Security controls
The federated ledger
Spheres, bridges, tokens, wallets and quorum.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0174What is a sphere?
One permissioned ledger per clinic or clinic network, holding hashes, consent and audit records and never patient data.
C0175What is a bridge?
A contact point between two spheres made of exactly two mirrored tokens, one on each side, with history recorded on both sides using a two-phase commit with time locks.
C0176Which token types exist?
The design lists ID, ROLE, CONS, GRANT, XFER, BRG-A/B, NODE, ALERT, BG and DELEG as a proposal. The final list and semantics are an open decision, and tokens are not financial assets.
C0177Is this a cryptocurrency?
No. Tokens are non-transferable authority and consent instruments, deliberately not tradeable assets.
C0178How many approvers does a sensitive action need?
Multi-key corroboration is decided; the threshold such as two of three and the signer roles are open. Until set the policy engine refuses to execute.
C0179What are mintable wallets?
Identity-bound wallets for patients, proxies, staff, nodes and services created only by quorum with identity binding, rate limits and a mass-mint alarm. Class semantics are open.
C0180Is the ledger a single point of failure?
Care never blocks on the ledger: writes queue locally. The design replaces "all nodes must agree" with quorums to avoid creating a shutdown lever.
C0181What technology will run the ledger?
A permissioned Hyperledger Fabric baseline behind a service interface, with a signed hash-chained log as an alternative for single-owner spheres. The choice is open.
C0182Can the ledger prove clinical content is true?
No. It proves that an authority or event existed. It cannot recall data already delivered under a valid earlier authority.
C0183What if the two sides of a bridge disagree?
Explicit states, time locks and abort semantics handle partition. Formal verification of the protocol is planned before production and not done.
C0184Who holds the root of trust?
Initially the owner, which the design calls an organizational single point of failure and a legal liability to be reduced by role diversity, hardware tokens and external witness anchors.
C0185How are ledger pseudonyms made?
By keyed hashing with a per-sphere key and per-patient randomness, so pseudonyms differ across spheres and linkage exists only inside consented, encrypted records.
C0186Does consent use the ledger?
Consent tokens record that a signed, scoped, time-bound authorization exists. The document itself stays off the ledger.