Security, privacy and audit requirements · C0883
Does AuroraMed provide HIPAA privacy operations: accounting of disclosures, ROI, amendments, restrictions, breach workflow?
In the pilot (v0.2.0, synthetic data)
Short answer
The pilot covers part of this. The rest is designed, not built. Pilot detail: Disclosure log + access report only; no ROI/amendments/restrictions/breach workflow. REQ-2205 says the system must provide HIPAA privacy operations: accounting of disclosures, ROI, amendments, restrictions, breach workflow. Its acceptance check: accounting report for a test patient complete.
This exists in the synthetic-data pilot only.
- Specification item
- REQ-2205
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Does AuroraMed segment sensitive data into compartments with separate keys and policies (psychotherapy, SUD, HIV/STI, reproductive health, genetic, minors, VIP)? Designed
- Does AuroraMed provide patient-facing access reports and consent directives (opt-in/opt-out for HIE, research)? Designed
- Does AuroraMed support data segmentation for privacy (HL7 DS4P labels)? Designed
- Does AuroraMed provide break-glass emergency access with reason code, time limit, notifications and mandatory review? Pilot
See it in context: Security, privacy, consent, audit and access control · Search the help center · Ask a question