Separate from the website
The patient application may handle identity, consent, notifications, referrals, and authorized health information. Its privacy notice must identify the relevant country institutions and legal roles.
Patient agency
The final notice will explain access, correction, consent, revocation, representatives, account closure, deletion requests, retention exceptions, complaints, and regulator contacts.
Minimum permissions
Device and data permissions must be limited to functions the patient uses, requested in context, and reconciled with Apple App Privacy and Google Play Data Safety declarations.
Not yet an effective notice
This framework is not a substitute for the country-specific, legally reviewed notice that will govern a production patient application.
