Vendor lock-in and data ownership
Data ownership and exit
Clinic-owned records, portable export and end-of-contract.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0294Who owns the patient data?
The clinic is the system of record for its own patients, and the local database is primary. The design forbids monetizing patient data and secondary use without explicit consent.
C0295Can we take our data with us?
Portability is a design principle: structured export in standard formats, signed packages and a data return procedure at contract end. Export tooling is not built.
C0296What standards are used for export?
FHIR export and standard documents are planned, which is meant to avoid proprietary lock-in. They are not built.
C0297What happens at contract end?
The design specifies data return and a destruction certificate, key zeroization and optional hardware destruction. Contract wording is open.
C0298What if AuroraMed shuts down?
No continuity plan or escrow is published. Because the clinic keeps its own local database, a clinic is not dependent on cloud availability, but source-code or service escrow is an open question.
C0299Is the source code open?
No. The pilot is proprietary. No open-source commitment exists.
C0300Are hashes on the ledger a form of lock-in?
They are commitments, not data, and patient records are never written to the ledger, so leaving does not require extracting data from it.
C0301Can another vendor read our backups?
Backups are encrypted with keys the clinic controls in the strict tier; in the baseline tier the cloud operator holds wrapping keys under policy. Export into open formats is the intended exit path.
C0302Can our own IT staff run the server?
Administration without patient-data access is designed, with certified maintenance crews for larger tiers. Self-administration terms are open.
C0303Are we locked to AuroraMed hardware?
The small tier buys equipment from AuroraMed. The specification leaves the tablet hardware model open, and alternatives are not ruled out.
C0304Is there a minimum contract term?
Not decided. No contract terms exist yet: the billing period for the medium tier is unconfirmed, the hospital fee structure is open, and no agreement template has been reviewed by a lawyer.
C0305Can we migrate to another EHR later?
Standards-based export is the planned path. A migration guide is not written.
C0306Who controls encryption keys?
Keys sit in a clinic hardware module in the strict tier, and baseline keys are wrapped under HSM policy by the operator. Custody for small sites is TPM or smartcard; choices are open.
C0307Who can legally compel access to data?
A legal order is recorded as its own authority type with counsel approval and multi-person quorum, never treated as consent. Legal procedure for messages is an open item.
C0308Can AuroraMed staff read patient data?
The design says no: vendor administrators have no path to decrypt patient columns and every privileged session is recorded and dual-approved.