Mediloop
IDENTITY & TRUST CONNECTORS

Overview

1 of 6

Verify and link patients, professionals, organizations and trust frameworks while keeping authentication, identity proofing and authorization separate.

Identity TypesOIDC / SAMLNational IdPsProfessional RegistriesX.509 / PKIeIDASAuthorization
Trusted Identities

Verify patients, professionals and organizations through trusted sources.

Interoperable & Secure

Use standard federation and certificate mechanisms.

Multi-Country Support

Support Luxembourg, France and evolving European trust frameworks.

Seamless Integration

Link external identities to Mediloop Identity & SSO without coupling applications to each provider.

What Are Identity & Trust Connectors?
Identity is the foundation of trusted healthcare access
Identity & Trust Connectors connect Mediloop with trusted patient, professional, organization and certificate authorities. They establish identity and trust; authorization remains a separate Mediloop decision based on active membership, role, scopes, tenant context, consent and purpose of use.
Why It Matters
Avoid duplicating national identity integrations in every healthcare application
Use verified professional and organization status in clinical workflows
Keep external identities linked rather than replacing Mediloop user identity
Support cross-border and multi-country trust with clear provenance
Centralize certificate validation, revocation, audit and revalidation
Identity Types
Patient Identity

MPI, national identifiers, demographics and linked external patient identities.

Professional Identity

RPPS/e-CPS, LuxTrust and professional registry verification.

Organization & Facility

Legal entities, facilities, departments and external registry identifiers.

Federated Technical Identity

OIDC/SAML clients, certificates, service accounts and system trust.

Architecture Overview
1
External Identity Sources
LuxTrust, Pro Santé Connect, registries, eIDAS, OIDC/SAML
2
Identity Connectors
Federation adapters, certificate validation and attribute mapping
3
Identity Linking
Patient/professional/org identities linked to Mediloop records
4
Authorization Layer
Memberships, roles, scopes, consent and purpose
5
Applications
Patient, doctor, pharmacy, hospital and partner applications
Supported Systems
System / sourceIdentity typeMechanismStatus
LuxTrust (LU)Professional / citizen / organizationOIDC/certificates depending serviceCountry connector
Pro Santé Connect / e-CPS (FR)Healthcare professionalOIDC / national trustCountry connector
RPPS / national registriesProfessional attributesRegistry lookup / verificationAdapter
FINESS / organization registriesOrganization / facilityRegistry lookupAdapter
eIDAS / national eIDCross-border identityFederationEvolving EU support
Other enterprise IdPsUser / workforceOIDC / SAMLStandard
Key Use Cases
Sign in a verified healthcare professional
Link professional identity to the correct Mediloop membership
Resolve a patient across EHR/HIE identities using MPI
Verify a hospital, clinic, pharmacy or facility before tenant onboarding
Authenticate a partner application or service account
Validate a certificate and revocation status before system-to-system exchange
Security & Compliance
Authentication never grants clinical access by itself
Least privilege with tenant-aware scopes and memberships
Certificate revocation and expiry monitoring
Audit all identity linking/unlinking and verification events
Separate provider attributes from Mediloop authorization state
Support GDPR/eIDAS/national requirements and revalidation
Developer Integration Surface
How developers interact with this capability
Applications consume a stable Mediloop identity/trust contract; provider-specific federation, registry and certificate details stay inside connector adapters.
SurfaceOperation / resourceUseStatus
FederationOIDC / OAuth 2.x / SAMLAuthenticate with external identity providersStandard
Registry verificationRPPS / FINESS / LU registriesValidate professional or organization attributesCountry adapter
CertificatesX.509 / mTLS / OCSP / CRLSystem and professional trustPKI
Identity APIsLink / unlink / verify / resolveMediloop application identity workflowsVersioned when frozen
Eventsverification.changed / certificate.expiringAsynchronous trust updatesPlanned/evolving
Next Steps
Choose the identity type you need to verify
Configure the external provider or registry
Link verified identity to the correct Mediloop entity
Apply authorization and consent separately
Test revalidation, revocation and failure cases