Mediloop
NATIONAL & HEALTH INFORMATION EXCHANGE CONNECTORS

Consent, Governance & Cross-Border Trust

6 of 8

Connect Mediloop to national and cross-border health information exchange infrastructures using standards-based, governed adapters.

ConsentPurpose of useAccess policyeIDAS / national eIDmTLS / certificatesFHIR ProvenanceIHE ATNA
Patient Empowerment

Give patients appropriate control and transparency.

Regulatory Compliance

Apply GDPR, national rules and evolving EHDS requirements.

Trusted Exchange

Establish trust between people, organizations and infrastructures.

Secure by Design

Enforce policy, audit and minimization at every boundary.

Consent & Exchange Flow
1
Consent / Legal Basis
Consent, mandate or authorized purpose
2
Authorization & Trust
Validate person, professional, organization and connector
3
Data Exchange
Apply profile, minimization and routing
4
Audit & Provenance
Record access/policy/outcome
5
Ongoing Control
Revocation, expiry, revalidation
Consent Types
Explicit consent

Patient grants a specific permission where required.

Legal mandate

Exchange required/authorized by law.

Care context

Treatment relationship and applicable rules.

Secondary use

Separate governance/legal basis and controlled access.

Access Control & Authorization
Authenticate technical client, person/professional and organization as applicable
Evaluate membership, role, scopes, tenant and purpose independently
Apply patient consent/policy and national restrictions
Minimize returned resources/fields
Deny safely when required trust/policy inputs are missing
Trust & Cross-Border Authorization
LuxTrust / Pro Santé Connect or other national trust where applicable
eIDAS/national eID where supported
X.509 and mTLS for system trust
Certificate status/revocation validation
NCPeH trust agreements for MyHealth@EU
Organization/facility validation
Regulatory Framework
GDPR

Lawful basis, purpose limitation, minimization, transparency and rights.

EHDS

Phased EU requirements; label future capabilities.

National Rules

Country-specific DMP/DSP and authority requirements.

Contracts & Policies

Data-sharing/trust agreements and responsibilities.

Audit, Provenance & Monitoring
FHIR Provenance where appropriate
IHE ATNA / national audit requirements
Patient access history and compliance reporting
Correlation IDs across connector/identity/data services
Alerts for suspicious access or certificate problems
Tamper-evident evidence according to audit policy
Key Benefits
Higher patient trust and transparency
Safer cross-border exchange
Reduced risk of authentication-only access
Reusable policy enforcement
Clear regulatory evidence
Developer Integration Surface
SurfaceOperation / resourceUseStatus
Consent/policyConsent resource / policy decisionDetermine permitted data useGoverned service
Identity & trustOIDC/SAML/eID/certificatesAuthenticate and establish trustStandard + national
AuditFHIR Provenance / ATNA / audit logTrace decisionsStandard/profile
Connector policyPurpose/scopes/minimizationAuthorize exchangeMediloop governance
Next Steps
Define legal basis/consent policy
Map identity and trust inputs
Enforce policy before release
Validate revocation/denial/audit
Review policy as requirements evolve