Ledger, sync, offline and hardware requirements · C0931
How are patient pseudonyms built, and how can they be cut?
Designed, not yet built
Short answer
REQ-3010 is a top-priority requirement for all three tiers: patient pseudonyms must be HMAC(K_sphere, id‖r_patient) so that destroying r_patient severs linkage. Not yet. It is designed in the specification and not built in the pilot. To verify it, the specification says after erasure test, pseudonym cannot be recomputed from the id.
This is designed, not built.
- Specification item
- REQ-3010
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- How are record fingerprints on the ledger prevented from revealing anything? Designed
- How would cryptographic erasure of a patient's data work? Designed
- Does patient care wait for the ledger to be reachable? Designed
- How is a patient's consent signed and revoked on the ledger? Designed
See it in context: Federated ledger, spheres, tokens, wallets, bridges · Search the help center · Ask a question