雲端懷爾抓抓 · medcloud2-fhir-bridge

隱私權政策 Privacy Policy

Chrome 擴充功能的資料處理、保存與使用者選擇

最後更新:2026-08-01 生效日期:2026-07-31 版本:0.2.6

1. 適用範圍與單一用途

本政策適用於 Chrome 擴充功能「雲端懷爾抓抓(medcloud2-fhir-bridge)」。本擴充功能的單一用途,是協助依法且已獲授權的醫事人員,在健保醫療資訊雲端查詢系統(MediCloud)目前病人的情境中取得臨床參考資料,於使用者瀏覽器內轉換為 HL7 FHIR R4 Bundle,並由使用者下載或交給 MediPrisma 的瀏覽器本機匯入流程。

本擴充功能不是由衛生福利部中央健康保險署製作、授權或背書,也不會繞過或取代 MediCloud 的機構、醫事人員、讀卡、病人或其他驗證。

2. 本擴充功能處理的資料

在使用者明確啟動功能,且 MediCloud 已顯示目前病人時,本擴充功能依所需步驟處理:

本擴充功能不蒐集一般瀏覽紀錄、位置、付款資料、個人通訊、廣告識別碼、分析事件或跨網站追蹤資料。

3. 使用目的

上述資料只用於:

  1. 確認使用者目前操作的 MediCloud 病人。
  2. 取得使用者在該工作階段有權查看的臨床參考資料。
  3. 進行 schema、完整性、病人隔離與 FHIR reference 檢查。
  4. 在瀏覽器內轉換為 FHIR R4 Bundle。
  5. 依使用者選擇下載 FHIR JSON、下載原始回應,或交給 MediPrisma 的本機匯入流程。
  6. 顯示工作進度、錯誤與結果,並在期限到達時清除暫存。

資料不會用於廣告、行銷、資料仲介、信用評估、放款、建立使用者側寫,或與上述單一用途無關的模型訓練。

4. 資料來源與流向

MediCloud

資料來源為使用者已登入且有權查看的 https://medcloud2.nhi.gov.tw。驗證資訊不會回傳給 extension 背景程式、寫入 storage、放進下載檔、由 extension 記錄,或傳給 MediPrisma/發布者。MediCloud 可能依其規範保存使用者的查詢紀錄;該紀錄由 MediCloud/健保署管理,不提供給本 extension 發布者。

使用者下載

檔案下載後的保存、傳輸與刪除,由使用者及其所屬機構負責。

MediPrisma

使用者選擇 MediPrisma 時,本擴充功能會開啟或重用 https://mediprisma.tw/app/,把該次 FHIR Bundle 一次性交給該頁的瀏覽器本機檔案匯入元件。Bundle 不放入網址、查詢參數、hash、頁面 global 或可見 DOM 文字。若使用者之後在 MediPrisma 啟用 AI 或其他雲端功能,後續處理不再由本擴充功能控制,應以 MediPrisma 當時顯示的揭露與使用者所屬機構規範為準。

發布者與其他第三方

本擴充功能沒有發布者後端、分析工具、遙測、錯誤回報服務、廣告 SDK、追蹤像素或遠端程式碼。發布者不會透過本擴充功能接收病人資料、FHIR Bundle、RAW DATA、Bearer authorization 或使用紀錄。

5. 本機儲存與保存期間

本擴充功能不使用 chrome.storage.sync,不把資料同步到使用者的 Google 帳號。

6. 安全措施

沒有任何安全措施能保證零風險。使用者不得在未受控的共用電腦上處理病人資料,並應依所屬機構政策保護下載檔。

7. 使用者選擇與刪除

8. 兒童、臨床與法律限制

本擴充功能不是直接提供給兒童的一般消費者服務。具權限醫事人員可能依法在診療情境中處理未成年病人的資料,該處理仍受相同用途限制、安全措施、機構政策與適用法律規範。

MediCloud 資料與本擴充功能輸出均供臨床參考,不是診斷、治療建議或院內正式病歷。使用者應以官方來源、專業判斷及所屬機構的確認、簽章與病歷保存流程為準。

9. Chrome Web Store Limited Use

本擴充功能對使用者資料的使用遵守 Chrome Web Store User Data Policy,包括 Limited Use 要求。資料只用於提供或改善已揭露的單一用途;除政策允許且必要的情形外,不移轉、出售或供人員讀取,也不用於個人化廣告、資料仲介或信用評估。

The use of information received by this extension will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

10. 政策變更與聯絡方式

如資料類別、用途、分享對象、保存方式或權限有實質變更,發布者會在變更生效前更新本頁,並透過商店頁、extension 介面或其他適當方式醒目通知使用者並取得必要同意。

請勿在公開 issue、一般電子郵件或截圖中傳送真實姓名、身分證字號、生日、病歷、FHIR Bundle、RAW DATA、登入憑證或 token。

English Privacy Policy

1. Scope and single purpose

This policy applies to the Chrome extension medcloud2-fhir-bridge (雲端懷爾抓抓). Its single purpose is to help an authorized healthcare professional obtain clinical reference data for the patient currently displayed in Taiwan NHI MediCloud, convert that data locally in the user's browser into an HL7 FHIR R4 Bundle, and let the user download it or hand it to MediPrisma's browser-local import flow.

The extension is not produced, authorized, or endorsed by Taiwan's National Health Insurance Administration and does not bypass MediCloud authentication or access controls.

2. Data handled

After an explicit user action, the extension handles:

The extension does not collect general browsing history, location, payment data, personal communications, advertising identifiers, analytics events, or cross-site tracking data.

3. Use and sharing

Data is used only to verify the current patient, retrieve authorized MediCloud data, perform safety and FHIR validation, convert it to FHIR R4, display progress, remove expired results, and complete the user's selected download or MediPrisma import. It is not used for advertising, marketing, data brokerage, creditworthiness, lending, user profiling, or unrelated model training.

The publisher does not receive patient data, Bundles, raw responses, authorization values, or telemetry. The extension contains no publisher backend, analytics, advertising, tracking, error-reporting SDK, or remote code. MediCloud may retain the authorized user's query logs under its own policies; those logs are controlled by MediCloud/NHIA and are not provided to the extension publisher.

When the user chooses MediPrisma, the extension passes the Bundle once to the browser-local file-import control at https://mediprisma.tw/app/. The Bundle is not placed in a URL, query string, hash, page global, or visible DOM text. Any later use of an optional cloud or AI feature in MediPrisma is outside this extension's control and is subject to the disclosure shown by MediPrisma at that time and the user's organizational rules.

4. Local retention

Raw responses and authentication information remain only in short-lived execution memory. A completed FHIR Bundle may be staged in trusted-context-only chrome.storage.session, capped at 8 MiB and one hour. Download and confirmed MediPrisma import do not consume it; explicit user removal, replacement by a new job or patient switch, expiry, or browser-session end clears it. The extension does not use chrome.storage.sync.

Downloaded files are controlled by the user and their organization. The publisher cannot access or delete them.

5. Security and user choices

The extension uses exact host permissions, HTTPS, repeated patient-context checks, short-lived state, restricted session storage, packaged code only, and a narrow MediPrisma handoff context. Users may choose not to start capture, not to use MediPrisma, not to download a file, or to remove the extension.

6. Children and clinical limitation

The extension is not a general consumer service directed to children. Authorized healthcare professionals may handle a minor patient's data in a lawful clinical context, subject to the same purpose limitations, safeguards, organizational policies, and applicable law.

MediCloud data and the extension's output are clinical reference information, not a diagnosis, treatment recommendation, or official medical record. Users must follow authoritative sources, professional judgment, and their organization's approval, confirmation, signature, and retention processes.

7. Limited Use

The use of information received by this extension will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

User data is used only for the disclosed single purpose and is not sold, used for personalized advertising, provided to data brokers, or used for creditworthiness or lending.

8. Changes and contact

Material changes to data handling will be prominently disclosed before they take effect, with additional consent where required. They will not be disclosed only by silently editing this policy.

Never submit real patient records, full identifiers, FHIR Bundles, raw data, credentials, tokens, or unredacted screenshots through a public issue.