Health system institutions and professionals may process the health data of their patients under the Act, specialised legislation and the Authority's rules issued with the health authority. Everyone involved is bound by confidentiality, complementing professional secrecy and surviving the end of their relationship, with appropriate technical and organisational security. Consent is not needed where processing is necessary for essential public interest in health or for public health (such as serious cross-border threats or high standards of care, medicines and devices) with specific safeguards. Minimum parameters: health data generated in health establishments are processed under confidentiality and professional secrecy with the patient's prior consent, except for vital interests or for preventive or occupational medicine, assessment of work capacity, diagnosis, care or management of health and social systems under specialised law or a contract with a health professional, in which case only a professional bound by secrecy, or someone under that professional's responsibility, may process them; health data are anonymised or pseudonymised whenever possible; and any processing of anonymised health data requires the Authority's prior authorisation, on a technical protocol and a favourable report of the health authority.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.