CBCTHubCBCTHub
PricingBlogHelp
 
 
Back to blog
data-protectioncompliancemexicolfpdpppnom-024healthcare-dental

Patient data protection in Mexico: LFPDPPP, INAI, and NOM-024 compliance guide for dental imaging centers

CBCTHub·June 28, 2026
Patient data protection in Mexico: LFPDPPP, INAI, and NOM-024 compliance guide for dental imaging centers

A dental imaging center in Mexico handles sensitive personal data every day. The Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), in force since July 2010, protects it with one of the strongest frameworks in Latin America. The National Institute for Transparency, Access to Information and Personal Data Protection (INAI) is the supervisory authority and may impose fines up to 320,000 UMA days, doubled when sensitive data is involved.

This article explains what the LFPDPPP requires, how it interlocks with NOM-024-SSA3-2012 on clinical information systems and NOM-004-SSA3-2012 on the clinical file, and how CBCTHub satisfies each technical safeguard so your imaging center can operate with confidence.

LFPDPPP in plain English

The LFPDPPP entered into force on July 6, 2010 and applies to private individuals and entities that process personal data. Its 2011 Regulation details technical obligations. The 2013 Privacy Notice Guidelines set out the minimum content of the notice to the data subject.

Regulatory framework for a Mexican dental clinic

  • LFPDPPP (2010): federal law applicable to private parties.
  • LFPDPPP Regulation (2011): details principles and duties.
  • Privacy Notice Guidelines (2013): mandatory notice content.
  • General Law on Protection of Personal Data Held by Obligated Parties (2017): applies to IMSS, ISSSTE, and public hospitals.
  • NOM-024-SSA3-2012: electronic health record systems, security and confidentiality.
  • NOM-004-SSA3-2012: clinical file, minimum content and retention.
  • General Health Law: medical professional secrecy.

Sensitive personal data under the LFPDPPP

Article 3 fraction VI defines sensitive personal data as anything affecting the most intimate sphere of the data subject or whose improper use may give rise to discrimination. It expressly includes racial origin, present and future health status, genetic information, religious beliefs, and sexual life. A CBCT scan is sensitive data.

What the law specifically requires about patient data

Mandatory Privacy Notice

Every clinic must deliver a Privacy Notice to the patient before collecting their data. The Notice must include: identity and address of the controller, processing purposes, options to limit use, channels to exercise ARCO rights, expected transfers, and a mechanism for changes to the Notice. There are three modalities: integral, simplified, and short. The integral one must be available on the website or at reception.

Express consent for sensitive data

LFPDPPP Article 9 requires express written consent to process sensitive data. Advanced electronic signature or handwritten signature on paper meet the requirement.

ARCO rights (Access, Rectification, Cancellation, Opposition)

The data subject may exercise rights at any time. The controller has 20 business days to respond and 15 additional days to give effect to the request. A designated department or person must handle ARCO requests.

LFPDPPP principles

Lawfulness, consent, information, quality, purpose, fairness, proportionality, accountability. Every processing must meet all eight.

Security measures

Article 19 requires administrative, physical, and technical safeguards. The Regulation details the security management system. NOM-024 adds specific technical requirements for electronic clinical records.

Breach notification

Article 64 of the Regulation requires informing the data subject without delay when a breach occurs. There is no fixed clock like GDPR, but INAI case law has applied the immediacy principle.

International transfers

Cross-border data transfers require subject consent or fall under Article 37 exceptions. It is best practice to include protection clauses in contracts with foreign cloud providers.

Processor

Any vendor processing data on the controller''s behalf is a processor. It must sign a contract meeting Article 50 of the Regulation.

Retention (NOM-004)

NOM-004-SSA3-2012 sets that the clinical file must be retained at least five years from the last medical act, including imaging exams.

INAI penalties

  • From 100 to 160,000 UMA per minor or serious infraction. In 2026, the UMA is around MXN 113, so the range goes from roughly MXN 11,300 to MXN 18 million.
  • From 200 to 320,000 UMA for reinforced obligations (up to roughly MXN 36 million).
  • Fines DOUBLE when sensitive data is involved under LFPDPPP Article 64.
  • Custodial sentences of 3 months to 3 years for improper use and 6 months to 5 years for willful processing (Articles 67 and 68).

Concrete risks for a Mexican dental imaging center

Not displaying a Privacy Notice is one of the most common infractions INAI detects. Sending unencrypted scans by WhatsApp, missing the ARCO response deadline, or using a foreign cloud provider without an adequate contract are documented infractions. In 2023, INAI fined several healthcare institutions several million pesos for unnotified breaches.

How CBCTHub helps you comply with LFPDPPP and NOM-024

Privacy Notice template for Mexico

CBCTHub ships integral and simplified Privacy Notice templates adapted to LFPDPPP. You only personalize your clinic''s data.

Express written consent

CBCTHub''s informed-consent module generates the document per Article 9, sends it to the patient, and captures a verifiable electronic signature. Meets the express-consent requirement for sensitive data.

Encryption in transit and at rest

TLS 1.3 and AES-256 meet the technical measures required by Article 19 of LFPDPPP and NOM-024 security sections.

Audit log for ARCO rights

Every access and modification is logged. When a patient exercises ARCO, you export the log for the corresponding record from the clinic dashboard.

Documented ARCO procedure

CBCTHub lets you respond to access (data export), rectification (record edit), cancellation (deletion), and opposition (closure) requests in minutes, within the 20 business day clock.

Secure deletion for the cancellation right

DELETE /api/v1/exams/{id} removes the exam and all DICOMs in R2 irreversibly. Fulfills the cancellation right under LFPDPPP Article 25.

Portability via export-data

The endpoint /api/account/export-data returns the data in structured JSON for portability or audit.

Processor contract

CBCTHub signs a processor contract meeting LFPDPPP Regulation Article 50. Available at /privacidad.

Multi-tenant RLS on Supabase

Strict isolation between clinics. Honors the accountability principle of LFPDPPP Article 6.

Breach notification

If we detect a breach affecting your data, we notify you without delay so you can comply with Regulation Article 64.

LFPDPPP compliance checklist for your center

  • Designate a Personal Data Department or responsible person.
  • Publish integral Privacy Notice on website and simplified at reception.
  • Express-consent template for sensitive data.
  • Documented ARCO response procedure (20-day clock).
  • Documented security management system.
  • Contract with CBCTHub and every processor.
  • Retention policy of at least 5 years per NOM-004.
  • Comply with NOM-024 technical requirements if using electronic records.
  • Annual staff training.
  • Security incident log.

FAQ

Can I send scans via WhatsApp?

Not securely. WhatsApp does not guarantee the technical measures required by LFPDPPP Article 19 for sensitive data. Use a secure CBCTHub link that provides encryption, access control, and traceability.

How long must I retain the clinical file?

NOM-004-SSA3-2012 sets a minimum of 5 years from the last medical act. Many implant clinics keep records for the lifetime of the implant.

What happens if I lose the backup with sensitive data?

You must notify the data subject without delay under Regulation Article 64. The fine for failing security measures may double because sensitive data is involved.

Do I need to sign anything with CBCTHub?

Yes. Regulation Article 50 requires a processor contract. CBCTHub provides one at /privacidad.

Official resources

  • INAI
  • LFPDPPP (Chamber of Deputies PDF)
  • NOM-024-SSA3-2012
  • NOM-004-SSA3-2012

Download the CBCTHub processor contract | Solution for Mexican imaging centers | Plans and pricing

This article is informational and does not constitute legal advice. Consult with a Mexican data protection lawyer for your specific case.

Try free viewerSee solutions

Try CBCTHub for free

Upload, view, and share DICOM scans in the cloud. Nothing to install.

Create free account

Related articles

Patient data protection in Spain: LOPDGDD 3/2018 and GDPR compliance for dental imaging centers

Patient data protection in Spain: LOPDGDD 3/2018 and GDPR compliance for dental imaging centers

How a dental imaging center complies with Spain's LOPDGDD 3/2018, EU GDPR, and Law 41/2002 on clinical records. Obligations, penalties up to EUR 20M, and how CBCTHub helps.

Patient data protection in the USA: HIPAA and HITECH compliance guide for dental imaging centers

Patient data protection in the USA: HIPAA and HITECH compliance guide for dental imaging centers

How to comply with HIPAA (Public Law 104-191), Privacy Rule, Security Rule, and HITECH Act in a dental imaging clinic. PHI, BAA, OCR fines up to USD 1.5M per year.

Patient data protection in Chile: Law 19.628 and the new Law 21.719 for dental imaging centers

Patient data protection in Chile: Law 19.628 and the new Law 21.719 for dental imaging centers

Complete guide to Chile's current Law 19.628, the new Law 21.719 effective December 2026, and Law 20.584 on patient rights. How CBCTHub helps you comply today and tomorrow.

CBCTHubCBCTHub

Digital CBCT delivery. 100% local processing. No CDs, ever.

Download on theApp Store
Get it onGoogle Play

Solutions

Imaging centersDental radiologistsOnline CBCT viewer

Product

FeaturesPricingBlogAlternativesLearnEducationNewDevelopersAPIDemo

Support

Help centerFAQContactsoporte@cbcthub.comStatus+56 9 7632 9096

Company

AboutSecurityTerms of servicePrivacy policy

By country

United StatesUnited KingdomCanadaAustralia
HIPAA-readyGDPRLGPDLey 21.719

© 2026 CBCTHub. All rights reserved.

AppLab Software LLC · 1021 E Lincolnway, Cheyenne, WY 82001