HIPAA, LGPD, GDPR
Frameworks: what we claim and what we do not
AuroraMed is designed with these frameworks in mind. No compliance, certification or audit is claimed.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0066Is AuroraMed HIPAA compliant?
No claim of HIPAA compliance, certification or readiness is made, and no business associate agreement is offered. The design uses the HIPAA Security Rule as a reference checklist for counsel, and the pilot holds synthetic data only.
C0067Is AuroraMed GDPR compliant?
No. GDPR is a reference for rights such as access, correction and erasure. No compliance claim is made and no legal review has been completed.
C0068Is AuroraMed LGPD compliant?
No such claim. LGPD informs the rights workflows in the design, such as access, correction, deletion and portability. Counsel has not yet reviewed them.
C0069Has a lawyer reviewed the design?
Not yet. The design document states it has had no legal review. Every legal mapping is marked for review by qualified local counsel before anyone relies on it.
C0070Has an independent auditor reviewed the security?
No. There is no external audit and no independent penetration test. The pilot has a developer's own self-review and self-run probes only.
C0071Will AuroraMed sign a business associate agreement?
Undecided. Contracts, insurance and liability are open items. The library of mock contract drafts is a design reference, not an offer.
C0072Which HIPAA safeguards does the design use as a reference?
The design maps administrative, physical and technical safeguards such as unique user ID, emergency access, audit controls, integrity, authentication and transmission security to its own sections. It is a mapping for counsel, not a certificate.
C0073Is 42 CFR Part 2 supported?
A highly restricted compartment for substance-use records exists in the design. Legal operating model is open, and the pilot does not implement Part 2 logic.
C0074How would breach notification work?
The design computes notification clocks from the country profile and runs an incident workflow. The clocks vary by law and are pending verification. The workflow is not built.
C0075Does AuroraMed target the GDPR 72-hour breach window?
The design notes an internal 72-hour target for authority notification regardless of the statutory clock. It is a design target, not a delivered service level.
C0076What is a jurisdiction profile?
A signed configuration bundle for a country that sets language, legal bases, consent formats, residency, retention, breach timers, rights SLA and more. Templates exist in the design, with values pending verification.
C0077Is crypto-shredding accepted as deletion?
Open. Acceptance differs by authority and needs legal opinion. Until then the design treats it as putting data beyond use.
C0078What about the US Security Rule update proposal?
The specification notes it as proposed only and that the current rule applies. The design already targets its headline controls such as multi-factor authentication and encryption.
C0079Does AuroraMed support information-blocking rules?
The design logs exceptions and keeps interfaces open, but no claim is made about meeting those rules. Whether the owner seeks US certification is undecided.
C0080Who is the privacy officer?
The customer names its own privacy officer or data-protection officer role. AuroraMed provides tooling such as break-glass review queues and request cases. Appointment model is open.
C0081Does AuroraMed produce a records-of-processing register?
A register and impact-assessment artifacts are designed as generated outputs. They are not built.
C0082Which legal bases are used for health data?
Open per country: care provision, legal obligation, vital interests and consent are candidates. The profile lists allowed bases and counsel confirms them.
C0083Can the system show accounting of disclosures?
It is designed from the audit log, and the pilot already offers a disclosure log and per-patient access report to privacy staff.
C0084Can data be hosted in-country?
Residency is a profile setting with no cross-border replication by default. Cloud regions and residency rules per country are open and need verification.
C0085Does AuroraMed guarantee data residency?
No guarantee is made. Residency is a configurable design goal pending legal and operational decisions.
C0086How are sensitive biometrics handled?
Workforce biometric analytics are off by default and need privacy-officer sign-off, and raw typing cadence is not placed on a shared ledger.
C0087What does "legal minimums are not optional" mean?
The base tier must meet each country's law itself. The optional strict tier goes beyond it, never replaces it.
C0088How are privacy impact assessments supported?
By generated artifacts from the processing register where the law asks for them. The feature is designed, not built.
C0089Who appoints the data-protection officer for a clinic?
The customer appoints. Whether AuroraMed also designates its own is an open item for counsel.