Security, privacy and audit requirements · C0881
Does AuroraMed provide break-glass emergency access with reason code, time limit, notifications and mandatory review?
In the pilot (v0.2.0, synthetic data)
Short answer
The pilot covers part of this. The rest is designed, not built. In the pilot: Break-glass with reason, time limit, security alert to privacy officers and mandatory review queue; compartments are flags pending legal review. For reference, REQ-2203 (a top-priority requirement, all three tiers) says the system must provide break-glass emergency access with reason code, time limit, notifications and mandatory review. Check: review queue populated within 1 minute of event.
This exists in the synthetic-data pilot only.
- Specification item
- REQ-2203
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Does AuroraMed support RBAC, ABAC and ReBAC with a central policy decision point and local enforcement points? Pilot
- Does AuroraMed segment sensitive data into compartments with separate keys and policies (psychotherapy, SUD, HIV/STI, reproductive health, genetic, minors, VIP)? Designed
- Does AuroraMed provide HIPAA privacy operations: accounting of disclosures, ROI, amendments, restrictions, breach workflow? Pilot
- Does AuroraMed enforce access as role AND relationship AND purpose AND context AND consent AND risk AND quota for every read, write, print and export? Pilot
See it in context: Security, privacy, consent, audit and access control · Search the help center · Ask a question