Govern
Governance
Roles, policies, consent, classification, retention, MDM rules and approval workflows.
Roles
RBAC, scope, members
Access policies
ABAC + RBAC rules
Consent rules
Treatment, research, marketing
Classification
PHI, PII, Confidential
Retention
Retention & legal holds
Approval workflows
Multi-step approvals
Active policies
- HIPAA Minimum NecessaryPrivacy100%Active
- Zero Trust Network AccessSecurity98%Active
- PHI in Email — Block & QuarantineDLP100%Active
- Research Consent RequiredConsent92%Active
- Retention 7y — EncountersRetention100%Active
- MDM Match Threshold ≥ 0.92MDM100%Active
Roles
RBAC defined for the MVP
- ExecutiveScoped
- Compliance OfficerScoped
- Data StewardScoped
- ClinicianPHI: assigned patients
- AnalystDe-identified by default
- AdminFull access
- AuditorRead-only + audit