Ledger, sync, offline and hardware requirements · C0932
How would cryptographic erasure of a patient's data work?
Designed, not yet built
Short answer
The federated ledger, spheres, tokens, wallets, bridges part of the specification (REQ-3011) says cryptographic erasure must destroy DEK, salts and r_patient by quorum, write a tombstone and verify undecryptability. Designed, not built: there is no code for this in the pilot. Acceptance check: post-erasure decrypt attempt fails and is logged.
This is designed, not built.
- Specification item
- REQ-3011
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- How are patient pseudonyms built, and how can they be cut? Designed
- Does patient care wait for the ledger to be reachable? Designed
- Could the ledger's signature methods be upgraded later? Designed
- How are record fingerprints on the ledger prevented from revealing anything? Designed
See it in context: Federated ledger, spheres, tokens, wallets, bridges · Search the help center · Ask a question