# Privacy

**Portal version:** 0.1.0  
**Updated:** 2026-08-28  
**Source menu item:** Privacy  
**Availability:** Documented and testable

> The source contract and local workflow exist. Access still depends on the target hospital deployment and its policy gates.

Every app handoff documents clinical purpose, data flow, scope, privacy, operations, retention, and support before hospital review.

## What you can use now

- Minimize fields, keep PHI out of logs/evidence, define processors and residency, and document deletion/revocation behavior.
- Recheck authorization at each context disclosure.

## Current limits

- A published privacy notice does not replace a hospital data-processing and clinical-purpose decision.

## Next step

Start with the [medOS Developer overview](/developers/platform/overview) and confirm the target hospital’s enabled contracts before production work.

## Canonical references

- [FHIR R4 integration](/integrations/fhir)
- [Public API](/backend/public-api)
- [Security and compliance](/architecture/security-and-compliance)
- [Developer portal status and coverage](/developers/platform/changelog)

