Data categories
The platform may process organizational data, account data, staff and patient profiles, rehabilitation episodes, IRPs, tasks, questionnaires, self-reports, and action logs.
The platform may process organizational data, account data, staff and patient profiles, rehabilitation episodes, IRPs, tasks, questionnaires, self-reports, and action logs.
Access depends on the user role, organization, specific episode, professional assignment, and patient consent. Having an account does not mean global access to clinical data.
Organizations, staff, and patients join through controlled links or QR codes. Invitations expire, can be revoked, and are logged.
Consent decisions, token creation, access changes, emergency access, and sensitive clinical requests are recorded in the audit log.
A superadmin is a technical platform role and does not have routine clinical access. Exceptional access requires a separate break-glass flow with 2FA, a reason, justification, and audit logging.
Historical episode data remains part of a controlled rehabilitation context and does not become generally available to other organizations or staff without an appropriate basis.