Security, privacy and audit requirements · C0882
Does AuroraMed segment sensitive data into compartments with separate keys and policies (psychotherapy, SUD, HIV/STI, reproductive health, genetic, minors, VIP)?
Designed, not yet built
Short answer
The system must segment sensitive data into compartments with separate keys and policies (psychotherapy, SUD, HIV/STI, reproductive health, genetic, minors, VIP). That is REQ-2204, a top-priority requirement for all three tiers. This is on the design side of the line. Nothing in v0.2.0 does it. Test in the specification: compartment access without purpose refused.
This is designed, not built.
- Specification item
- REQ-2204
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Does AuroraMed provide break-glass emergency access with reason code, time limit, notifications and mandatory review? Pilot
- Does AuroraMed provide HIPAA privacy operations: accounting of disclosures, ROI, amendments, restrictions, breach workflow? Pilot
- Does AuroraMed provide patient-facing access reports and consent directives (opt-in/opt-out for HIE, research)? Designed
- Does AuroraMed support RBAC, ABAC and ReBAC with a central policy decision point and local enforcement points? Pilot
See it in context: Security, privacy, consent, audit and access control · Search the help center · Ask a question