes 79 GB of Sensitive Records
What Happened — The SISVISA platform unintentionally left 102,215 files (≈ 79 GB) publicly accessible on the internet. The files contain Brazilian tax identification numbers, identity documents, and other personal health‑surveillance data, and were not protected by any authentication mechanism.
Why It Matters for Compliance & Audit Readiness
- This is a textbook example of a control gap that SOC 2’s Confidentiality and Security criteria are designed to detect and remediate through documented access‑control policies and continuous evidence collection.
- Mapping the missing controls (e.g., “Restrict access to sensitive data” and “Encrypt data at rest”) to your SOC 2 audit framework provides the defensible trail auditors expect.
- Verisq’s Control Mapping capability can automatically align discovered misconfigurations with the relevant Trust Services Criteria, generating audit‑ready evidence.
Who Is Affected — Public‑health agencies, government health‑surveillance programs, and any downstream partners that consume SISVISA data (health‑care providers, research institutions).
Recommended Actions
- Conduct an immediate control‑gap assessment against SOC 2 Confidentiality and Security criteria (e.g., CC6.1, CC6.2).
- Remediate the misconfiguration: enforce authentication, encrypt data at rest, and implement strict IAM policies.
- Capture remediation steps in a continuous‑compliance platform to provide real‑time audit evidence. Source: HackRead
Technical Notes
- Attack vector: public‑internet exposure due to misconfiguration (no password protection).
- No CVE associated; the issue stems from inadequate configuration management.
- Data types: Brazilian CPF (tax ID), identity documents, health‑surveillance records. Source: HackRead