Governance & Audit ensures consent, auditability and access attestation across PHI and research paths — the layer compliance officers trust when investigating who touched which record.
Deny-by-default for research
Without explicit consent and policy approval, research exports do not proceed.
Could not build diagram for model "example-healthcare".
Append-only audit log for every data access.
Consent records and policy decisions.
Periodic access reviews for clinical roles.