Puerto Rico Act 111-2005
Act 111-2005 on the Privacy of Medical Information
Puerto Rico's medical information privacy law with breach notification requirement 'as expeditiously as possible' - stricter than federal standards.
Jurisdiction
Puerto Rico
PR
Enacted
Oct 25, 2005
Effective
Jan 1, 2006
Enforcement
Puerto Rico Department of Health
US territory - complementary to federal HIPAA
What It Requires
Who Must Comply
This law applies to:
- • Healthcare providers in Puerto Rico
- • Entities processing medical information
- • Mental health service providers
Capability triggers:
Who bears obligations:
Safety Provisions
- • Medical information privacy protections
- • Breach notification 'as expeditiously as possible'
- • Patient consent requirements
- • Security safeguards for medical data
Enforcement
Enforced by
Puerto Rico Department of Health
Penalties
Civil penalties for violations
Quick Facts
- Binding
- Yes
- Mental Health Focus
- Yes
- Child Safety Focus
- No
- Algorithmic Scope
- No
Why It Matters
Puerto Rico's 'as expeditiously as possible' breach notification for medical info creates potentially stricter timeline than HIPAA for mental health chatbots processing Puerto Rican users' data.
Cite This
APA
Puerto Rico. (2005). Act 111-2005 on the Privacy of Medical Information. Retrieved from https://nope.net/regs/pr-act-111-2005
BibTeX
@misc{pr_act_111_2005,
title = {Act 111-2005 on the Privacy of Medical Information},
author = {Puerto Rico},
year = {2005},
url = {https://nope.net/regs/pr-act-111-2005}
} Related Regulations
Puerto Rico Cybersecurity Act
Puerto Rico's comprehensive cybersecurity law establishing cybersecurity framework for public and private sectors, complementing Act 111-2005 breach notification.
CARICOM CCSCAP 2025
CARICOM's 2025 regional cyber security framework establishing digital safety culture and coordinated incident response across 18 member states.
Chile Cybersecurity Law
First cybersecurity framework law in Latin America (Law 21,663 promulgated Mar 26, 2024; published Apr 8, 2024). Creates National Cybersecurity Agency (ANCI), mandatory incident reporting, and encryption rights.
Argentina AI Strategy
Non-binding AI governance guidelines establishing principles for responsible AI use. Argentina positioning as AI innovation hub with limited regulatory barriers. Emphasizes transparency, accountability, and human oversight. Multiple legislative proposals pending inspired by EU AI Act, aiming to establish formal regulatory authority.
AIDA
Would have regulated high-impact AI systems with potential penalties up to $25M or 5% global revenue. Part of Bill C-27 which died when Parliament ended.
Peru AI Regulations
Peru's first comprehensive AI regulatory framework, inspired by EU AI Act. Establishes three-tier risk-based approach: prohibited uses, high-risk systems (including healthcare), and low-risk/acceptable AI. First general AI regulation in Latin America. Requires human oversight, transparency, and risk assessments for high-risk AI including healthcare applications.