Vendor lock-in and data ownership · C0306
Who controls encryption keys?
Designed, not yet built
Short answer
Keys sit in a clinic hardware module in the strict tier, and baseline keys are wrapped under HSM policy by the operator. Custody for small sites is TPM or smartcard; choices are open.
This is designed, not built.
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Can we migrate to another EHR later? Designed
- Who can legally compel access to data? Designed
- Can AuroraMed staff read patient data? Designed
- Is there a minimum contract term? Open
See it in context: Data ownership and exit · Search the help center · Ask a question