MaxArc Global Health Impact Platform

Restricted Patient Locator & Authorized Search

Restricted · Authorized personnel only · Not a public locator

Locate continuity records only when authorized, consented, and audited.

A highly restricted, privacy-preserving locator for authorized health personnel — never a public search, never anonymous, never surveillance. Every request needs an authorized role, a valid purpose, and consent or documented lawful authority. Disclosure is minimum-necessary and time-limited, denials never reveal whether a record exists, and emergency break-glass access is exceptional, documented, and reviewed. AI scores matches and flags risk; authorized humans decide.

You are viewing the Restricted Patient Locator & Authorized Search Dashboard
Authorization & privacy posture: Access is never public or anonymous. An authorized role with a valid stated purpose and consent or documented lawful authority is required. Only the minimum-necessary result scope is disclosed. High-risk and sensitive requests require escalation and second approval. Denied requests never reveal whether a patient record exists. Precise location is never disclosed unless explicitly authorized. Emergency (break-glass) access is exceptional, documented, time-limited, and fully audited. All patient references are masked synthetic tokens. No identifiable data is stored or disclosed. Retention is limited to auditable request metadata; disclosures are minimized and time-limited. This is not a public locator, not surveillance, and not a full EHR.
Locator requests 5

Total authorized-search attempts

Approved searches 2

Restricted, minimum-necessary

Denied requests 2

Existence never revealed

Pending second review 2

Sensitive / ambiguous

Consent exceptions 2

Requiring human review

High-risk attempts 2

Escalated for review

Cross-facility matches 4

AI-scored candidates

Identity ambiguity 2

Unresolved match candidates

Disclosure events 2

Time-limited, minimum-necessary

Open escalations 2

Awaiting privacy review

Audit completion 100%

Requests with audit events

AI risk signals 4

Human decision required

Locator requests

No public or anonymous search. Each request carries an authorized role, stated purpose, consent/authority, and an access decision.

RequestRequesting org / facilityRolePurposeConsentDecision
LOC-6001
PT-MASK-A1
District Referral Hospital Network
District Referral Hospital
tb-program-officer continuity of care consent on file approved
LOC-6002
PT-MASK-B2
Partner NGO - Continuity Program
Hilltop Community Clinic
hiv-continuity-nurse continuity of care consent on file pending-second-review 2nd review
LOC-6003
PT-MASK-C3
Partner NGO - Continuity Program
Hilltop Community Clinic
field-outreach-worker locate for outreach not on file denied
LOC-6004
PT-MASK-D4
District Referral Hospital Network
District Referral Hospital
emergency-clinician emergency care unable to obtain emergency approved-emergency 2nd review escalate
LOC-6005
PT-MASK-E5
Ministry of Health - Eastern
Riverside Health Center
unverified-account bulk lookup not on file denied escalate

Possible cross-facility matches

AI scores identity-match confidence and surfaces candidates; a human always confirms before any disclosure.

RequestMasked refCandidate facilityConfidenceAmbiguityConfirmation
LOC-6001 PT-MASK-A1 District Referral Hospital 94% clear human confirms
LOC-6002 PT-MASK-B2 Riverside Health Center 71% ambiguous human confirms
LOC-6002 PT-MASK-B2 Hilltop Community Clinic 69% ambiguous human confirms
LOC-6004 PT-MASK-D4 District Referral Hospital 88% clear human confirms

Access decisions

RequestDecisionDecided byPurposeDisclosureSecond approver
LOC-6001 approved facility-privacy-officer continuity of care min-necessary
LOC-6002 pending-second-review facility-privacy-officer continuity of care min-necessary program-privacy-lead
LOC-6003 denied facility-privacy-officer locate for outreach min-necessary
LOC-6004 approved-emergency emergency-clinician emergency care min-necessary clinical-privacy-lead
LOC-6005 denied program-privacy-lead bulk lookup min-necessary

Disclosure events

Only minimum-necessary scope is disclosed; precise location is never disclosed unless explicitly authorized, and disclosures are time-limited.

RequestScope disclosedPrecise locationTime-limited
LOC-6001 care facility and active case only no precise location time-limited
LOC-6004 active clinical alerts and facility no precise location time-limited

Denied requests

  • LOC-6003 — no consent or lawful authority. Request cannot be fulfilled. No information about the existence of any record is disclosed. existence not revealed
  • LOC-6005 — high risk access pattern and no authority. Request denied and escalated. No information about the existence of any record is disclosed. existence not revealed

Consent exceptions requiring review

  • LOC-6002 — identity ambiguity before disclosure (program-privacy-lead) open
  • LOC-6004 — break glass post access consent review (clinical-privacy-lead) open

Emergency (break-glass) access

  • LOC-6004 — break-glass yes, time-limited 60 min, post-access review required, documented yes.

Escalations

  • clinical privacy lead — break-glass emergency access requires post-access review open
  • security privacy officer — suspected excessive/bulk lookup from unverified account open

Access decisions by role

  • tb-program-officer 1
  • hiv-continuity-nurse 1
  • field-outreach-worker 1
  • emergency-clinician 1
  • unverified-account 1

Access decisions by purpose

  • continuity of care 2
  • locate for outreach 1
  • emergency care 1
  • bulk lookup 1

AI-assisted match & risk signals

  • excessive search behavior — Unverified account attempting bulk lookup without authority Next: deny, escalate to security-privacy-officer, review account. human decision required
  • identity ambiguity — Two facility match candidates with close confidence; disclosure withheld pending second review Next: authorized reviewer disambiguates before any disclosure. human decision required
  • no consent access attempt — Outreach locate attempt without consent or lawful authority Next: deny; do not reveal record existence. human decision required
  • break glass access — Emergency break-glass access granted; time-limited and pending post-access review Next: complete post-access consent and compliance review. human decision required

AI posture

AI assists with

  • identify likely cross-facility matches
  • score identity-match confidence
  • detect duplicate or conflicting records
  • flag suspicious access patterns
  • identify excessive search behavior
  • recommend minimum-necessary result scope
  • support authorized reviewer triage

AI must never

  • autonomously approve access
  • autonomously disclose identity or location
  • override consent or legal requirements
  • reveal whether a record exists after denial
  • autonomously merge patient records
  • autonomously close audit or compliance reviews

AI supports restricted locator review: it scores identity-match confidence, surfaces likely cross-facility matches, detects duplicate/conflicting records, flags suspicious or excessive access, and recommends minimum-necessary scope. AI never approves access, discloses identity or location, overrides consent or law, reveals record existence after denial, merges records, or closes audit/compliance reviews on its own.

Runtime boundary & linkage

  • Impact runtime: impact.maxarchealth.com on 127.0.0.1:3201.
  • Medical Library boundary remains separate at library.maxarchealth.com (port 3101) and is not used here.
  • MaxTrax EHR remains separate; this is not a full EHR and does not couple repositories.
  • Linked to patient continuity (Task-005) without coupling to MaxTrax EHR.
  • Legacy policy route /restricted-locator-policies remains available and unchanged.