When a company operates a medical service, it accumulates the most protected category of information that exists under Mexican law. That's not rhetorical exaggeration: health data is sensitive personal data, and the law treats it differently than an address or a phone number.
This article explains what changed with the law in force since 2025, where the real risk concentrates in a large operation, and why the critical point is almost never a hack — it's something far more everyday: who can see what.
What changed in 2025
In March 2025, a new Ley Federal de Protección de Datos Personales en Posesión de los Particulares was published and took effect the day after publication. Two changes matter for any company that handles its people's medical information.
The first is about authority. The Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) was dissolved, and its powers were transferred to the Secretaría Anticorrupción y Buen Gobierno. The counterpart changed, and so did the institutional logic of oversight.
The second is about exposure. The law provides for fines ranging from 100 to 160,000 UMA for certain violations and from 200 to 320,000 UMA for the most serious ones, with an additional fine for repeat offenses. When the violation involves sensitive data, those amounts can be increased up to two times.
Note: fines are expressed in Unidades de Medida y Actualización (UMA), not in pesos. The UMA's value is updated every year, so the peso amount of a given penalty changes over time. At the UMA value in effect in 2026, the doubled ceiling of 320,000 UMA for a sensitive-data violation sits above 75 million pesos.
Why health data is the most exposed category
Sensitive data is data whose misuse could lead to discrimination. Health falls squarely into that definition, and two practical consequences follow:
- The applicable penalty amount can be increased up to two times compared with ordinary personal data.
- The standard of care expected of the company is higher — in consent, in access control, and in security.
Where the real risk sits in a large operation
The usual mental image of data risk is a cyberattack. In practice, at companies with an in-house medical service, the problem tends to be far more mundane — and for that same reason, harder to spot.
- Clinical records kept in spreadsheets or shared folders, with no control over who has access.
- Medical exam results that arrive by email and sit in inboxes for years.
- HR staff with access to clinical detail, not just administrative status.
- Historical files from old plants or subsidiaries that no one has reviewed in years.
- No audit log: not being able to show who consulted which record, and when.
The specific problem of HR access
This deserves its own section because it carries the most consequences and gets discussed the least.
The Reglamento Federal de Seguridad y Salud en el Trabajo (RFSST) is explicit about what gets reported to the employer: fitness for work, not diagnosis, "with full respect for the confidentiality required by medical ethics" (art. 50). If the department making labor decisions has access to an employee's medical diagnosis instead of only their fitness status, any later decision about that person is exposed to being challenged. You don't need to prove the diagnosis influenced the decision — showing the access existed is enough. The access itself becomes the evidence.
That's why separating access isn't just another technical feature of a system. It's the control that protects the company — and the person.
Table 1
Who needs to see what in an occupational clinical record
| Role | What they need to see to do their job | What they shouldn't see |
|---|---|---|
| Service physician | The full clinical record of the people they treat | Information about colleagues who aren't their patients |
| HR | Administrative status: whether the exam was performed, fitness, validity period, absences | Diagnoses, clinical notes, and detailed results |
| Leadership | Aggregated, anonymized data about the population | Any data that could identify a specific person |
In a review, the question won't just be whether someone saw something they shouldn't have. It will be whether your system could have prevented it — and whether you can prove it.
What to review in your company
An honest self-assessment starts with uncomfortable, specific questions — not a general diagnosis:
Watch out: if the answer to "who can open an employee's clinical record?" includes anyone outside of medical staff, that's the most urgent finding in your operation.
Points that tend to get overlooked
- Traceability. Restricting access isn't enough; you need to be able to prove, with a log, who consulted what and when.
- Outside vendors. Subcontracted labs and clinics also handle this data, and responsibility doesn't fully transfer away just because there's a contract.
- The privacy notice. It needs to be specific to processing your workforce's health data, not a generic text reused from the website.
The bottom line is simple: your employees' medical records already exist and are already the company's responsibility. What's actually in your hands is which system they live in, and who can open them.
Sources
- Ley Federal de Protección de Datos Personales en Posesión de los Particulares, published in the Diario Oficial de la Federación on March 20, 2025
- Reglamento Federal de Seguridad y Salud en el Trabajo, article 50