Skip to content
Product 03 · Who sees what

Identity & Access. Precision, not perimeters.

Most healthcare breaches are not break-ins. They are legitimate accounts reading records they had no business reading. MediVault decides access per request, per field, against the care relationship — and records the decision either way.

Policy inputs
6
Granularity
Field-level
Deprovision
< 60 s
Federation
SAML · OIDC
A fingerprint illuminated on the glass of a biometric reader.
Per request, not per perimeter

Prove it again.
Every request, not once at the door.

A fingerprint on a reader confirms one thing: this specific person, right now. MediVault asks that same question of every record read — role, attributes, care relationship, purpose and consent — instead of trusting a badge issued last year.

6
Policy inputs evaluated
Field-level
Access granularity
< 60 s
Deprovisioning on exit
SAML · OIDC
Identity federation
How access decisions are recorded

Six inputs decide
every single request.

Role-based access alone cannot express 'this cardiologist, for this patient, during this admission, for treatment, unless the patient objected'. MediVault evaluates all six inputs on every call.

Role

What the person is: physician, nurse, radiologist, coder, administrator, external partner or patient.

Attributes

Department, site, specialty, employment status, training currency and device posture at the moment of the request.

Care relationship

Whether an active clinical relationship exists between this practitioner and this patient — the control most systems simply skip.

Purpose of use

Treatment, payment, operations, research or patient request — declared per request and recorded in the audit event.

Consent

The patient's standing directives and any explicit restrictions they have placed on specific record classes or specific providers.

Context

Time, network origin, geography and whether the request arrives through the portal, an API client or an emergency channel.

A radiologist sees imaging.
Finance sees billing.

Below is a default policy set, shipped ready to use and fully editable. Most organisations adjust it rather than build from scratch — the defaults already encode Swiss clinical governance norms.

RolePermitted scopeExplicitly denied
Treating physicianFull clinical record for patients in an active care relationshipRecords outside their care relationship, billing internals
RadiologistImaging studies, diagnostic reports and referring indicationsPsychiatric notes, financial and administrative records
Nursing staffCare plans, medication administration, vitals and ward notesHistoric records outside the current admission
Finance & billingCoded procedures, insurance data and invoice attachmentsClinical narrative, diagnostic images, free-text notes
AdministratorUser accounts, policies, audit dashboards and configurationPlaintext clinical content — administration is not access
External providerOnly what the patient or referring clinic explicitly sharedEverything else, with automatic expiry on shared links
PatientTheir own records, access history and sharing controlsOther patients' data and clinician-internal drafts

Note the administrator row. Platform administration and clinical data access are separate privileges in MediVault. An administrator can manage users, policies and audit dashboards without ever being able to read a patient's clinical content. Escalating one does not escalate the other.

Break-glass, done
without breaking governance.

An unconscious patient arrives and the treating team has no prior relationship. Access must be immediate. Accountability must be absolute. These are not in conflict if the system is designed for it.

Declared, not silent

The clinician must actively invoke emergency access and state a reason. There is no hidden override and no shared admin credential.

Scoped and time-boxed

Break-glass grants widened access to a named patient for a bounded window — typically 4 hours — then expires automatically.

Immediately visible

The event alerts the duty security officer and the patient's care team the moment it is invoked, not in a monthly report.

Mandatory review

Every invocation enters a review queue with a 24-hour SLA. Unreviewed events escalate to clinical governance automatically.

Patient-visible

The access appears in the patient's own access history with its stated justification, exactly like any other access.

Never disabled

Break-glass cannot be turned off, because a system that blocks emergency care is a clinical safety hazard. It is governed, not prevented.

One identity
across your estate.

Clinicians already have an institutional login. MediVault consumes it rather than creating another password for them to reuse.

Protocols
SAML 2.0 and OpenID Connect for authentication; SCIM 2.0 for automated user and group provisioning and deprovisioning.
Identity providers
Microsoft Entra ID, Okta, Keycloak, Ping and Swiss cantonal identity federations. On-premise Active Directory via a hardened connector.
Multi-factor
TOTP and FIDO2/WebAuthn hardware keys, enforced by policy. Where your IdP already enforces MFA, MediVault consumes the assertion rather than duplicating the prompt.
Deprovisioning
SCIM deactivation revokes every active session within 60 seconds. A clinician who leaves on Friday cannot read a record on Saturday.
Service accounts
Machine identities use short-lived mTLS certificates or OAuth 2.0 client credentials, scoped per integration and rotated automatically every 24 hours.
Session policy
Configurable idle timeout (default 30 minutes), absolute session cap, concurrent-session limits and step-up authentication for sensitive record classes.
Identity & Access

Model your org chart
before you commit.

Send us your role structure and clinical governance policy. We will return a working MediVault policy set, with the access matrix mapped to your departments, at no cost and with no obligation.

Default policy sets ship pre-configured for Swiss clinical governance norms