Consent, Governance & Cross-Border Trust
6 of 8Connect Mediloop to national and cross-border health information exchange infrastructures using standards-based, governed adapters.
Give patients appropriate control and transparency.
Apply GDPR, national rules and evolving EHDS requirements.
Establish trust between people, organizations and infrastructures.
Enforce policy, audit and minimization at every boundary.
Patient grants a specific permission where required.
Exchange required/authorized by law.
Treatment relationship and applicable rules.
Separate governance/legal basis and controlled access.
Lawful basis, purpose limitation, minimization, transparency and rights.
Phased EU requirements; label future capabilities.
Country-specific DMP/DSP and authority requirements.
Data-sharing/trust agreements and responsibilities.
| Surface | Operation / resource | Use | Status |
|---|---|---|---|
| Consent/policy | Consent resource / policy decision | Determine permitted data use | Governed service |
| Identity & trust | OIDC/SAML/eID/certificates | Authenticate and establish trust | Standard + national |
| Audit | FHIR Provenance / ATNA / audit log | Trace decisions | Standard/profile |
| Connector policy | Purpose/scopes/minimization | Authorize exchange | Mediloop governance |