Medicilio RPM
Remote Patient Monitoring software — Patient Manual
| Symbol | Particular | Value |
|---|---|---|
| Manufacturer | Manufacturer | Cantieri Digitali Medtech S.r.l., Corso di Porta Romana 6, 20122 Milano (IT), VAT/P.IVA IT11328810962 |
| Caution | Consult the Instructions for Use | This document |
| UDI | UDI-DI | [UDI-DI placeholder to be assigned before placing on market] |
| MD | Device category | Medical Device: Class IIa software (MDSW) |
| REF | Trade name | Medicilio RPM |
| Version | Software version | 1.0.0 |
| CE | CE mark | [CE-NUMBER placeholder] · Notified Body: [NB-NUMBER placeholder] |
| Date | Date of issue | 2026-09-07 |
| eIFU | Electronic IFU | Available at https://ifu.medicilio.it per Regulation (EU) 2021/2226 |
EU MDR 2017/745 · Class IIa Medical Device Software (MDSW)
Software version 1.0.0 · Date of issue 2026-09-07
Cantieri Digitali Medtech S.r.l. · Corso di Porta Romana 6, 20122 Milano (IT)
Medicilio RPM is a software medical device intended for the remote monitoring of patients enrolled in a clinician-prescribed care pathway. It collects measurements from compatible connected medical devices and from manual patient input, evaluates each measurement against clinician-set thresholds, raises alerts when thresholds are breached, and supports clinicians in producing AI-assisted telemonitoring reports that they must review and sign before any report is released to the patient.
Medicilio RPM is qualified as Medical Device Software (MDSW) per MDCG 2019-11 and is classified as Class IIa under EU Regulation 2017/745 (MDR).
This document is the Instructions for Use (IFU) for Medicilio RPM. It combines the regulatory IFU content required by Annex I §23 of the MDR with the operational depth required by the intended users to operate the device safely.
Medicilio RPM is delivered as two end-user applications that connect to the manufacturer's cloud back end:
| Component | Required platform | Notes |
|---|---|---|
| Clinician / operator web application | Modern evergreen web browser supporting current Chrome, Firefox, Edge or Safari (latest two major versions) | React 18 single-page application; minimum screen resolution 1280×800. |
| Patient application | Delivered preinstalled on a Medicilio-provided Lenovo Tab M11 tablet (MediaTek Helio G88; 4 GB or 8 GB RAM; 64 GB or 128 GB storage; Android 13 with manufacturer-supported upgrades and security patches at least until January 2028), locked by a Mobile Device Management (MDM) tool to run only the Medicilio application. See §6.2. | |
| Network : clinician web | Stable broadband (≥10 Mbps download / ≥2 Mbps upload), HTTPS to manufacturer cloud and to video provider | Required for video consultations |
| Network : patient mobile | Mobile data or Wi-Fi (≥5 Mbps recommended), HTTPS | Required to upload measurements and to receive notifications |
| Account | Personal account, provisioned by an authorised role | See §7 |
| Time | Device time set automatically via OS network time | Manual time skew may cause incorrect activity scheduling |
The "label" of a software medical device is the in-app device-identification screen, which carries the device identification per §23.2 and §23.4(a). In the patient application it is the foot of the Profile screen, below Logout: it states that Medicilio RPM is a medical device, with the software version, the release date and the device UDI, and carries a link to these Instructions for Use.
The Medicilio cloud back end is hosted on Google Cloud in the EU region (Belgium, Frankfurt and Milan). All clinical data remains in the EU.
Cantieri Digitali Medtech S.r.l. Corso di Porta Romana 6 20122 Milano (MI), Italy VAT / P.IVA IT11328810962
| Channel | Contact |
|---|---|
| Support email | info@medicilio.it |
| Support telephone | +39 0238592673 |
| Support hours | Lun–Ven 8:00–20:00, Sab 9:00–13:00 Europe/Rome |
| In-app chat (Medicilio Customer Support) | "Supporto di Medicilio" channel inside the patient app and clinician web app. |
Feedback on these Instructions for Use, or on the device, may be sent to info@medicilio.it. Feedback is not a substitute for the serious-incident reporting procedure described in §15.
These Instructions for Use are delivered electronically as permitted by Regulation (EU) 2021/2226. A printed copy is available, at no charge, within 7 calendar days of a written request sent to the support email above.
You can also open the current Instructions for Use from inside the app, using the link at the foot of the Profile screen. The link always opens the current patient edition.
The following symbols are used on the cover page and throughout this document, in accordance with ISO 15223-1:2021. Where a harmonised symbol does not apply, a description is provided in this section.
| Symbol | ISO 15223-1 reference | Meaning |
|---|---|---|
| Manufacturer | §5.1.1 | Identifies the manufacturer of the medical device |
| Date | §5.1.3 | 2025 |
| SN | §5.4.1 | Medicilio RPM v1.6 |
| Caution | §5.4.4 | Consult the Instructions for Use |
| eIFU | §5.4.3 | Electronic Instructions for Use indicator |
| MD | §5.7.10 | Identifies a medical device |
| UDI | §5.7.7 | Unique Device Identifier |
| Translated eIFU | §5.7.8 | Electronic Instructions for Use indicator in Italian |
| CE | (EU MDR) | The device complies with applicable EU regulations |
The IFU also uses four in-text callouts to draw attention to information of different criticality:
Information about a hazard that, if ignored, may lead to patient harm, clinically incorrect decisions, or device misuse.
Information whose disregard may degrade device performance or cause an avoidable workflow failure, without immediate patient harm.
Operational context that helps the user act correctly.
Optional guidance to use the device more effectively.
The following warnings apply to all users of the device.
Medicilio RPM is intended for the asynchronous remote monitoring of patients in stable clinical conditions. It must not be used for medical emergencies, real-time monitoring, ICU or perioperative monitoring, continuous in-person observation, or any clinical situation requiring an immediate response. In a suspected emergency, the patient or user must call the applicable emergency number (in Italy: 112) and must not rely on Medicilio, its alerts, chat, notifications, or messages.
Medicilio RPM is intended for adult patients. Do not use the device for patients outside the intended population, or for patients unable to understand or operate the patient-facing application, unless a designated caregiver is available and use has been assessed and authorized by the responsible healthcare organization.
Medicilio RPM displays measurements, computes threshold breaches and drafts telemonitoring reports as decision support for qualified healthcare professionals. It does not replace clinical judgement. All clinical decisions, including modifications to therapy or escalation, must be made by a qualified clinician.
Only measurements obtained with the compatible medical devices listed in §6 may be relied on as clinical data. Measurements entered manually by the patient are recorded with an explicit manual data source and are not equivalent to a verified Class IIa measurement.
Each Medicilio account is personal. Users must not share login credentials or one-time passwords. A pathway must not be activated for a patient other than the one identified in the patient record.
Patients and healthcare professionals must distinguish clinical communications from administrative messages, automated notifications, and non-clinical support communications. Administrative, automated, or support-channel communications must not be interpreted as individualized clinical advice unless clearly identified as such by the responsible healthcare professional. Clinically relevant exchanges in chat must be summarized in the patient's clinical record according to the healthcare organization's procedure.
Messages exchanged in the Supporto Medico Dottore chat are a communication channel, not a substitute for medical advice or a clinical consultation. Patients must not rely on chat messages in place of contacting their clinician directly or, in an emergency, the applicable emergency number (in Italy: 112). Clinically relevant exchanges are summarised by the clinician in the patient's pathway notes.
Using the device outside its intended use, environment, or user profile described in this section may invalidate the intended performance and may put the patient at risk.
Medicilio RPM : Remote Patient Monitoring software, software version 1.0.0.
Medicilio RPM is a medical device software platform intended for remote monitoring of adult patients by receiving, transmitting, storing, and presenting physiological parameter measurements from compatible connected devices and patient-reported data entered by the patient, to support healthcare professionals in clinical follow-up and chronic disease management.
Medicilio RPM includes an AI-assisted report generation function that produces draft summaries of patient data for review by a healthcare professional.
Medicilio RPM does not itself perform physiological measurements; physiological measurements are provided by the connected devices.
Medicilio RPM addresses two target client populations: (1) healthcare provider organisations (hospitals, clinics, independent practices) that prescribe and operate the pathway, and (2) patients assigned to a pathway.
Within each client, the device has the following intended users.
| Field | Value |
|---|---|
| Type | Lay user : adult patient responsible for entering patient-reported data and viewing their own data via the patient interface |
| Age | Adult (≥18) |
| Level of instructions | Lay person; no prior clinical training assumed |
| User training | Reads this IFU and completes the in-app onboarding tutorial; receives a telephone briefing from the Medicilio Customer Support upon kit delivery |
| Interface | Patient mobile application |
Medicilio RPM is operated in two environments:
The device is not intended to be used in operating theatres, intensive care units, or in any environment where life-supporting decisions must be made in real time.
Adult patients (18 years of age and older) requiring remote monitoring as part of clinical follow-up or chronic disease management. Patients must be able to use the mobile application, or have a designated caregiver acting on their behalf, and must have been prescribed a remote-monitoring pathway by an authorised clinician.
Candidate clinical benefits:
Medicilio RPM is not a measuring device in itself: it records, evaluates and presents measurements taken by compatible connected medical devices listed in §6, each carrying its own CE marking and its own accuracy specification. The performance characteristics of Medicilio RPM are:
Who can perform this action (associating devices to a pathway): Department Doctor, Independent Practice Doctor, Department Doctor Head, Medicilio Customer Support, Ops.
Medicilio RPM is used with a configured patient home kit. The devices included depend on the monitoring pathway prescribed to the patient.
Each device has its own Instructions for Use. The user must follow the device manufacturer's IFU for setup, positioning, cleaning, calibration, battery handling, warnings, contraindications, and maintenance.
| Category | Regulatory framework | Treatment in Medicilio RPM |
|---|---|---|
| EU MDR medical devices : predominantly Class IIa, with one Class I device (Omron VIVA) (§6.1) | Regulation (EU) 2017/745 (some devices under MDR Article 120 transition from MDD 93/42/EEC) | Measurements are ingested as clinical data and evaluated against per-pathway thresholds. |
| EU IVDD / IVDR in-vitro diagnostic device (§6.1) | Directive 98/79/EC (IVDD) / Regulation (EU) 2017/746 (IVDR) | Measurements are ingested by Medicilio RPM as clinical data and evaluated against per-pathway thresholds. |
| Non-medical wellness devices (§6.1) | Not regulated as medical devices | Some parameters (body weight, step count, heart rate) may be ingested by Medicilio RPM but are not equivalent to clinical-device measurements. See the warning in §6.1.3 |
For correct positioning, cleaning, calibration, battery handling, warnings and contraindications of each device, consult the IFU supplied by the device manufacturer. The Medicilio RPM Instructions for Use do not replace those documents.
Medicilio RPM connects to CE-marked medical devices, predominantly Class IIa (with the possible exception of Class I devices, e.g. body-composition scales), across the following categories:
Each device retains its own CE marking, accuracy specification, and manufacturer's Instructions for Use, which must be followed for setup, positioning, cleaning, calibration, battery handling, warnings, contraindications, and maintenance (see the IMPORTANT note below).
The current list of compatible devices is kept updated and is available to users upon request by contacting Medicilio support (see §2.2).
Each accessory has its own Instructions for Use.
Medicilio RPM may also ingest data from non-medical wellness devices in the following categories: smartwatches (step count, heart rate) and body-composition scales. These devices are not regulated as medical devices; their manufacturers explicitly declare this, and their accuracy claims (where present) are wellness-grade, not clinical-grade. The specific models currently in use are available upon request by contacting Medicilio support (see §2.2).
Medicilio RPM ingests body weight, step count and heart rate from non-medical wellness devices such as smartwatches and body-composition scales. The manufacturers of these devices have explicitly declared that they are not medical devices. Their accuracy claims, when present, are wellness-grade and do not satisfy the performance requirements of EU MDR Class IIa measurement. Clinicians must treat these readings as informative wellness data only. They must not be used as the sole basis for any clinical decision and must not be treated as equivalent to a measurement obtained with one of the Class IIa devices listed in §6.1.1.
The patient receives, as part of the home kit, a tablet on which the Medicilio patient application is preinstalled. The tablet is locked by a Mobile Device Management (MDM) tool so that only the Medicilio application can run on it; navigation outside the app, installation of other applications, and access to the operating system are not permitted.
| Field | Value |
|---|---|
| Brand and model | Lenovo Tab M11. |
| Processor | MediaTek Helio G88 Octa-core (2× Arm Cortex-A75 @ 2.0 GHz + 6× A55 @ 1.8 GHz); Arm Mali-G52 MC2 GPU |
| Memory | 4 GB or 8 GB LPDDR4x (soldered, not upgradable) |
| Storage | 64 GB or 128 GB eMMC 5.1; microSD card slot up to 1 TB (exFAT) |
| Operating system | Android 13 at delivery, with manufacturer-supported OS upgrades to Android 15 and security patches at least until January 2028 (per Lenovo PSREF) |
| Connectivity | Wi-Fi (WLAN model) or Wi-Fi + cellular nano-SIM (WWAN model); Bluetooth; USB-C 2.0 |
| SIM | SIM card with dedicated data plan, supplied in the home kit on WWAN variants. |
| Provided to | The patient, for the duration of the pathway only |
| Permitted use | Solely for the prescribed monitoring activities described in §8 |
| End of pathway | The tablet must be returned to Medicilio together with the rest of the home kit. See §16.1. |
You can lock the tablet's screen at any time, so that it does not disturb you at night. The tablet cannot be switched off: it needs to stay on so that your activities, notifications and measurements keep working. Leave it connected to its charger.
Attempts to bypass the MDM lock, install third-party applications, change network settings, or use the tablet for any purpose other than the prescribed monitoring invalidate the intended performance and may interrupt monitoring. Report any tablet fault to the Medicilio Customer Support (see §2.2) rather than attempting to repair it.
Medicilio RPM supports the following measurement types:
Medicilio RPM uses passwordless authentication via one-time password (OTP) sent by email. There is no permanent password to remember.
If you do not receive the OTP within a few minutes, check the spam folder of your email account. Do not request multiple OTPs in rapid succession; only the latest one is valid.
The Medicilio Customer Support verifies your identity by phone (e.g. tax code, date of birth) before your pathway is activated.
Open the profile screen and select Esci.
Sessions expire automatically after a period of inactivity:
30 days for the patient, on the Medicilio-provided MDM-locked tablet (see §6.2);
Closing the mobile app does not, by itself, terminate the session, explicit logout is required to terminate the session on demand.
The patient operates Medicilio RPM exclusively from the MDM-locked tablet supplied in the home kit (see §7.2). Once the pathway is active, the app presents the activities scheduled for the day, ordered by how soon they must be done.
Activities include:
Where an activity has a recommended time, that time belongs to one of three slots, always shown with its hours: Morning 05:00–12:00, Afternoon 12:00–18:00, Evening 18:00–24:00. Whatever the activity, the day closes at 23:59:59 and nothing can be recorded for that day afterwards.
Your clinician decides, for each measurement, whether its timing matters clinically:
Questionnaires have no time slot at all: you can complete them at any point in the day.
If you take a medication but cannot record it straight away, for example because you are away from the tablet, you can still record it later the same day. You are asked which part of the day you took it in. See §8.5.
The first screen on the tablet shows the Today view. It is split into two zones.
The top zone stays in place while the rest of the screen scrolls. It carries a small number of summary cards, each of which opens a panel with more detail when tapped:
The lower zone scrolls and contains, in order:
Each activity shows its name, its recommended time, and its current state.
If a scheduled activity (measurement, drug intake, questionnaire) is not completed within its time window, the app sends a reminder notification.
Device-specific notes and tutorial videos
Manual entry must be used only when a connected device is not available or has failed. Manual values are not equivalent to a verified measurement from a compatible medical device and may be excluded from clinical decision-making by the clinician.
Peak flow cannot be entered manually. The reading reaches your care team only from the device.
A medication can be recorded until 23:59:59 of the day it was due. If nothing is recorded by then, it is closed as not recorded. Your care team sees this as distinct from a dose declared as not taken.
Once you confirm a medication as taken, the record is sent to your care team and cannot be corrected from the app. Before confirming, check that you have chosen the right part of the day. If you realise afterwards that you recorded something incorrectly, tell your care team through the in-app chat (see §10.4).
When you are asked who took a measurement and you answer that it was somebody else, the reading is not filed as yours: your care team does not see it in your history, your trends or your reports. The activity stays open so you can still measure yourself.
Values you enter manually, questionnaire answers, and symptom descriptions may be reviewed and verified by your care team before any clinical decision is made based on them.
If a measurement result requires attention, you will receive a push and in-app notification prompting you to repeat the measurement, and see a Re-measurement requested screen immediately after the result. You are asked to repeat the measurement within a short window (typically 5–10 minutes). One of two outcomes follows:
This notification to your care team is not an emergency response. It is handled without a guaranteed immediate reply, and it is not a substitute for calling 112 in a suspected emergency. If you feel unwell, do not wait for the app or for Medicilio staff to respond, call 112.
If you miss the notification
Whenever a measurement needs confirming and you have not yet responded, a card appears among your activities on the home screen, naming the measurement concerned. It stays there until you complete the flow or your care team closes the alert.
Tapping the card asks who took the measurement and then guides you through measuring again if that is needed. If the repeat measurement is within range you can move on to your next activity; if it is still out of range you are advised to call the emergency number.
If a measurement could not be read
The device itself may signal that a reading did not work: the cuff moved, the ECG trace was too noisy, or the value is outside what is physically possible. The reading is then not shown to you or to your care team. The app shows an error screen, you receive a notification, and the activity reopens so you can measure again.
If the app tells you a measurement could not be used, no value has reached your care team for that attempt. Repeat the measurement following the on-screen instructions. If it fails repeatedly, contact support (see §2.2).
Open the History entry from the main menu. Select the day for which you want to see the completed or uncompleted activities.
Open Reports from the Documents tab in the History.
The patient can request an appointment from the mobile app; the Medicilio Customer Support confirms the slot.
The patient receives an email when: the activation fee and first month's subscription are due; a payment attempt fails (after the second consecutive failure, the pathway is paused and the patient is notified); the pathway is reactivated following a successful payment; or the pathway becomes active.
The patient must contact a healthcare professional in the following circumstances:
Durations: 30, 45 or 60 minutes.
Two appointment types require a video session:
The patient (and caregiver, where applicable) receives an email and SMS confirmation when a televisit or teleassistance is scheduled or rescheduled, a reminder email and SMS the day before, and a push notification 10 minutes before the appointment (followed by an SMS after 5 minutes if the push is not opened). Home visits and in-studio visits do not generate these notifications to the patient.
After a televisit or teleassistance, the clinician produces an appointment report. The report is signed electronically and only the signed version is visible to the patient.
Note: Only teleassistance requests submitted by the patient can be deleted, and only while they have not yet been accepted by the Medicilio Customer Support. Once the request has been taken in charge, it can no longer be deleted or modified. To change the details of a pending request, delete it and submit a new one. Appointments scheduled by a clinician cannot be cancelled from the patient app.
After an appointment moves to Completed status, the clinician can produce a report or clinical note for that session. The signed report is visible to the patient under the Documents section in the patient menu on the tablet.
Who can upload documents: Patient
Who can delete a document: Patient (only their own documents, and only if the healthcare professional has not yet viewed the document).
| Constraint | Value |
|---|---|
| Maximum file size | 20 MB |
| Maximum batch size | 5 files |
| Allowed MIME types | PDF, JPEG, PNG |
| Download URL validity | 1 hour |
| QR-upload session validity | 30 minutes |
A patient can upload supporting documents (e.g. lab results) directly to their pathway from the patient tablet. Two upload methods are available: taking a photo with the tablet camera, or transferring files from another device via QR code. QR-code sessions expire after 30 minutes.
Who can perform this action: Patient (only on documents uploaded by the patient and not yet reviewed by a healthcare professional).
Both chat channels are created as soon as your pathway becomes active. The chat icon shows a badge when there are messages you have not read.
Two chat channels exist in the patient app.
| Channel | Purpose | Allowed participants |
|---|---|---|
| Supporto di Medicilio | Non-clinical operational support (Medicilio Customer Support) | Patient, Medicilio Customer Support, Ops |
| Supporto Medico Dottore | Clinical communication channel with the assigned clinical team | Patient, Department Doctor, Independent Practice Doctor, Department Doctor Head, Healthcare Professional |
You can edit or delete a message after sending it, from that message's own actions. This applies only to messages you sent yourself. If editing or deleting is no longer available, the app explains why.
The chat channels are not monitored in real time. Messages may be read with significant delay. In an emergency, call 112 and do not use the chat.
Medicilio RPM is hosted on Google Cloud Platform in the EU region (Belgium, Frankfurt and Milan). All clinical data and personal data are stored in the EU. Databases and their backups are held in the regions named above. Object storage, which holds archived application logs, uses Google Cloud EU multi-region storage and may therefore hold data in any European Union member state.
Personal data is processed in accordance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended. The Data Controller is the healthcare provider organisation that prescribes the pathway; Cantieri Digitali Medtech S.r.l. acts as Data Processor.
Medicilio's information-security controls follow the principles of confidentiality, integrity and availability appropriate to a Class IIa MDSW under MDR §23.4(ab) and MDCG 2019-16. This Instructions for Use does not cite specific information-security management standards; the underlying organisational controls are documented in Medicilio's internal Quality Management System.
If you suspect that an unauthorised person has access to your Medicilio account or to the email inbox associated with it:
The tablet provided for the use of the Medicilio application is managed and locked through a Mobile Device Management (MDM) tool. The device is configured so that only the Medicilio application can be used. Patients are not permitted to access the operating system, browse outside the application, install or remove applications, modify device settings, or attempt to unlock, reset, jailbreak, root, or otherwise alter the device configuration. Patients should handle the tablet with care, keep it clean and dry, avoid exposing it to liquids, heat, dust, or physical damage, and promptly report any malfunction, loss, theft, damage, or unexpected device behavior to Medicilio or the designated support contact.
Medicilio RPM is delivered as cloud software (back end) and as two client applications (web and mobile). The release cadence is approximately one release every three months; security and hotfix releases may be issued more often.
Patient and pathway data are backed up by the manufacturer as part of the cloud back-end operation. Users do not need to perform local backups.
See §12.2.
The patient is responsible for:
The table below covers the most common user-facing failure modes.
| Symptom | Likely cause | Action |
|---|---|---|
| OTP email never arrives | Email filtered as spam, or wrong email | Check spam folder; ensure the address matches the one on file; contact support |
| Measurement does not appear in the app | Connectivity loss; gateway off; device battery low | Restore network; charge the device |
| Video session does not start | Browser permissions for camera/microphone denied; firewall blocks Whereby | Grant browser permissions; check the network; restart the browser |
| Patient cannot delete a document | Healthcare professional has already reviewed it | This is intended behaviour. Patient must contact the clinical team. |
When something in your home kit stops working, a card appears on the home screen for as long as the problem lasts. Tapping it opens a page explaining what the app has detected, with numbered steps to put it right and the technical-support telephone number at the bottom.
| Card | What it means | What to do |
|---|---|---|
| The gateway has come unplugged | The home gateway is no longer connected, so your measurements are not reaching your care team | Follow the steps on the card to reconnect it, then tap "I have done this, check" |
| The router has no signal | The router is connected but has no usable network signal | Follow the steps on the card to reposition it, then tap "I have done this, check" |
| The tablet is almost out of battery | The tablet's battery is at or below 10% | Connect the tablet to its charger. The card disappears on its own once the battery recovers |
When you tap "I have done this, check", the app checks whether the problem is fixed. If it is, the card disappears. If it is not, the service centre is alerted and will contact you, and the card stays on the home screen. If more than one thing needs attention, you see one card per problem.
While the gateway or the router is not working, measurements you take may not reach your care team. Do not assume that a measurement you took during the problem has been received.
Any serious incident that occurs in relation to Medicilio RPM must be reported to:
A "serious incident" is defined in Article 2(65) of MDR 2017/745 as an incident that, directly or indirectly, led, might have led or might lead to: the death of a patient, user or other person; the serious deterioration of a person's state of health; or a serious public-health threat.
Reporting a serious incident is mandatory under the MDR. The reporter (clinician, Medicilio Customer Support operator, or patient) should preserve any screenshots, message threads, or device logs that may help reconstruct the incident.
When a pathway reaches its planned end, it is marked as Completed. If it needs to be ended early, it is marked as Cancelled. In both cases, any future scheduled activities are removed and the associated devices are released from the patient's record. The patient receives an email when the pathway reaches its planned end or is cancelled early.
At the end of the pathway, the patient must return the entire home kit, including the MDM-locked tablet (see §6.2), the home gateway, the SIM card, and all measurement devices, to Medicilio using the return instructions provided by the Medicilio Customer Support. The tablet remains locked to the Medicilio application and must not be retained for personal use.
Who can delete a patient record: Department Doctor Head, Independent Practice Doctor, Medicilio Customer Support, Ops.
When a patient record is deleted, the following sequence is applied:
Once a patient is deleted, the personal data are not visible or recoverable through the Medicilio RPM user interface. Restoration from the sealed audit store is performed only by Medicilio data-protection staff and only in response to a documented data-subject or regulatory request. Confirm the patient's identity and the deletion intent before proceeding.
Clinical data linked to a pathway are retained for 10 years from the end of the pathway, in accordance with the applicable Italian SSN rules on healthcare records and with the GDPR principle of storage limitation. At the expiry of the retention period, retained clinical data are deleted or further anonymised so that they can no longer be attributed to an identified or identifiable patient.
The 10-year retention period applies to clinical data associated with the pathway. Operational records, billing records, and vigilance-related records may be subject to different statutory retention obligations under Italian law.
| Term | Definition |
|---|---|
| Pathway | A clinician-prescribed care plan combining vital-parameter measurements, drug intakes, questionnaires and appointments over a defined duration. |
| Activity | A discrete scheduled action within a pathway (measurement, drug intake, questionnaire). |
| Medicilio Customer Support | The internal Medicilio support team: operationally distinct from any external Medicilio Customer Support project. Includes the roles Medicilio Customer Support and Ops. |
| Threshold | The numeric or boolean limit configured per pathway against which incoming measurements are evaluated. |
| Alert | A record created when a threshold is breached; carries a level (yellow or red) and a status. |
| AlertNotification | The record that drives Medicilio Customer Support and emergency-contact notifications for red-level breaches. |
| Telemonitoring report | A clinical document drafted by the AI component and reviewed, edited and signed by the clinician before release to the patient. |
| AppointmentReport | The signed report produced after a televisit or teleassistance. |
| Home kit | The set of devices delivered to the patient (gateway, tablet, one or more measurement devices, SIM). |
| MDR | Regulation (EU) 2017/745 on medical devices. |
| MDSW | Medical Device Software (MDCG 2019-11 qualification). |
| SSN | Servizio Sanitario Nazionale : the Italian national health service. |
| UDI-DI | Unique Device Identifier : Device Identifier. |
| eIFU | Electronic Instructions for Use (Regulation (EU) 2021/2226). |
| Medicilio Customer Support (chat channel) | The non-clinical "Supporto di Medicilio" channel. |
| Whereby | The third-party video provider used for televisits and teleassistance. |
| Time slot | Morning 05:00–12:00, Afternoon 12:00–18:00, or Evening 18:00–24:00. Whatever the activity, the day closes at 23:59:59. |
| Fixed / flexible measurement | Set by your clinician for each measurement. A fixed measurement can only be recorded inside its time slot; a flexible one counts at any point in the day. See §8.1. |
| Adherence | How consistently you complete your prescribed activities, shown on the home screen and shared with your care team. |
| PEF | Peak expiratory flow, measured with a spirometer where your clinician has prescribed it. See §6.3. |
| Version | Date | Author | Summary of changes |
|---|---|---|---|
| 1.0.0 | 2026-09-07 | Cantieri Digitali Medtech S.r.l. | Initial issue. |