Patient rights
Data-subject rights overview
The right to see, correct, restrict, export and, where law allows, delete your data.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0041Can a patient get their records faster than the usual 72 hours?
Speeding up record requests is a stated design goal: a patient-signed consent replaces manual request and fax. Legal review steps cannot be compressed where law demands them. No turnaround figure has been measured, so none is promised.
C0042How would a patient prove who they are?
Identity proofing at enrollment is the anchor: in person with government ID or remote at a comparable assurance level. A signature proves control of a key, not identity, so the design treats enrollment as the crux.
C0043What if a patient has no smartphone?
The design includes assisted signing at reception with a witness, plus guardian and proxy modes. Not every patient is expected to manage keys.
C0044What if the patient is a minor or incapacitated?
Delegated consent by a guardian or proxy is supported in the design, with scoped views and age-based transitions for adolescent confidential care. The portal is not built yet.
C0045Can a patient correct a mistake in their record?
Corrections are append-only amendments: the original stays visible, the amendment is recorded and the commitment updated. Medical records generally cannot be silently rewritten.
C0046Can a patient ask for deletion?
Where law permits, deletion is done by destroying the keys for that compartment so backups become unreadable, plus a tombstone record. Whether that counts as legal erasure awaits a legal opinion. Regulated clinical records may have to be kept.
C0047What if the law says records must be kept for years?
Retention duties override erasure for regulated clinical records. The design offers anonymization or restriction where deletion is not allowed.
C0048Can patients export their data?
A signed, structured export is designed, using a standard format. FHIR export is planned, not built.
C0049Can a patient withdraw consent?
Revocation is recorded at once and blocks new access. Copies already lawfully delivered cannot be recalled, and the system tells patients so in plain language.
C0050Can a patient limit who sees their record?
The design supports restriction flags and compartments that the policy engine enforces. The pilot has VIP and restricted flags.
C0051Can patients see which organizations received their data?
A ledger query filtered by the patient's pseudonym would list entities that received data. It is a design feature, not built.
C0052How does a patient complain?
Through a documented process with the customer's privacy officer or data-protection officer and, where applicable, the regulator. Process content is customer-owned.
C0053Are consent screens written in plain language?
The design requires plain, layered language with no pre-ticked boxes, and a screen that shows who receives what, for what purpose, until when.
C0054Can consent be forced under pressure?
The design includes an optional duress PIN that signs nothing while quietly alerting the clinic, and a cool-off delay for large standing consents.
C0055Does consent travel between clinics?
Consent would be evaluated at access time against ledger state. In the strict tier every cross-site access needs fresh patient-signed consent. The ledger is designed, not built.
C0056How fresh must a cached consent be?
Open. The design keeps a local cache with a staleness bound and denies conservatively when stale, except in emergencies. The staleness limit is an open decision.
C0057Do parents see a teen's confidential care?
No, by design: a proxy loses adolescent-confidential items at the age transition. Rules per state and country need counsel.
C0058Can a patient see their own notes?
The design gives patients a view of their record under release rules. The portal is not built, and release rules are configurable per jurisdiction.
C0059Does AuroraMed record which version of a consent text was signed?
The consent object includes a hash of the exact rendered text and the signature, so what was shown is what was signed.
C0060Can a patient consent to research separately?
Yes in the design: research and secondary use is opt-in, granular and separate from treatment.
C0061What about emergencies when consent cannot be given?
Emergency access rests on the vital-interest basis with no signature, limited to that patient, and is always reviewed afterwards.
C0062Can a court order override consent?
A legal-order override is recorded as its own authority type with counsel approval and multi-person quorum. It is not treated as consent.
C0063Are patients told about copies already shared?
Yes: revocation affects future access only, and this is stated plainly to the patient.
C0064Can the patient's representative act after death?
The specification lists deceased-representative consent as a special case. Specific rules vary by jurisdiction and require counsel.
C0065Can patients pay bills through the portal?
A payment feature is designed through certified processors that never store card data in the record. Billing and the portal are not built.