There's an objective way to know whether the system where your company keeps clinical records complies with the standard: check the public registry of certified systems published by Mexico's Ministry of Health. If the system you use doesn't appear there, it isn't certified. There's no gray area.
This guide explains what NOM-024 is, who it applies to, and how to run that check in a few minutes — including what to look at beyond simply finding the name on the list.
What NOM-024 is and who it applies to
NOM-024-SSA3-2012 regulates Sistemas de Información de Registro Electrónico para la Salud, known by their Spanish acronym SIRES. In plain terms: it regulates the software where electronic clinical records live.
According to the Dirección General de Información en Salud (DGIS) itself, the standard is mandatory nationwide for every establishment that provides medical care and is part of Mexico's National Health System and adopts a SIRES. It also reaches individuals or companies that hold the ownership, use, authorship, distribution, or commercialization rights to those systems.
Put another way: the obligation touches two parties — the establishment operating the medical service, and the software vendor. Neither can shift the responsibility onto the other.
What the certification evaluates
The certificate is issued by Mexico's Ministry of Health through the DGIS, after a conformity-assessment procedure. When you review a certificate in the public registry, you'll see it specifies a concrete scope, for example:
- The area of application, public or private sector.
- Whether it includes a Health Information Security Management System.
- The modules covered, such as outpatient care, dental health, or mental health.
- The vendor's legal name, the system's name, and the exact certified version.
- The certificate's start and end dates.
Note: certification is granted to a specific version of the system, not to the vendor in general. A certificate covering version 2 doesn't automatically cover version 3.
How to verify it in four steps
The check is public, free, and requires no filing. Anyone on your compliance team can do it:
- Go to the Dirección General de Información en Salud portal, to the NOM-024-SSA3-2012 Certification section.
- Open the section listing SIRES Certified under NOM-024-SSA3-2012.
- Search by your system vendor's legal name, not the product's commercial name. On the list, systems appear under the holding company.
- Open the certificate's detail and check three things: the certified version, the scope, and the validity dates.
The most common mistake when verifying
Many people stop at the first step: they find the name, breathe a sigh of relief, and close the page. The three data points that follow are the ones that actually matter, because a certificate can exist and still not cover your case.
Table 1
Three things to check on any certificate, beyond the name simply appearing on the list
| What to check | Why it matters | Warning sign |
|---|---|---|
| Certified version | The certificate covers a specific software version | You're running a version different from the one on the certificate |
| Scope | Defines which modules and which area the certification covers | The scope doesn't include the type of service your company operates |
| Validity | Certificates have a start date and an end date | The end date has already passed, or is about to |
Watch out for the phrase “we're in the certification process”
It's a common answer when someone asks for the certificate, and the standard itself anticipated it. The official registry includes an explanatory note that, citing numeral 7.4.2 of NOM-024, clarifies that a system is not considered to be in the certification process unless verification dates have actually been assigned in response to a request.
In other words: having started conversations, having hired a consultant, or intending to get certified doesn't count as being in process. There's also a public tracking section for systems currently in the certification process, so that claim can be checked too.
The list is public, the certificate has dates, and the version is written down. This isn't a matter of opinion — it's a fact you look up.
Watch out: the public registry also logs non-compliance results. A system can have gone through the procedure and failed to earn certification, and that gets recorded too.
Sherpa's own listing
So you can run through the exercise with a real example, here's how Sherpa appears in the official registry:
- Legal name: Sherpa Monterrey, S.A. de C.V.
- Certified system: Sherpa Salud Ocupacional 3.0, version 3.
- Area of application: private sector.
- Scope: Health Information Security Management System and outpatient care.
- Validity: July 31, 2026 to July 30, 2028.
We suggest checking it yourself on the Ministry of Health's portal, and applying the exact same criteria to the system your company uses today. That comparison tends to be the shortest, clearest conversation a compliance team can have.
Sources
- NOM-024-SSA3-2012, on electronic health record information systems, Diario Oficial de la Federación
- Registry of certified Health Information Registry Systems, Dirección General de Información en Salud, Ministry of Health