Privacy fundamentals
The privacy model
US-style compartmentalized privacy by default, with optional strict privacy for Latin America.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0021What privacy model does AuroraMed follow?
US-style compartmentalization is the default: role, relationship, purpose, context and risk must all line up before access. Latin American customers can switch on a stricter optional tier. Legal minimums in each country still apply regardless of tier.
C0022Is strict privacy a paid add-on?
For Latin America it is decided as a switchable, optional paid tier. It goes beyond legal minimums. The baseline tier has to satisfy local law on its own, pending counsel review.
C0023What does the strict tier add?
The design adds keys held only in the clinic, cloud sees ciphertext only, per-patient keys everywhere, patient-signed consent for every cross-site access, and enhanced audit visible to patients. It is designed, not built.
C0024Does a cheaper plan weaken privacy or security?
It must not. The specification says tiers change price and scale, never the legal-minimum privacy and security floor.
C0025What is a compartment?
A slice of the record with its own keys and policy, such as mental-health, substance-use, HIV, reproductive, genetic, minors, or VIP. The general chart shows that restricted data exists and needs a logged reason to open.
C0026Can staff see VIP patients freely?
In the pilot, VIP and restricted patients are hidden from anyone without an explicit care assignment. Break-glass is possible but raises a security alert and a mandatory review.
C0027Who can see a patient's Social Security number?
The pilot masks it. Revealing it needs a stated purpose, is audited, and shows for only a few seconds.
C0028Is patient data ever sold or used to train AI?
The design forbids monetizing patient data and secondary use without explicit consent and legal basis. AI inference is designed to run on site or in an approved region, and patient data may not train models without separate written approval.
C0029Where is patient data stored?
The design places it on a per-clinic closed on-site server, with an encrypted backup copy in the cloud. The pilot runs on a cloud hub and holds synthetic data only.
C0030Is patient data stored on the ledger?
Never. Only hashes, consent records and audit records go on the federated ledger, so deletion and correction rights can be honored. The ledger is designed, not yet built.
C0031Can a hash on the ledger identify someone?
The design uses salted commitments with per-record salts kept off the ledger, because plain hashes of low-entropy data can be guessed. Destroying a salt breaks linkability.
C0032Do registration staff see clinical charts?
No. In the pilot registrars deliberately have no chart access, only demographics and registration functions.
C0033Do IT administrators see patient data?
The design prevents it: administration is separated from data, database administrators cannot decrypt patient columns, and key release needs an attested policy decision.
C0034How is minimum necessary enforced?
Access is role AND relationship AND purpose AND context AND risk, evaluated server-side. Roles such as billing or quality see only the minimum needed for the work item.
C0035Are messages and alerts kept on site?
Yes by design: messaging, Memo Desk and code alerts run on the on-site server, carry no patient data to pagers by default, and never touch the ledger.
C0036Does keystroke analytics monitor staff typing?
It is off by default. If a customer enables it where law allows, it is a review flag only and never a sole lockout trigger, with workforce notice and privacy-officer sign-off.
C0037Is patient contact information exposed in alerts?
Alert payloads in the pilot do not carry patient identifiers to external channels, and there are no external channels. The design keeps pager and SMS text free of patient data.
C0038What does "closed loop" mean for a clinic?
No inbound connections from the internet to the clinic server and controlled outbound connections only. It is a network design term, not a claim that nothing can ever go wrong.
C0039How long is data retained?
Retention depends on country, state and record type and is set in a signed profile. The specification leaves the values open pending counsel. Audit defaults are proposals only.
C0040Can patients see who looked at their record?
The design derives a patient-visible access history from the audit log. A patient portal is not built yet, so the pilot offers a per-patient access report to privacy staff.