Patient data protection in Mexico: LFPDPPP, INAI, and NOM-024 compliance guide for dental imaging centers
A dental imaging center in Mexico handles sensitive personal data every day. The Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), in force since July 2010, protects it with one of the strongest frameworks in Latin America. The National Institute for Transparency, Access to Information and Personal Data Protection (INAI) is the supervisory authority and may impose fines up to 320,000 UMA days, doubled when sensitive data is involved.
This article explains what the LFPDPPP requires, how it interlocks with NOM-024-SSA3-2012 on clinical information systems and NOM-004-SSA3-2012 on the clinical file, and how CBCTHub satisfies each technical safeguard so your imaging center can operate with confidence.
LFPDPPP in plain English
The LFPDPPP entered into force on July 6, 2010 and applies to private individuals and entities that process personal data. Its 2011 Regulation details technical obligations. The 2013 Privacy Notice Guidelines set out the minimum content of the notice to the data subject.
Regulatory framework for a Mexican dental clinic
- LFPDPPP (2010): federal law applicable to private parties.
- LFPDPPP Regulation (2011): details principles and duties.
- Privacy Notice Guidelines (2013): mandatory notice content.
- General Law on Protection of Personal Data Held by Obligated Parties (2017): applies to IMSS, ISSSTE, and public hospitals.
- NOM-024-SSA3-2012: electronic health record systems, security and confidentiality.
- NOM-004-SSA3-2012: clinical file, minimum content and retention.
- General Health Law: medical professional secrecy.
Sensitive personal data under the LFPDPPP
Article 3 fraction VI defines sensitive personal data as anything affecting the most intimate sphere of the data subject or whose improper use may give rise to discrimination. It expressly includes racial origin, present and future health status, genetic information, religious beliefs, and sexual life. A CBCT scan is sensitive data.
What the law specifically requires about patient data
Mandatory Privacy Notice
Every clinic must deliver a Privacy Notice to the patient before collecting their data. The Notice must include: identity and address of the controller, processing purposes, options to limit use, channels to exercise ARCO rights, expected transfers, and a mechanism for changes to the Notice. There are three modalities: integral, simplified, and short. The integral one must be available on the website or at reception.
Express consent for sensitive data
LFPDPPP Article 9 requires express written consent to process sensitive data. Advanced electronic signature or handwritten signature on paper meet the requirement.
ARCO rights (Access, Rectification, Cancellation, Opposition)
The data subject may exercise rights at any time. The controller has 20 business days to respond and 15 additional days to give effect to the request. A designated department or person must handle ARCO requests.
LFPDPPP principles
Lawfulness, consent, information, quality, purpose, fairness, proportionality, accountability. Every processing must meet all eight.
Security measures
Article 19 requires administrative, physical, and technical safeguards. The Regulation details the security management system. NOM-024 adds specific technical requirements for electronic clinical records.
Breach notification
Article 64 of the Regulation requires informing the data subject without delay when a breach occurs. There is no fixed clock like GDPR, but INAI case law has applied the immediacy principle.
International transfers
Cross-border data transfers require subject consent or fall under Article 37 exceptions. It is best practice to include protection clauses in contracts with foreign cloud providers.
Processor
Any vendor processing data on the controller''s behalf is a processor. It must sign a contract meeting Article 50 of the Regulation.
Retention (NOM-004)
NOM-004-SSA3-2012 sets that the clinical file must be retained at least five years from the last medical act, including imaging exams.
INAI penalties
- From 100 to 160,000 UMA per minor or serious infraction. In 2026, the UMA is around MXN 113, so the range goes from roughly MXN 11,300 to MXN 18 million.
- From 200 to 320,000 UMA for reinforced obligations (up to roughly MXN 36 million).
- Fines DOUBLE when sensitive data is involved under LFPDPPP Article 64.
- Custodial sentences of 3 months to 3 years for improper use and 6 months to 5 years for willful processing (Articles 67 and 68).
Concrete risks for a Mexican dental imaging center
Not displaying a Privacy Notice is one of the most common infractions INAI detects. Sending unencrypted scans by WhatsApp, missing the ARCO response deadline, or using a foreign cloud provider without an adequate contract are documented infractions. In 2023, INAI fined several healthcare institutions several million pesos for unnotified breaches.
How CBCTHub helps you comply with LFPDPPP and NOM-024
Privacy Notice template for Mexico
CBCTHub ships integral and simplified Privacy Notice templates adapted to LFPDPPP. You only personalize your clinic''s data.
Express written consent
CBCTHub''s informed-consent module generates the document per Article 9, sends it to the patient, and captures a verifiable electronic signature. Meets the express-consent requirement for sensitive data.
Encryption in transit and at rest
TLS 1.3 and AES-256 meet the technical measures required by Article 19 of LFPDPPP and NOM-024 security sections.
Audit log for ARCO rights
Every access and modification is logged. When a patient exercises ARCO, you export the log for the corresponding record from the clinic dashboard.
Documented ARCO procedure
CBCTHub lets you respond to access (data export), rectification (record edit), cancellation (deletion), and opposition (closure) requests in minutes, within the 20 business day clock.
Secure deletion for the cancellation right
DELETE /api/v1/exams/{id} removes the exam and all DICOMs in R2 irreversibly. Fulfills the cancellation right under LFPDPPP Article 25.
Portability via export-data
The endpoint /api/account/export-data returns the data in structured JSON for portability or audit.
Processor contract
CBCTHub signs a processor contract meeting LFPDPPP Regulation Article 50. Available at /privacidad.
Multi-tenant RLS on Supabase
Strict isolation between clinics. Honors the accountability principle of LFPDPPP Article 6.
Breach notification
If we detect a breach affecting your data, we notify you without delay so you can comply with Regulation Article 64.
LFPDPPP compliance checklist for your center
- Designate a Personal Data Department or responsible person.
- Publish integral Privacy Notice on website and simplified at reception.
- Express-consent template for sensitive data.
- Documented ARCO response procedure (20-day clock).
- Documented security management system.
- Contract with CBCTHub and every processor.
- Retention policy of at least 5 years per NOM-004.
- Comply with NOM-024 technical requirements if using electronic records.
- Annual staff training.
- Security incident log.
FAQ
Can I send scans via WhatsApp?
Not securely. WhatsApp does not guarantee the technical measures required by LFPDPPP Article 19 for sensitive data. Use a secure CBCTHub link that provides encryption, access control, and traceability.
How long must I retain the clinical file?
NOM-004-SSA3-2012 sets a minimum of 5 years from the last medical act. Many implant clinics keep records for the lifetime of the implant.
What happens if I lose the backup with sensitive data?
You must notify the data subject without delay under Regulation Article 64. The fine for failing security measures may double because sensitive data is involved.
Do I need to sign anything with CBCTHub?
Yes. Regulation Article 50 requires a processor contract. CBCTHub provides one at /privacidad.
Official resources
Download the CBCTHub processor contract | Solution for Mexican imaging centers | Plans and pricing
This article is informational and does not constitute legal advice. Consult with a Mexican data protection lawyer for your specific case.
Try CBCTHub for free
Upload, view, and share DICOM scans in the cloud. Nothing to install.
Create free accountRelated articles
Patient data protection in Spain: LOPDGDD 3/2018 and GDPR compliance for dental imaging centers
How a dental imaging center complies with Spain's LOPDGDD 3/2018, EU GDPR, and Law 41/2002 on clinical records. Obligations, penalties up to EUR 20M, and how CBCTHub helps.
Patient data protection in the USA: HIPAA and HITECH compliance guide for dental imaging centers
How to comply with HIPAA (Public Law 104-191), Privacy Rule, Security Rule, and HITECH Act in a dental imaging clinic. PHI, BAA, OCR fines up to USD 1.5M per year.
Patient data protection in Chile: Law 19.628 and the new Law 21.719 for dental imaging centers
Complete guide to Chile's current Law 19.628, the new Law 21.719 effective December 2026, and Law 20.584 on patient rights. How CBCTHub helps you comply today and tomorrow.