Health Data Privacy & Compliance

Your health information security is our highest priority. Learn about our comprehensive data privacy compliance program and how we protect your personal health information across all AyudaMedico services.

Last Updated: August 10, 2026

LFPDPPP Compliant

Full compliance with Mexican Federal Data Protection Law

COFEPRIS

Federal health risk protection compliance

INAI Registered

Registered with Mexico's national data protection authority

ISO 27001

International information security management standard

Notice of Privacy Practices (Aviso de Privacidad)

This Notice of Privacy Practices describes how AyudaMedico may use and disclose your personal health information to carry out treatment, payment, or healthcare operations, and for other purposes permitted or required by Mexican law. It also describes your rights regarding your health information under the LFPDPPP (Ley Federal de Protección de Datos Personales en Posesión de los Particulares).

We are required by law to maintain the privacy and security of your personal health data, provide you with this notice of our legal duties and privacy practices, follow the terms of the notice currently in effect, and notify you if we are unable to accommodate a requested restriction.

Important: This notice is effective as of August 10, 2026 and applies to all personal health information maintained by AyudaMedico. Please read this entire notice carefully and contact us if you have any questions. This notice is governed by the laws of the United Mexican States (Estados Unidos Mexicanos).

1. Our Commitment to Health Data Privacy

AyudaMedico is fully committed to protecting the privacy and security of your personal health information in compliance with the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) of Mexico, and applicable international best practices for healthcare data security.

1.1 Platform Overview

AyudaMedico is a Mexican digital health platform that connects patients with cancer screening services, laboratory tests, telemedicine consultations, and insurance coordination. Our platform serves multiple stakeholders including:

  • Patients seeking cancer screenings, lab tests, and medical consultations
  • Licensed physicians and specialist doctors providing telemedicine and in-person consultations
  • Certified diagnostic laboratories offering a wide range of clinical tests
  • Insurance partners coordinating health coverage and claims
  • Agents and managers facilitating service delivery and patient support
  • Representatives promoting doctors and booking patient appointments on their behalf

1.2 Scope of Protected Information

We protect all personally identifiable health information, including:

  • Laboratory test results and diagnostic reports
  • Medical histories and cancer risk assessment data
  • Treatment plans and physician consultation records
  • Billing, insurance, and payment information
  • Any information that could be used to identify you as a patient or platform user

2. Privacy Rule Compliance (LFPDPPP & ARCO Rights)

2.1 Permitted Uses and Disclosures

We use and disclose your personal health information only for the following purposes without additional authorization:

  • Treatment: Coordinating and managing your healthcare services, lab tests, and consultations
  • Payment: Processing billing, insurance claims, and subscription payments
  • Platform Operations: Quality improvement, training, accreditation, and business management
  • Legal Compliance: Fulfilling obligations under Mexican law, INAI directives, and regulatory requirements

2.2 Uses Requiring Authorization

We will obtain your written authorization before using or disclosing your data for:

  • Marketing communications not directly related to your treatment or services
  • Transfer or sale of personal data to third parties outside the platform
  • Any purpose not covered by the permitted uses above

2.3 Minimum Necessary Standard

We adhere to the "minimum necessary" principle — we only use, disclose, or request the minimum amount of personal health information necessary to accomplish the intended purpose, except when:

  • Disclosing to healthcare providers (doctors, labs) for treatment
  • Disclosing to you (the individual) upon your request
  • Required by Mexican law or applicable regulations

2.4 Your ARCO Rights

Under the LFPDPPP, you have the following ARCO rights regarding your personal data:

  • Access: Request access to your personal data held by AyudaMedico
  • Rectification: Request correction of inaccurate or incomplete data
  • Cancellation: Request deletion of your data when no longer necessary
  • Opposition: Object to the use of your data for specific purposes

3. Artificial Intelligence (AI) Processing & Health Data

AyudaMedico uses artificial intelligence (AI) technologies to enhance the quality and efficiency of healthcare services. This section describes how AI processes your personal health information and the safeguards we apply.

3.1 AI-Powered Features

Our platform uses AI to provide the following health-related features:

  • AI Treatment Summaries: Generating structured summaries of patient diagnoses, prescriptions, and treatment plans
  • Insurance Form Autofill: Automatically extracting and populating insurance claim forms from uploaded documents
  • Insurance Layout Detection: Analyzing insurance document formats to identify field mappings
  • Medical Test Page Generation: Creating informational content for laboratory tests and cancer screening services
  • AI Chat Assistant: Providing general health information and platform navigation support

3.2 Third-Party AI Provider — OpenAI

AI features on AyudaMedico are powered by OpenAI (OpenAI, L.L.C., San Francisco, CA, USA). When you use AI-powered features, certain personal health information may be transmitted to OpenAI's API for processing. This includes:

  • Patient health summaries, diagnoses, and treatment notes (for AI Treatment Summaries)
  • Insurance document content and form field data (for Insurance Form Autofill)
  • Laboratory test names, descriptions, and clinical context (for Test Page Generation)
  • User-submitted messages and health queries (for AI Chat Assistant)

3.3 Data Minimization for AI Processing

We apply the minimum necessary principle to all AI processing:

  • Only the data strictly required for the specific AI task is transmitted to OpenAI
  • Patient identifiers are anonymized or pseudonymized where technically feasible
  • AI requests do not include unnecessary personal details beyond the scope of the task
  • AI-generated outputs are reviewed for accuracy before being stored or displayed

3.4 AI Audit Logs

To ensure accountability and transparency, AyudaMedico maintains comprehensive AI audit logs for all AI-assisted operations. These logs record:

  • The type of AI operation performed (e.g., treatment summary, insurance autofill)
  • The user role and session that initiated the AI request
  • Timestamp and duration of each AI interaction
  • A reference to the data categories processed (without storing the full content)
  • The AI model and provider used for each operation

3.5 AI Data Retention

AI-related data is subject to the following retention rules:

  • AI audit logs are retained for a minimum of 12 months for compliance and security review purposes
  • Data transmitted to OpenAI is governed by OpenAI's API data usage policies; AyudaMedico does not authorize OpenAI to use submitted data for model training
  • AI-generated content stored on our platform (e.g., treatment summaries) follows the same retention schedule as the associated patient record

3.6 User Consent for AI Processing

By using AI-powered features on AyudaMedico, you consent to the processing of your personal health information as described in this section. You have the right to:

  • Opt out of AI-powered features by contacting our Privacy Officer — manual alternatives are available for all AI-assisted workflows
  • Request a copy of AI audit log entries associated with your account
  • Request deletion of AI-generated content linked to your health records, subject to legal retention requirements
  • Receive a plain-language explanation of any AI-generated output that affects your care or billing

4. Payment Processing & Financial Data Security

AyudaMedico processes subscription payments and service fees through Stripe (Stripe, Inc., San Francisco, CA, USA), a PCI DSS Level 1 certified payment processor. This section describes how payment data is handled and protected.

4.1 Payment Data We Collect

When you make a payment on AyudaMedico, the following data is collected and processed:

  • Payment card details (card number, expiry date, CVV) — collected directly by Stripe and never stored on AyudaMedico servers
  • Billing name and address associated with the payment method
  • Transaction amount, currency, and payment status
  • Stripe Payment Intent ID and subscription identifiers for reconciliation

4.2 Stripe as Payment Processor

All payment card data is handled exclusively by Stripe. AyudaMedico:

  • Does not store, log, or have access to full card numbers or CVV codes
  • Uses Stripe's secure payment elements (hosted fields) to collect card data directly in Stripe's environment
  • Receives only a tokenized payment method reference from Stripe for subscription management
  • Processes Stripe webhook events to update subscription and payment status in our database

4.3 PCI DSS Compliance

Payment card data security is maintained through:

  • Stripe's PCI DSS Level 1 certification — the highest level of payment security compliance
  • TLS 1.3 encryption for all payment-related data transmissions
  • No cardholder data environment (CDE) on AyudaMedico infrastructure
  • Stripe webhook signature verification to prevent fraudulent payment event injection

4.4 Payment Data Retention

Payment transaction records are retained as follows:

  • Transaction metadata (amount, date, status, Stripe IDs) is retained for 7 years for tax and accounting compliance under Mexican fiscal law
  • Full card details are never retained by AyudaMedico — only Stripe retains tokenized payment method references
  • Subscription billing history is accessible to patients through their account dashboard

5. Security Safeguards Implementation

5.1 Administrative Safeguards

We have implemented comprehensive administrative measures:

  • Security Management Process: Risk analysis, risk management, and sanction policies
  • Workforce Security: Authorization procedures, workforce clearance, and termination procedures
  • Information Access Management: Role-based access controls for patients, doctors, labs, agents, and managers
  • Security Awareness Training: Regular training for all workforce members
  • Security Incident Procedures: Incident response and reporting protocols
  • Contingency Planning: Data backup, disaster recovery, and emergency operations
  • Partner Agreements: Data processing agreements with all laboratory and insurance partners

5.2 Physical Safeguards

Our physical security measures include:

  • Facility Access Controls: Secure offices, restricted access areas, and visitor management
  • Workstation Security: Policies for secure workstation use and positioning
  • Device and Media Controls: Disposal procedures and media re-use protocols
  • 24/7 Surveillance: Security cameras and monitoring systems at all branch locations
  • Secure Storage: Locked file cabinets and secure storage rooms for physical records

5.3 Technical Safeguards

We employ advanced technical security measures:

  • Access Controls: Unique user identification, role-based permissions, and automatic session logoff
  • Audit Controls: Comprehensive logging and monitoring of system activity across all user roles, including AI audit logs
  • Integrity Controls: Mechanisms to ensure health data has not been altered or destroyed
  • Transmission Security: End-to-end encryption for all electronic health data transmissions
  • Multi-Factor Authentication: Additional security layers for platform access
  • Encryption: AES-256 encryption for data at rest and TLS 1.3 for data in transit
  • Intrusion Detection: Real-time monitoring for unauthorized access attempts

6. Your Privacy Rights

6.1 Right to Access Your Records

You have the right to inspect and obtain copies of your health records, lab results, and consultation history. We will:

  • Provide access within 20 business days of your request
  • Provide records in the format you request, if readily producible
  • Charge only reasonable, cost-based fees for copies
  • Provide explanations if we deny access (with limited exceptions)

6.2 Right to Rectification

You may request corrections to your health information if you believe it is incorrect or incomplete. We will:

  • Respond to your request within 20 business days
  • Make the correction if we agree
  • Allow you to submit a statement of disagreement if we deny your request
  • Include your statement with all future disclosures

6.3 Right to an Accounting of Disclosures

You can request an accounting of certain disclosures we have made. We will provide:

  • A list of disclosures for the past twelve months
  • Date, recipient, purpose, and description of each disclosure
  • Free accounting once per year; reasonable fee for additional requests

6.4 Right to Request Restrictions

You may request restrictions on how we use or disclose your personal health data. We will evaluate all restriction requests and respond within the legally required timeframe.

6.5 Right to Confidential Communications

You can request that we communicate with you in a specific way or at a specific location. We will accommodate reasonable requests, such as:

  • Sending correspondence to an alternative address
  • Contacting you only at certain phone numbers or email addresses
  • Using specific communication methods (email, phone, in-app messaging)

7. Data Breach Notification Procedures

7.1 Breach Definition

A breach is an unauthorized acquisition, access, use, or disclosure of personal health information that compromises the security or privacy of the information. We treat any incident as a potential breach until proven otherwise.

7.2 Our Response Protocol

In the event of a breach affecting your personal health data, we will:

  • Conduct immediate investigation within 24 hours of discovery
  • Perform risk assessment to determine breach severity
  • Implement containment measures to prevent further unauthorized access
  • Document all aspects of the incident and response
  • Notify affected individuals within 72 hours of discovery
  • Report to INAI (Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales) as required by Mexican law
  • Notify relevant health authorities if the breach affects a significant number of individuals

7.3 Individual Notification

If you are affected by a breach, we will notify you by:

  • Email or in-app notification (based on your communication preferences)
  • Providing a clear description of what happened
  • Explaining the types of information involved
  • Describing steps we are taking to investigate and mitigate harm
  • Recommending steps you can take to protect yourself
  • Providing contact information for questions

8. Partner & Laboratory Data Management

8.1 Data Processing Agreements

We enter into data processing agreements with all third-party partners who may access personal health information, including:

  • Certified diagnostic laboratories and pathology facilities
  • Insurance partners and health coverage coordinators
  • IT service providers and cloud hosting companies
  • Billing and payment processing services (including Stripe)
  • AI service providers (including OpenAI)
  • Legal and consulting firms

8.2 Partner Obligations

Our data processing agreements require partners to:

  • Implement appropriate safeguards to protect personal health data
  • Report any security incidents or breaches immediately
  • Ensure their subcontractors comply with applicable privacy laws
  • Return or destroy personal data at the end of the contract
  • Make their internal practices available for review upon request

8.3 Ongoing Monitoring

We continuously monitor our partners through:

  • Regular compliance audits and assessments
  • Annual agreement reviews and updates
  • Security incident reporting requirements
  • Performance metrics and SLA monitoring

9. Training and Workforce Compliance

9.1 Mandatory Training Programs

All workforce members, including employees, contractors, and platform partners, must complete:

  • Initial privacy and data security training upon onboarding
  • Annual refresher training and regulatory updates
  • Specialized training for roles with access to patient health data
  • Security awareness training including phishing and social engineering
  • Incident response and breach notification procedures
  • AI ethics and responsible use training for roles that use AI-powered features

9.2 Sanctions Policy

We enforce strict sanctions for privacy violations:

  • Verbal or written warnings for minor violations
  • Suspension or termination for serious violations
  • Mandatory retraining before return to duties
  • Reporting to authorities for criminal violations
  • Civil and criminal penalties as prescribed by Mexican law

10. Patient Rights Exercise Procedures

10.1 How to Exercise Your Rights

To exercise any of your privacy rights, you must submit a written request to our Privacy Officer. We provide forms for:

  • Authorization for Use or Disclosure of Personal Health Data
  • Request to Access Health Records and Lab Results
  • Request to Rectify Health Information
  • Request for Cancellation (Deletion) of Personal Data
  • Request for Accounting of Disclosures
  • Request for Restrictions on Use or Disclosure
  • Opt-Out of AI Processing of Personal Health Data

10.2 Request Processing

We will process your request as follows:

  • Acknowledge receipt within 5 business days
  • Verify your identity before processing
  • Respond within the timeframe required by LFPDPPP (20 business days)
  • Provide written explanation if we deny any request
  • Document all requests and responses

11. Compliance Monitoring and Auditing

11.1 Internal Audits

We conduct regular internal audits to ensure ongoing compliance:

  • Quarterly security risk assessments
  • Monthly access log and AI audit log reviews
  • Annual comprehensive compliance audits
  • Surprise spot checks and inspections
  • Third-party security penetration testing

11.2 External Oversight

We welcome and cooperate with external oversight:

  • INAI (Instituto Nacional de Transparencia) investigations and audits
  • COFEPRIS (Comisión Federal para la Protección contra Riesgos Sanitarios) inspections
  • State health department inspections
  • Insurance company compliance reviews

12. Updates and Policy Changes

We reserve the right to change our privacy practices and this notice. Any changes will apply to all personal health data we maintain, including information created or received before the change. We will:

  • Post the current notice on our website
  • Make copies available at all branch locations
  • Provide new notice to active patients upon request
  • Send email notification of material changes (if you have opted in)
  • Update the "Last Modified" date at the top of this notice

Contact Our Privacy Officer

For questions about this notice, to exercise your privacy rights, or to file a complaint, please contact our designated Privacy Officer:

Privacy Officer

Rahul Verma

Email

Loading...

Phone

+52-(553)-038-8218

Privacy Inquiries Hotline

Mailing Address

Privacy Officer

AyudaMedico

Loading...

Filing a Complaint

If you believe your privacy rights have been violated, you have the right to file a complaint with us or with the INAI (Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales). You will not be retaliated against for filing a complaint.

File a Complaint With:

AyudaMedico Privacy Officer

Contact information listed above

INAI — Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales

Insurgentes Sur 3211, Pedregal de San Ángel

Ciudad de México, C.P. 04500

Phone: 800 835 4324

Website: www.inai.org.mx