- Patient, representative, encounter, and consent
- Verify identity before disclosure or action, preserve demographic history and duplicate review, bind records and work to the correct encounter and purpose, verify representative authority, record applicable consent and communication choice, provide correction paths, and prevent cross-patient or cross-tenant access.
- Source provenance, version, and display
- Preserve originals and digests, author and organization, event and collection time, patient and encounter, preliminary or final status, correction and supersession, intended use and sensitivity; display source and age near derived values; and block stale or conflicting evidence from disappearing in summaries.
- Privacy, security, suppliers, and records
- Confirm legal and contractual scope, minimize data, apply least privilege, separate duties, protect data in transit and at rest, govern suppliers and subcontractors, log access and disclosure, test recovery and incident response, preserve patient rights and corrections, and enforce retention and disposal.
- Clinical authority and software-function boundary
- Define intended use, users, patient population, inputs, outputs and exclusions; determine applicable medical-device or other regulation with qualified owners; preserve source inspection and independent judgment; validate in context; monitor performance and harm; and reserve diagnosis, treatment, orders, advice and urgent action for authorized roles.
- Orders, referrals, results, and communication
- Assign accountable owners and backups, set risk-based due conditions, show the current record, require acknowledgement and qualified review, preserve rationale and authorized action, verify patient and care-team communication, escalate failed contact or overdue work, and close only on defined follow-up evidence.
- Downtime, recovery, change, and safety review
- Maintain safe minimum records and manual procedures, protect access during outage, prevent duplicate actions, record work and decisions, reconcile on restoration, test rollback, revalidate material workflow or model changes, investigate incidents and complaints, preserve corrections, and retire unsafe or unsupported functions.