IDENTITY & TRUST CONNECTORS
Overview
1 of 6Verify and link patients, professionals, organizations and trust frameworks while keeping authentication, identity proofing and authorization separate.
Identity TypesOIDC / SAMLNational IdPsProfessional RegistriesX.509 / PKIeIDASAuthorization
Trusted Identities
Verify patients, professionals and organizations through trusted sources.
Interoperable & Secure
Use standard federation and certificate mechanisms.
Multi-Country Support
Support Luxembourg, France and evolving European trust frameworks.
Seamless Integration
Link external identities to Mediloop Identity & SSO without coupling applications to each provider.
What Are Identity & Trust Connectors?
Identity is the foundation of trusted healthcare access
Identity & Trust Connectors connect Mediloop with trusted patient, professional, organization and certificate authorities. They establish identity and trust; authorization remains a separate Mediloop decision based on active membership, role, scopes, tenant context, consent and purpose of use.
Why It Matters
Avoid duplicating national identity integrations in every healthcare application
Use verified professional and organization status in clinical workflows
Keep external identities linked rather than replacing Mediloop user identity
Support cross-border and multi-country trust with clear provenance
Centralize certificate validation, revocation, audit and revalidation
Identity Types
Patient Identity
MPI, national identifiers, demographics and linked external patient identities.
Professional Identity
RPPS/e-CPS, LuxTrust and professional registry verification.
Organization & Facility
Legal entities, facilities, departments and external registry identifiers.
Federated Technical Identity
OIDC/SAML clients, certificates, service accounts and system trust.
Architecture Overview
1
External Identity Sources
LuxTrust, Pro Santé Connect, registries, eIDAS, OIDC/SAML
2
Identity Connectors
Federation adapters, certificate validation and attribute mapping
3
Identity Linking
Patient/professional/org identities linked to Mediloop records
4
Authorization Layer
Memberships, roles, scopes, consent and purpose
5
Applications
Patient, doctor, pharmacy, hospital and partner applications
Supported Systems
| System / source | Identity type | Mechanism | Status |
|---|---|---|---|
| LuxTrust (LU) | Professional / citizen / organization | OIDC/certificates depending service | Country connector |
| Pro Santé Connect / e-CPS (FR) | Healthcare professional | OIDC / national trust | Country connector |
| RPPS / national registries | Professional attributes | Registry lookup / verification | Adapter |
| FINESS / organization registries | Organization / facility | Registry lookup | Adapter |
| eIDAS / national eID | Cross-border identity | Federation | Evolving EU support |
| Other enterprise IdPs | User / workforce | OIDC / SAML | Standard |
Key Use Cases
Sign in a verified healthcare professional
Link professional identity to the correct Mediloop membership
Resolve a patient across EHR/HIE identities using MPI
Verify a hospital, clinic, pharmacy or facility before tenant onboarding
Authenticate a partner application or service account
Validate a certificate and revocation status before system-to-system exchange
Security & Compliance
Authentication never grants clinical access by itself
Least privilege with tenant-aware scopes and memberships
Certificate revocation and expiry monitoring
Audit all identity linking/unlinking and verification events
Separate provider attributes from Mediloop authorization state
Support GDPR/eIDAS/national requirements and revalidation
Developer Integration Surface
How developers interact with this capability
Applications consume a stable Mediloop identity/trust contract; provider-specific federation, registry and certificate details stay inside connector adapters.
| Surface | Operation / resource | Use | Status |
|---|---|---|---|
| Federation | OIDC / OAuth 2.x / SAML | Authenticate with external identity providers | Standard |
| Registry verification | RPPS / FINESS / LU registries | Validate professional or organization attributes | Country adapter |
| Certificates | X.509 / mTLS / OCSP / CRL | System and professional trust | PKI |
| Identity APIs | Link / unlink / verify / resolve | Mediloop application identity workflows | Versioned when frozen |
| Events | verification.changed / certificate.expiring | Asynchronous trust updates | Planned/evolving |
Next Steps
Choose the identity type you need to verify
Configure the external provider or registry
Link verified identity to the correct Mediloop entity
Apply authorization and consent separately
Test revalidation, revocation and failure cases