Identity & Access. Precision, not perimeters.
Most healthcare breaches are not break-ins. They are legitimate accounts reading records they had no business reading. MediVault decides access per request, per field, against the care relationship — and records the decision either way.
- Policy inputs
- 6
- Granularity
- Field-level
- Deprovision
- < 60 s
- Federation
- SAML · OIDC

Prove it again.
Every request, not once at the door.
A fingerprint on a reader confirms one thing: this specific person, right now. MediVault asks that same question of every record read — role, attributes, care relationship, purpose and consent — instead of trusting a badge issued last year.
- 6
- Policy inputs evaluated
- Field-level
- Access granularity
- < 60 s
- Deprovisioning on exit
- SAML · OIDC
- Identity federation
Six inputs decide
every single request.
Role-based access alone cannot express 'this cardiologist, for this patient, during this admission, for treatment, unless the patient objected'. MediVault evaluates all six inputs on every call.
Role
What the person is: physician, nurse, radiologist, coder, administrator, external partner or patient.
Attributes
Department, site, specialty, employment status, training currency and device posture at the moment of the request.
Care relationship
Whether an active clinical relationship exists between this practitioner and this patient — the control most systems simply skip.
Purpose of use
Treatment, payment, operations, research or patient request — declared per request and recorded in the audit event.
Consent
The patient's standing directives and any explicit restrictions they have placed on specific record classes or specific providers.
Context
Time, network origin, geography and whether the request arrives through the portal, an API client or an emergency channel.
A radiologist sees imaging.
Finance sees billing.
Below is a default policy set, shipped ready to use and fully editable. Most organisations adjust it rather than build from scratch — the defaults already encode Swiss clinical governance norms.
| Role | Permitted scope | Explicitly denied |
|---|---|---|
| Treating physician | Full clinical record for patients in an active care relationship | Records outside their care relationship, billing internals |
| Radiologist | Imaging studies, diagnostic reports and referring indications | Psychiatric notes, financial and administrative records |
| Nursing staff | Care plans, medication administration, vitals and ward notes | Historic records outside the current admission |
| Finance & billing | Coded procedures, insurance data and invoice attachments | Clinical narrative, diagnostic images, free-text notes |
| Administrator | User accounts, policies, audit dashboards and configuration | Plaintext clinical content — administration is not access |
| External provider | Only what the patient or referring clinic explicitly shared | Everything else, with automatic expiry on shared links |
| Patient | Their own records, access history and sharing controls | Other patients' data and clinician-internal drafts |
Note the administrator row. Platform administration and clinical data access are separate privileges in MediVault. An administrator can manage users, policies and audit dashboards without ever being able to read a patient's clinical content. Escalating one does not escalate the other.
Break-glass, done
without breaking governance.
An unconscious patient arrives and the treating team has no prior relationship. Access must be immediate. Accountability must be absolute. These are not in conflict if the system is designed for it.
Declared, not silent
The clinician must actively invoke emergency access and state a reason. There is no hidden override and no shared admin credential.
Scoped and time-boxed
Break-glass grants widened access to a named patient for a bounded window — typically 4 hours — then expires automatically.
Immediately visible
The event alerts the duty security officer and the patient's care team the moment it is invoked, not in a monthly report.
Mandatory review
Every invocation enters a review queue with a 24-hour SLA. Unreviewed events escalate to clinical governance automatically.
Patient-visible
The access appears in the patient's own access history with its stated justification, exactly like any other access.
Never disabled
Break-glass cannot be turned off, because a system that blocks emergency care is a clinical safety hazard. It is governed, not prevented.
One identity
across your estate.
Clinicians already have an institutional login. MediVault consumes it rather than creating another password for them to reuse.
- Protocols
- SAML 2.0 and OpenID Connect for authentication; SCIM 2.0 for automated user and group provisioning and deprovisioning.
- Identity providers
- Microsoft Entra ID, Okta, Keycloak, Ping and Swiss cantonal identity federations. On-premise Active Directory via a hardened connector.
- Multi-factor
- TOTP and FIDO2/WebAuthn hardware keys, enforced by policy. Where your IdP already enforces MFA, MediVault consumes the assertion rather than duplicating the prompt.
- Deprovisioning
- SCIM deactivation revokes every active session within 60 seconds. A clinician who leaves on Friday cannot read a record on Saturday.
- Service accounts
- Machine identities use short-lived mTLS certificates or OAuth 2.0 client credentials, scoped per integration and rotated automatically every 24 hours.
- Session policy
- Configurable idle timeout (default 30 minutes), absolute session cap, concurrent-session limits and step-up authentication for sensitive record classes.
Model your org chart
before you commit.
Send us your role structure and clinical governance policy. We will return a working MediVault policy set, with the access matrix mapped to your departments, at no cost and with no obligation.
Default policy sets ship pre-configured for Swiss clinical governance norms