Security, privacy and audit requirements · C0914
Would the system track breach-notification deadlines?
Designed, not yet built
Short answer
Breach workflow must compute regulatory clocks from the active profile and track notifications. That is REQ-4304, a top-priority requirement for all three tiers. This is on the design side of the line. Nothing in v0.2.0 does it. Test in the specification: clock started on incident declaration.
This is designed, not built.
- Specification item
- REQ-4304
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- When a record is corrected, is the original erased? Designed
- Does AuroraMed maintain records of processing (ROPA) and support DPIA/RIPD artifacts? Designed
- Does AuroraMed target records-request fulfilment materially faster than the 72-hour norm through the consent flow; legal-review steps are not compressed? Designed
See it in context: Privacy operations and patient rights · Search the help center · Ask a question