Medical records in most LATAM jurisdictions must be retained 15-20 years. Data encrypted with ECC today will still exist when quantum hardware can break it. The exposure is already locked in.
Where the cryptographic exposure sits
Electronic health records (EHR) are encrypted at rest using symmetric keys wrapped with ECC key exchange. The ECC component is the quantum-vulnerable link. DICOM medical imaging transfer (PACS systems) uses TLS with ECDHE. Inter-hospital patient referral networks authenticate with ECC-based certificates. Patient identity verification in national health portals (Brazil's ConecteSUS, Chile's FONASA digital, Mexico's IMSS digital) uses PKI chains anchored in ECC root certificates. The defining risk in healthcare is not immediate decryption. It is that patient data archived today under ECC encryption will be retroactively accessible once hardware matures, well within the retention window.
The regulatory landscape moving now
LGPD, Brazil (Lei 13.709/2018)
Requires appropriate technical measures to protect sensitive personal data. ANPD (the enforcement authority) has begun referencing cryptographic controls in its technical guidelines. Medical data is explicitly classified as sensitive data requiring heightened protection.
Ley 1581, Colombia
Data protection law covers health data as sensitive personal data. SIC (the enforcement authority) has issued sector-specific guidance referencing encryption standards.
Ley 19.628, Chile (updated 2024)
Chile's updated data protection law (Ley 21.719) introduces stricter technical safeguard requirements that implicitly cover cryptographic controls for health data.
NOM-004-SSA3, Mexico
Clinical record standard requires security controls including encryption for electronic patient records. References FIPS-compatible standards for health information systems.
What a QTA delivers for this sector
A QTA scoped to your EHR encryption key hierarchy and patient identity PKI delivers: which stored records are protected by quantum-vulnerable key wrapping, the migration priority by data sensitivity tier, and a compliance narrative for LGPD/Ley 1581 auditors.
