Resources
Glossary
Terms used on this site and in the specification, in plain language.
- ABAC / RBAC / ReBAC
- Ways of deciding access: by attributes, by role, or by relationship (for example being on a patient’s care team). The design combines them; the pilot uses role tier, scope and assignment.
- ADT
- Admit, discharge, transfer: the messages that tell other systems where a patient is. Not emitted by the pilot.
- Alert classes
- Code, clinical-critical, ping (emergency, urgent, standard), routine result, security and system. Each has its own priority and timers.
- ARCO rights
- Access, rectification, cancellation and opposition: the data-subject rights in several Latin American laws, including Peru’s.
- AuroraMed Packaging
- The engine that assembles a customer-specific version of the app from a signed manifest.
- Break-glass
- Emergency access to a chart you would not normally see, with a stated reason, a time limit, an alert to privacy staff and a mandatory review.
- Bridge
- In the design, a link between two ledger spheres using two mirrored tokens. Designed, not built.
- Care team
- The people assigned to a patient. In the pilot it scopes who sees the chart and who receives alerts.
- CIE-10 / ICD-10-CM
- Diagnosis code sets. The pilot bundles a subset of ICD-10-CM.
- Code (Code Blue and others)
- A named emergency alert. Meanings are typical usage; each facility confirms its own.
- Compartment
- A category of especially sensitive records (for example mental health). In the pilot it is a flag plus an attested purpose, not a consent engine.
- CPOE
- Computerised provider order entry. The pilot has free-text orders; structured orders are Coming in Wave 2.
- Crypto-shredding
- Deleting data by destroying its encryption keys. Designed; whether it counts as legal erasure is pending legal opinion.
- Deny by default
- Access is refused unless a rule allows it.
- Design goal
- Something the specification aims at and that has not been measured or proven.
- DPO / privacy officer
- The named person responsible for data-protection duties. The roster has privacy roles (tier T8).
- Durable Object
- A hosting building block; the pilot uses one per facility for live updates and timers.
- Element type registry
- The signed list of content types the system will accept. Partly built as a capability registry.
- eMAR / BCMA
- Electronic medication administration record and barcode checking. Designed, not built.
- FHIR
- A modern healthcare data exchange standard. Planned, not built.
- Hash chain
- Records that each contain the fingerprint of the one before, so changes are detectable.
- HL7 v2
- A long-established messaging standard between hospital systems. Not built.
- Jurisdiction profile
- A signed country or state configuration (retention, consent formats, breach clocks and more). Templates only, values to be verified.
- Ledger
- In the design, a shared log of hashes, consent records and audit roots. Patient records are never written to it. Not built.
- Manifest
- The signed configuration that tells the app which modules, permissions and settings a customer gets.
- Memo Desk
- The formal internal memo feature. Not for urgent clinical matters.
- MFA / TOTP
- A second sign-in step using a time-based code from an authenticator app.
- MRN
- Medical record number. In the pilot it is a clinic prefix, a counter and a check digit.
- Open item
- A decision the owner or counsel has not made yet. Shown on this site with an Open label.
- PHI
- Protected health information: identifiable patient data. Not allowed in the pilot.
- Read-side limiter
- A designed control that limits reads, not writes, and pauses only sync when tripped.
- Safe-degrade ladder
- A designed set of levels from normal operation to full local-only operation.
- Simulated
- Behaviour produced by the pilot’s internal interface with synthetic data rather than a real external system.
- Sphere
- In the design, one clinic or clinic network with its own ledger channel and governance keys.
- Synthetic data
- Made-up patients and records used for demonstration and testing.
- Tier (T0 to T9, TS)
- Permission tiers in the role roster. Do not confuse with the pricing tiers (small, medium, large) or privacy tiers (base, local, strict, sovereign).
- Two-person rule
- A change or action that needs a second, different person to approve.
- Wave 1 / Wave 2
- Wave 1 (v0.2.0) is built and verified on synthetic data. Wave 2 (v0.3.0) is being built and is not yet shipped.