﻿# HAD Digital - Role-Permission Matrix

**Version:** 1.0.0  
**Date:** 5 September 2026  
**Clinical Owner:** Dr Kais Aldabbagh, Polyclinique St Come - Medical Oncology

---

## Overview

This document defines the access control matrix for HAD Digital. Each role has specific permissions for viewing and interacting with patient data, based on their relationship to the patient episode.

---

## Roles

| Role | Description | Typical Users |
|------|-------------|---------------|
| oncologist | Hospital oncologist / referring physician | Dr Martin, Dr Dupont |
| had_nurse | HAD coordinating nurse | Nurse Moret, Nurse Bernard |
| community_nurse | Community / HAD nurse | Nurse Leroy, Nurse Petit |
| gp | General practitioner | Dr Thomas, Dr Robert |
| pharmacist | Hospital / HAD pharmacist | Pharmacist Garcia |
| patient | Patient | Marie Durand, Pierre Martin |
| caregiver | Caregiver / family member | Family members |
| admin | System administrator | IT staff |

---

## Permission Matrix

### Patient Data

| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|------------|------------|-----------|-----------------|-----|------------|---------|-----------|-------|
| View patient list | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| View patient details | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| View patient demographics | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| View patient medical history | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| Edit patient information | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |

*patient and caregiver can only view their own data

---

### Toxicity Reports

| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|------------|------------|-----------|-----------------|-----|------------|---------|-----------|-------|
| Submit patient report | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ | ✓ | ✗ |
| Submit clinician observation | ✓ | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ |
| View all reports | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| View own reports | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| View assigned patient reports | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| Confirm grades | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |

*patient and caregiver can only view reports for their own episode

---

### CTCAE Grades

| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|------------|------------|-----------|-----------------|-----|------------|---------|-----------|-------|
| View all grades | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| View assigned patient grades | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| Confirm provisional grades | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
| Override automated grades | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |

*patient and caregiver can only view grades for their own episode

---

### Alerts

| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|------------|------------|-----------|-----------------|-----|------------|---------|-----------|-------|
| View all alerts | ✓ | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ |
| View assigned alerts | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| Acknowledge alerts | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| Escalate alerts | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Resolve alerts | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |

---

### Timeline

| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|------------|------------|-----------|-----------------|-----|------------|---------|-----------|-------|
| View all timeline events | ✓ | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ |
| View assigned patient timeline | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| Add timeline notes | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✗ | ✓ |

*patient and caregiver can only view timeline for their own episode

---

### Treatment Plans

| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|------------|------------|-----------|-----------------|-----|------------|---------|-----------|-------|
| View all treatment plans | ✓ | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ |
| View assigned patient plans | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| Create treatment plans | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
| Modify treatment plans | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |

*patient and caregiver can only view plans for their own episode

---

### Messages

| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|------------|------------|-----------|-----------------|-----|------------|---------|-----------|-------|
| Send direct messages | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| View all messages | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| View own messages | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| View assigned patient messages | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |

*patient and caregiver can only view messages for their own episode

---

### Export & Reports

| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|------------|------------|-----------|-----------------|-----|------------|---------|-----------|-------|
| Export toxicity summary | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| View audit log | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Generate clinical reports | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |

---

### System Administration

| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|------------|------------|-----------|-----------------|-----|------------|---------|-----------|-------|
| Manage users | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Manage roles | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| View system logs | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Configure system | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |

---

## Data Visibility Rules

### Episode-Based Access

1. **Oncologist:** Can see all patients assigned to them
2. **HAD Nurse:** Can see all patients in their HAD structure
3. **Community Nurse:** Can see patients assigned to them for home visits
4. **GP:** Can see patients who have designated them as their GP
5. **Pharmacist:** Can see patients with active treatment plans
6. **Patient:** Can see only their own data
7. **Caregiver:** Can see only the patient they are linked to
8. **Admin:** Can see all patients (for system administration)

### Data Minimization

1. **Minimum Necessary:** Each role sees only the data necessary for their function
2. **Purpose Limitation:** Data is used only for the purpose it was collected
3. **Access Logging:** All data access is logged in the audit trail
4. **Consent:** Patient consent is required for data sharing (implicit in HAD admission)

---

## Implementation Notes

### MVP Implementation

The MVP implements basic role-based access control:

1. **Authentication:** All users must log in with username/password
2. **Session Management:** Session cookies with 24-hour expiry
3. **Role Checking:** API endpoints check user role before processing
4. **Data Filtering:** Queries filter data based on user role and patient assignment

### Future Enhancements

1. **Fine-Grained Permissions:** Individual permission flags instead of role-based
2. **Episode-Based Access:** Dynamic access based on active episodes
3. **Consent Management:** Explicit patient consent for data sharing
4. **Audit Trail Enhancement:** Log all data access with timestamps
5. **Multi-Factor Authentication:** MFA for clinicians (required by spec)
6. **Session Timeout:** Configurable session timeout based on role

---

## Clinical Responsibility

**Important:** Access control does not replace clinical responsibility. Even with access to data, clinicians must:

1. **Verify patient identity** before discussing care
2. **Document clinical decisions** in the appropriate record
3. **Respect patient privacy** and confidentiality
4. **Follow institutional policies** for data sharing
5. **Report security incidents** immediately

---

## References

- GDPR Article 5(1)(c) - Data minimization
- French Data Protection Act (Loi Informatique et Libertés)
- CNIL Guidelines for Health Data
- French National Authority for Health (HAS) - HAD Standards
