Mediloop
IDENTITY & TRUST CONNECTORS

Organization & Facility Identity

4 of 6

Verify and link patients, professionals, organizations and trust frameworks while keeping authentication, identity proofing and authorization separate.

OrganizationsFacilitiesFINESSRegistriesTenantsHierarchyIdentifiers
Trusted Organization Data

Verify entities against official registries.

Hierarchical Structure

Represent legal entities, facilities, departments and services.

Multi-Tenant Ready

Link external identities to Mediloop tenants and memberships.

Interoperable

Use stable identifiers for national and cross-border exchange.

Organization Identity Model
1
External Registries
FINESS, Luxembourg registries, ROR and trusted sources
2
Registry Adapters
Fetch, validate and normalize organization attributes
3
Mediloop Organization
Link external identifiers to tenant/legal entity
4
Hierarchy
Facility, unit, service and location relationships
5
Linked Entities
Memberships, apps, certs, contracts and compliance
Identity Sources
SourceEntityUse
FINESS / ROR (FR)Legal entity / establishmentAuthoritative identifiers and status
Luxembourg registriesHospitals, clinics, pharmacies, laboratoriesNational verification
ROR (international)Research/health organizationsCross-reference where relevant
Partner directoriesAuthorized external organizationsPartner onboarding with verification
Data Model
LayerExampleIdentity rule
Legal entity / tenantHospital groupStable Mediloop tenant; external IDs linked
FacilityHospital / clinic / pharmacyVerified external identifiers
Organizational unitCardiology serviceInternal structure; external mapping optional
LocationSite / room / addressPhysical/operational location, not necessarily legal identity
Hierarchy & Structure
Keep legal identity separate from organizational hierarchy
Allow one legal entity to operate multiple facilities
Represent parent/child relationships with validity dates
Do not derive Mediloop permissions directly from external hierarchy
Support organization changes without rewriting audit history
APIs & Examples
httpCopy
# Illustrative organization resolution
GET /v1/identity/organizations/resolve?system=finess&identifier=123456789
Authorization: Bearer <token>
Illustrative route; production organization identity APIs will be versioned when frozen.
Security & Compliance
Verify authoritative source and freshness
Review organization status before production onboarding
Separate registry attributes from tenant permissions
Audit create/link/update/reverification events
Restrict sensitive legal/contract data to proper scopes
Developer Integration Surface
SurfaceOperation / resourceUseStatus
Registry adapterlookup / verify external organizationOrganization verificationCountry-specific
Organization APIresolve / link / hierarchyApplication organization contextPlanned/versioned
FHIROrganization / LocationClinical interoperability representationFHIR
Tenant contextX-Tenant-Id + membershipAuthorize Mediloop operationsCore
Next Steps
Identify authoritative registry
Map external IDs to tenant/facility model
Validate hierarchy and status
Configure memberships separately
Schedule revalidation