Security
Last updated: August 14, 2026
This is a courtesy English translation. The legally binding version is the Spanish original on docenlinea.mx.
Our approach
OnlineDoc (DocEnLinea) is the connection layer between platforms and a network of medical reviewers in Mexico. We treat clinical data at a PHI-grade security standard — a voluntary security floor that we layer on top of the binding Mexican framework (LFPDPPP, applicable NOMs, and the LGS). These US-style standards are not required by Mexican law; we adopt them so partners in the United States can integrate with confidence.
The medical reviewer (a physician with a valid cédula profesional, under the Responsable Sanitario) is the controller of clinical data; OnlineDoc acts as the processor, storing and surfacing data on the controller's instructions. See our Data Processing Addendum.
Account & access security
- Two-step verification (2FA): TOTP is mandatory for all reviewer and staff accounts; no privileged action without it.
- Strong passwords: minimum length and complexity enforced server-side, checked against known breached-password databases (HaveIBeenPwned k-anonymity — the password never leaves our servers).
- Human verification: anti-bot challenge (Cloudflare Turnstile) on signup and login.
- Least privilege: role- and scope-gated access; per-affiliate API credentials that are rotatable and revocable.
- Signed integrations: partner webhooks are signed (HMAC-SHA256) with replay protection.
Data protection
- Encryption in transit: TLS 1.2+ everywhere, with HSTS.
- Encryption at rest: all data stores are encrypted at rest; the most sensitive clinical fields receive additional field-level encryption.
- Data minimization: we accept only the data a reviewer needs; labs and documents upload directly to storage via signed URLs, never embedded in requests.
- Audit logging: an append-only access log records who did what, from where, and with what result — without storing clinical content.
- PHI-scrubbed logging: application logs and error monitoring are scrubbed of clinical content.
Infrastructure & subprocessors
The platform runs on established cloud infrastructure with a security edge (WAF, bot mitigation, DDoS protection) in front of a HIPAA-eligible database. Every vendor that touches personal data does so under a contractual agreement, and we seek Business Associate Agreements (BAAs) where applicable.
The full, current list of third parties is published on our Subprocessors page.
Certifications & roadmap
OnlineDoc is on a path toward Business Associate Agreements (BAAs), PHI-grade safeguards, HIPAA-aligned controls, and SOC 2, as a voluntary security baseline. We describe these as goals we are actively working toward, not as completed certifications. The binding compliance framework for the Mexican pipeline remains the LFPDPPP, applicable NOMs, and the LGS — see Mexico Compliance.
Reporting a vulnerability
If you believe you've found a security issue, please contact us at security@docenlinea.mx. We appreciate responsible disclosure and will respond promptly.
