Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

TRUST

Consent

Represent consent as a versioned, purpose- and scope-aware state that can be evaluated by applications and integrations at decision time.

Owner
Privacy & Identity Governance
Scope
Consent-controlled data use and sharing
Status
Published control statement
01 / CONTROL

Control model

01

Scope

Subject, purpose, data category, recipient/role and validity period can constrain authorization.

02

Lifecycle

Capture, activation, renewal, withdrawal and expiry are explicit states.

03

Enforcement

Current consent is evaluated together with role/policy rather than treated as a static checkbox.

04

Evidence

Version, actor/channel, timestamp, policy context and resulting state are retained where required.

02 / BOUNDARY

Responsibility boundary

Withdrawal affects future authorization decisions; historical evidence may remain where retention/accountability policy requires it.

03 / ESCALATION

Evidence and escalation

Consent disputes or corrections should include the affected service/context and consent event without exposing unrelated health information.

CONSENT RECORD

Consent is a versioned authorization context

A useful consent record answers who granted what, for which purpose, to which recipient, for how long and under which policy/version. It also preserves later revocation or supersession.

01

Grantor & authority

Identify the person granting consent and, for caregiver/delegated scenarios, the authority/relationship under which they act.

02

Scope & purpose

Record data/resource categories, intended purpose, recipient/controller context and any restrictions—not only a yes/no flag.

03

Duration & version

Preserve grant time, effective period, policy/notice version and the evidence shown at the decision point.

04

Revocation

Make withdrawal/supersession effective prospectively, preserve historical evidence and communicate the changed state to dependent workflows.

CONSENT LIFECYCLE

From request to withdrawal without losing evidence

Every transition is visible to the user and to systems that depend on the permission state.

RequestPresent purpose, data scope, recipient, duration and consequences in the user’s context.
Verify authorityConfirm patient/caregiver/delegate identity and relationship as required.
DecisionCapture grant/deny with policy version and timestamp.
UseExpose the active permission state to authorized workflow/API decisions.
ChangeAllow scoped update or revocation; do not overwrite the historical decision.
Propagate & auditNotify dependent services and correlate state changes with access/audit evidence.
METRO INFORMATION DESIGN

Connected flow with explicit decisions and evidence

consent lifecycle
REST · FHIR · OAuth/OIDC · Event · Webhook · Evidence
Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access