HealthTAG / Trust & Access
Data custody, authorization และ audit แยกหน้าที่ออกจากกัน
โรงพยาบาลเป็นผู้ควบคุม clinical-data layer ขณะที่ HealthTAG เพิ่มกลไก identity, authorization และ audit รอบการแลกเปลี่ยนข้อมูล
ข้อมูลสุขภาพอยู่ที่ไหน
Clinical records อยู่ใน FHIR infrastructure ฝั่งโรงพยาบาล ไม่ได้ถูกเก็บเป็นเวชระเบียนบน blockchain
Access authorization
HealthTAG Module อยู่ใน network โรงพยาบาล และ authorization window ปัจจุบันมีอายุ 15 นาที
Immutable ledger
Blockchain ใช้บันทึก consent และ access events เป็นประวัติที่แก้ย้อนหลังได้ยาก ไม่ได้ใช้แทน authentication, encryption หรือ API security