| Identity & contact |
User, VNeID/RAR, organization
|
Onboarding, authentication, communication
|
Authorized applications, IAM and workflows
|
Contract/policy-specific; deletion or restriction when
applicable
|
| Health data |
Patient, HIS, devices, applications
|
Care, monitoring, coordination |
Authorized care roles and integrations
|
Depends on record type and deployment policy
|
| Kiosk / device data |
D1078, D1007, DeviceKit |
Measurement session, quality, Observation
|
Kiosk, care team, integration |
Session/record policy with offline-queue cleanup
|
| Laboratory data |
LIS/lab workflows |
Order, specimen, QC, result |
Lab, clinician and patient according to authorization
|
Lab record and customer policy
|
| Imaging data |
PACS/DICOM |
Diagnosis, consultation, integration
|
Authorized roles |
Imaging retention and legal/operational holds
|
| TeleHealth data |
Appointment, uploads, consultation
|
Remote consultation and follow-up
|
Patient, clinician, care team |
Metadata/content per configuration and policy
|
|
Caregiver / delegated access
|
Delegation, task, consent |
Care on behalf of another person |
Caregiver and care team |
Delegation revocation/expiry is a key trigger
|
| Audit & evidence |
IAM, app, API, consent, device
|
Accountability, investigation, proof
|
Authorized security/compliance/admin roles
|
Separate audit/evidence retention policy
|