# HAD Digital - Role-Permission Matrix
Version: 1.0.0 Date: 5 September 2026 Clinical Owner: Dr Kais Aldabbagh, Polyclinique St Come - Medical Oncology
Overview
This document defines the access control matrix for HAD Digital. Each role has specific permissions for viewing and interacting with patient data, based on their relationship to the patient episode.
Roles
| Role | Description | Typical Users |
|---|---|---|
| oncologist | Hospital oncologist / referring physician | Dr Martin, Dr Dupont |
| had_nurse | HAD coordinating nurse | Nurse Moret, Nurse Bernard |
| community_nurse | Community / HAD nurse | Nurse Leroy, Nurse Petit |
| gp | General practitioner | Dr Thomas, Dr Robert |
| pharmacist | Hospital / HAD pharmacist | Pharmacist Garcia |
| patient | Patient | Marie Durand, Pierre Martin |
| caregiver | Caregiver / family member | Family members |
| admin | System administrator | IT staff |
Permission Matrix
Patient Data
| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|---|---|---|---|---|---|---|---|---|
| View patient list | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| View patient details | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| View patient demographics | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| View patient medical history | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| Edit patient information | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
*patient and caregiver can only view their own data
Toxicity Reports
| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|---|---|---|---|---|---|---|---|---|
| Submit patient report | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ | ✓ | ✗ |
| Submit clinician observation | ✓ | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ |
| View all reports | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| View own reports | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| View assigned patient reports | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| Confirm grades | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
*patient and caregiver can only view reports for their own episode
CTCAE Grades
| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|---|---|---|---|---|---|---|---|---|
| View all grades | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| View assigned patient grades | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| Confirm provisional grades | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
| Override automated grades | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
*patient and caregiver can only view grades for their own episode
Alerts
| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|---|---|---|---|---|---|---|---|---|
| View all alerts | ✓ | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ |
| View assigned alerts | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| Acknowledge alerts | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| Escalate alerts | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Resolve alerts | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
Timeline
| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|---|---|---|---|---|---|---|---|---|
| View all timeline events | ✓ | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ |
| View assigned patient timeline | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| Add timeline notes | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✗ | ✓ |
*patient and caregiver can only view timeline for their own episode
Treatment Plans
| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|---|---|---|---|---|---|---|---|---|
| View all treatment plans | ✓ | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ |
| View assigned patient plans | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
| Create treatment plans | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
| Modify treatment plans | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
*patient and caregiver can only view plans for their own episode
Messages
| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|---|---|---|---|---|---|---|---|---|
| Send direct messages | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| View all messages | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| View own messages | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| View assigned patient messages | ✓ | ✓ | ✓ | ✓ | ✓ | ✓* | ✓* | ✓ |
*patient and caregiver can only view messages for their own episode
Export & Reports
| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|---|---|---|---|---|---|---|---|---|
| Export toxicity summary | ✓ | ✓ | ✓ | ✓ | ✓ | ✗ | ✗ | ✓ |
| View audit log | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Generate clinical reports | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
System Administration
| Permission | oncologist | had_nurse | community_nurse | gp | pharmacist | patient | caregiver | admin |
|---|---|---|---|---|---|---|---|---|
| Manage users | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Manage roles | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| View system logs | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Configure system | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
Data Visibility Rules
Episode-Based Access
- Oncologist: Can see all patients assigned to them
- HAD Nurse: Can see all patients in their HAD structure
- Community Nurse: Can see patients assigned to them for home visits
- GP: Can see patients who have designated them as their GP
- Pharmacist: Can see patients with active treatment plans
- Patient: Can see only their own data
- Caregiver: Can see only the patient they are linked to
- Admin: Can see all patients (for system administration)
Data Minimization
- Minimum Necessary: Each role sees only the data necessary for their function
- Purpose Limitation: Data is used only for the purpose it was collected
- Access Logging: All data access is logged in the audit trail
- Consent: Patient consent is required for data sharing (implicit in HAD admission)
Implementation Notes
MVP Implementation
The MVP implements basic role-based access control:
- Authentication: All users must log in with username/password
- Session Management: Session cookies with 24-hour expiry
- Role Checking: API endpoints check user role before processing
- Data Filtering: Queries filter data based on user role and patient assignment
Future Enhancements
- Fine-Grained Permissions: Individual permission flags instead of role-based
- Episode-Based Access: Dynamic access based on active episodes
- Consent Management: Explicit patient consent for data sharing
- Audit Trail Enhancement: Log all data access with timestamps
- Multi-Factor Authentication: MFA for clinicians (required by spec)
- Session Timeout: Configurable session timeout based on role
Clinical Responsibility
Important: Access control does not replace clinical responsibility. Even with access to data, clinicians must:
- Verify patient identity before discussing care
- Document clinical decisions in the appropriate record
- Respect patient privacy and confidentiality
- Follow institutional policies for data sharing
- Report security incidents immediately
References
- GDPR Article 5(1)(c) - Data minimization
- French Data Protection Act (Loi Informatique et Libertés)
- CNIL Guidelines for Health Data
- French National Authority for Health (HAS) - HAD Standards