AuroraMed v0.2.0 is a synthetic-data pilot. See exactly what's built →

HIPAA, LGPD, GDPR

Frameworks: what we claim and what we do not

AuroraMed is designed with these frameworks in mind. No compliance, certification or audit is claimed.

How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration

C0066Is AuroraMed HIPAA compliant?

No claim of HIPAA compliance, certification or readiness is made, and no business associate agreement is offered. The design uses the HIPAA Security Rule as a reference checklist for counsel, and the pilot holds synthetic data only.

Not offered / no claim madePermalink

C0067Is AuroraMed GDPR compliant?

No. GDPR is a reference for rights such as access, correction and erasure. No compliance claim is made and no legal review has been completed.

Not offered / no claim madePermalink

C0068Is AuroraMed LGPD compliant?

No such claim. LGPD informs the rights workflows in the design, such as access, correction, deletion and portability. Counsel has not yet reviewed them.

Not offered / no claim madePermalink

C0069Has a lawyer reviewed the design?

Not yet. The design document states it has had no legal review. Every legal mapping is marked for review by qualified local counsel before anyone relies on it.

Not offered / no claim madePermalink

C0070Has an independent auditor reviewed the security?

No. There is no external audit and no independent penetration test. The pilot has a developer's own self-review and self-run probes only.

Not offered / no claim madePermalink

C0071Will AuroraMed sign a business associate agreement?

Undecided. Contracts, insurance and liability are open items. The library of mock contract drafts is a design reference, not an offer.

Open decisionPermalink

C0072Which HIPAA safeguards does the design use as a reference?

The design maps administrative, physical and technical safeguards such as unique user ID, emergency access, audit controls, integrity, authentication and transmission security to its own sections. It is a mapping for counsel, not a certificate.

Designed, not yet builtPermalink

C0073Is 42 CFR Part 2 supported?

A highly restricted compartment for substance-use records exists in the design. Legal operating model is open, and the pilot does not implement Part 2 logic.

Designed, not yet builtPermalink

C0074How would breach notification work?

The design computes notification clocks from the country profile and runs an incident workflow. The clocks vary by law and are pending verification. The workflow is not built.

Designed, not yet builtPermalink

C0075Does AuroraMed target the GDPR 72-hour breach window?

The design notes an internal 72-hour target for authority notification regardless of the statutory clock. It is a design target, not a delivered service level.

Designed, not yet builtPermalink

C0076What is a jurisdiction profile?

A signed configuration bundle for a country that sets language, legal bases, consent formats, residency, retention, breach timers, rights SLA and more. Templates exist in the design, with values pending verification.

Designed, not yet builtPermalink

C0077Is crypto-shredding accepted as deletion?

Open. Acceptance differs by authority and needs legal opinion. Until then the design treats it as putting data beyond use.

Open decisionPermalink

C0078What about the US Security Rule update proposal?

The specification notes it as proposed only and that the current rule applies. The design already targets its headline controls such as multi-factor authentication and encryption.

Designed, not yet builtPermalink

C0079Does AuroraMed support information-blocking rules?

The design logs exceptions and keeps interfaces open, but no claim is made about meeting those rules. Whether the owner seeks US certification is undecided.

Designed, not yet builtPermalink

C0080Who is the privacy officer?

The customer names its own privacy officer or data-protection officer role. AuroraMed provides tooling such as break-glass review queues and request cases. Appointment model is open.

Designed, not yet builtPermalink

C0081Does AuroraMed produce a records-of-processing register?

A register and impact-assessment artifacts are designed as generated outputs. They are not built.

Designed, not yet builtPermalink

C0082Which legal bases are used for health data?

Open per country: care provision, legal obligation, vital interests and consent are candidates. The profile lists allowed bases and counsel confirms them.

Open decisionPermalink

C0083Can the system show accounting of disclosures?

It is designed from the audit log, and the pilot already offers a disclosure log and per-patient access report to privacy staff.

Designed, not yet builtPermalink

C0084Can data be hosted in-country?

Residency is a profile setting with no cross-border replication by default. Cloud regions and residency rules per country are open and need verification.

Open decisionPermalink

C0085Does AuroraMed guarantee data residency?

No guarantee is made. Residency is a configurable design goal pending legal and operational decisions.

Not offered / no claim madePermalink

C0086How are sensitive biometrics handled?

Workforce biometric analytics are off by default and need privacy-officer sign-off, and raw typing cadence is not placed on a shared ledger.

Designed, not yet builtPermalink

C0087What does "legal minimums are not optional" mean?

The base tier must meet each country's law itself. The optional strict tier goes beyond it, never replaces it.

Designed, not yet builtPermalink

C0088How are privacy impact assessments supported?

By generated artifacts from the processing register where the law asks for them. The feature is designed, not built.

Designed, not yet builtPermalink

C0089Who appoints the data-protection officer for a clinic?

The customer appoints. Whether AuroraMed also designates its own is an open item for counsel.

Open decisionPermalink
See the synthetic-data demo first.Request a demo