IDENTITY & TRUST CONNECTORS
Organization & Facility Identity
4 of 6Verify and link patients, professionals, organizations and trust frameworks while keeping authentication, identity proofing and authorization separate.
OrganizationsFacilitiesFINESSRegistriesTenantsHierarchyIdentifiers
Trusted Organization Data
Verify entities against official registries.
Hierarchical Structure
Represent legal entities, facilities, departments and services.
Multi-Tenant Ready
Link external identities to Mediloop tenants and memberships.
Interoperable
Use stable identifiers for national and cross-border exchange.
Organization Identity Model
1
External Registries
FINESS, Luxembourg registries, ROR and trusted sources
2
Registry Adapters
Fetch, validate and normalize organization attributes
3
Mediloop Organization
Link external identifiers to tenant/legal entity
4
Hierarchy
Facility, unit, service and location relationships
5
Linked Entities
Memberships, apps, certs, contracts and compliance
Identity Sources
| Source | Entity | Use |
|---|---|---|
| FINESS / ROR (FR) | Legal entity / establishment | Authoritative identifiers and status |
| Luxembourg registries | Hospitals, clinics, pharmacies, laboratories | National verification |
| ROR (international) | Research/health organizations | Cross-reference where relevant |
| Partner directories | Authorized external organizations | Partner onboarding with verification |
Data Model
| Layer | Example | Identity rule |
|---|---|---|
| Legal entity / tenant | Hospital group | Stable Mediloop tenant; external IDs linked |
| Facility | Hospital / clinic / pharmacy | Verified external identifiers |
| Organizational unit | Cardiology service | Internal structure; external mapping optional |
| Location | Site / room / address | Physical/operational location, not necessarily legal identity |
Hierarchy & Structure
Keep legal identity separate from organizational hierarchy
Allow one legal entity to operate multiple facilities
Represent parent/child relationships with validity dates
Do not derive Mediloop permissions directly from external hierarchy
Support organization changes without rewriting audit history
APIs & Examples
httpCopy
# Illustrative organization resolution
GET /v1/identity/organizations/resolve?system=finess&identifier=123456789
Authorization: Bearer <token>Illustrative route; production organization identity APIs will be versioned when frozen.
Security & Compliance
Verify authoritative source and freshness
Review organization status before production onboarding
Separate registry attributes from tenant permissions
Audit create/link/update/reverification events
Restrict sensitive legal/contract data to proper scopes
Developer Integration Surface
| Surface | Operation / resource | Use | Status |
|---|---|---|---|
| Registry adapter | lookup / verify external organization | Organization verification | Country-specific |
| Organization API | resolve / link / hierarchy | Application organization context | Planned/versioned |
| FHIR | Organization / Location | Clinical interoperability representation | FHIR |
| Tenant context | X-Tenant-Id + membership | Authorize Mediloop operations | Core |
Next Steps
Identify authoritative registry
Map external IDs to tenant/facility model
Validate hierarchy and status
Configure memberships separately
Schedule revalidation