Explains how Amphora Health handles patient requests to access their information, correct a duplicate record, or request cancellation of their data in Vaquita EHR.
Ánfora Salud S.A.P.I. de C.V. (“Amphora Health”) issues this Policy to explain how we handle a patient’s request to access their information, correct a duplicate record, or ask that we stop using their data, in the current context of Vaquita EHR: an electronic health record used by physicians and hospitals, to which patients do not yet have direct access. It complements, without replacing, the current Privacy Notice.
To define how, in the current context of Vaquita EHR, three types of patient requests are handled: access to their information, merging of duplicate records, and cancellation or blocking of their data; and to anticipate how this handling will change once the Patient Portal is integrated.
This policy is inspired by the four Pillars of Meaningful Use, applied to Amphora Health’s context:
In addition to these pillars, this policy is guided by the four classic principles of bioethics:
Patients may exercise any of the following requests:
Today, the patient does not have their own account in Vaquita EHR: their record is managed by the physician or institution that treats them. The patient may exercise their rights through any of the following channels:
Regardless of the channel through which the request arrives, we will make our best effort to confirm that whoever is requesting it is the patient or their representative. We know that no verification method is infallible; that is why we keep a record of how each request was verified.
The verification method depends on the channel:
The patient may request a copy of their information, subject to identity verification. If we cannot deliver part of the information, for example because it includes another person’s data, we explain this to the patient in writing.
Amphora Health’s Legal Affairs Office decides in each case whether blocking or deletion applies, and the response to the patient always explains the exact reason, in accordance with applicable personal data protection law.
Sometimes the same patient ends up with two different records, for example if they registered twice or changed institutions. The patient, their physician, or the institution may ask us to unify them, or the system itself may detect it through matching logic.
The minimum elements that are compared, and that must match exactly across all four for the merge to be resolved automatically, are:
| Element | Description |
|---|---|
| Full name | The patient’s first and last name(s), as captured in each record. |
| National ID Number | The patient’s unique national identity identifier; in Mexico, this corresponds to the CURP (Clave Única de Registro de Población). |
| Date of birth | Day, month, and year of the patient’s birth. |
| Place of birth | Country, state, and city of the patient’s birth. |
The system can also detect approximate matches on these same elements (for example, capture variations, accents, or the order of last names), but an approximate match never resolves the merge on its own: it only serves to flag a possible case and send it for human review under the following paragraph.
No single element is automatically sufficient to merge records, including the National ID Number, since it may be duplicated, miscalculated, or mistranscribed in the record. The merge is resolved automatically only when all four elements match exactly:
National ID Number, full name, date of birth, and place of birth. In the event of any partial match, the case is escalated to Amphora Health’s Medical Department for a physician to review before proceeding. When the match is exact across all four elements, Amphora Health’s Information and Technology Office executes the merge. No merge is performed without human approval. If a merge is later found to have been an error, it can be reversed, and the patient may request that review.
When approving a merge, whoever executes it designates one of the two records as primary. This works in two ways, depending on the stage:
When the patient is a minor or legally incapacitated, their father, mother, guardian, or legal representative may exercise these rights on their behalf, upon proof of that representation. If a patient has died, their relatives or heirs may request access to their record upon proof of kinship or entitlement.
Amphora Health plans to integrate a Patient Portal within Vaquita EHR, through which patients will, for the first time, be able to log in directly with their own account to view their information, download it, and request that we send it to another physician or institution of their choice, without depending on their physician or institution to channel the request. The rights and procedures described in this Policy will not change with this integration: what will change is the channel through which the patient exercises them. The portal will be free for the patient; in the future, its operation could be funded through advertising or a marketplace of health products or services, without this being able to condition or increase the cost of exercising these rights, and subject to prior evaluation of its compatibility with the current Privacy Notice.
Every request handled is logged with the date, type of request, who resolved it, and the outcome, subject to the current Log Retention Policy. Amphora Health documents and periodically reviews the performance of the matching logic, in order to adjust its criteria if it generates too many errors.
This Policy takes effect upon its formal approval and is reviewed whenever the applicable legal framework, the architecture of Vaquita EHR or the future Patient Portal, or the matching logic changes.
Applicable regulations in Mexico:
International references taken as a design practice, without constituting a legal obligation for Amphora Health in Mexico: