Help center
The specification, requirement by requirement
The AuroraMed specification has 454 functional requirements in 49 modules. As of September 30, 2026, 8 are built at MVP scope in the synthetic-data pilot, 53 are partly built, 9 are placeholders and 384 are not built. That is what an honest coverage table looks like.
Reading this table
Counts come from the developer's own gap analysis of the pilot against the specification. They are not a measure of percent complete, and requirements differ enormously in size. Wave 2 items are labelled Coming until verified.
Configuration, Element Type Registry and Jurisdiction Profiles (17)
Governs which content exists, how it is classified and how each country/state behaves.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-0101 | The system shall accept only content element types that exist in the signed Element Type Registry and shall reject and audit any other type. | Pilot Partly built | C0832 |
| REQ-0102 | The Element Type Registry shall store, per type, the attributes in file 01: shape, required fields, validation, class, retention, ledger code, role-tier permissions and audit events. | Designed Not built | C0833 |
| REQ-0103 | Registry releases shall be signed by AuroraMed compliance, verified by the on-site server before activation, and their hash shall be anchored to the ledger. | Designed Not built | C0834 |
| REQ-0104 | Family members (artifact families in file 01 section 6) shall be creatable by authorized administrators without a software release. | Designed Not built | C0835 |
| REQ-0105 | Each deployment shall load exactly one active Jurisdiction Profile per country context, signed by AuroraMed and countersigned by the customer's privacy officer/DPO. | Designed Not built | C0836 |
| REQ-0106 | Jurisdiction Profiles shall configure at least: language set, legal bases allowed, consent formats, data residency, retention periods, breach-notification timers, subject-rights SLA, DPO requirement, workforce analytics switch, and crypto-erasure acceptance. | Designed Not built | C0837 |
| REQ-0107 | The system shall ship profile templates for US (HIPAA baseline), BR (LGPD), CO, CL, MX, PE and AR, each with values marked [verify] until counsel confirms. | Designed Not built | C0838 |
| REQ-0108 | The system shall support the T-BASE, T-LOCAL, T-STRICT and T-SOVEREIGN privacy tiers as profile-controlled feature sets and shall show the active tier in the administrator console. | Designed Not built | C0839 |
| REQ-0109 | Configuration changes affecting access policy, retention, tier, alert policy or code-alert definitions shall require dual control and be versioned with rollback. | Pilot Partly built | C0840 |
| REQ-0110 | The system shall support configuration simulation ("what-if") for access policies before activation. | Designed Not built | C0841 |
| REQ-0111 | The system shall provide a terminology management function (import, version pin, mapping, deprecation) with a release record per code-system update. | Designed Not built | C0842 |
| REQ-0112 | The system shall maintain a Licence Register for licensed content (CPT, SNOMED CT, LOINC use terms, NANDA-I/NIC/NOC, instruments, drug knowledge bases) and block enabling content without a recorded licence. | Designed Not built | C0843 |
| REQ-0113 | The system shall provide localization for at least en-US, es-419 and pt-BR for UI, forms, notices, alerts and patient documents, with translation review status per string. | Designed Not built | C0844 |
| REQ-0114 | The system shall support per-facility enterprise structure (organization, facility, department, unit, room, bed) and multi-facility sphere membership. | Designed Placeholder only | C0845 |
| REQ-0115 | The system shall keep master files (locations, departments, order catalog, result catalog, charge master) under change control with effective dating. | Designed Not built | C0846 |
| REQ-0116 | The system shall provide build/config export and import as signed bundles for test-to-production promotion. | Designed Not built | C0847 |
| REQ-0117 | The system shall support non-production environments (test, train) with synthetic data only and shall block import of production PHI into them. | Pilot Partly built | C0848 |
Patient identity and master patient index (25)
Registration identity, matching, merge, cross-sphere linkage.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-0201 | The system shall create a patient record with a unique internal identifier, never derived from a national identifier. | Pilot Built at MVP scope | C0548 |
| REQ-0202 | The system shall capture multiple identifier types per patient with issuer, period and status. | Designed Not built | C0549 |
| REQ-0203 | The system shall validate national identifiers with the checksum of their type (CPF, CNS, RUT, CURP, DNI, NPI, MBI format) and shall store them encrypted with a blind index. | Designed Not built | C0550 |
| REQ-0204 | The system shall support deterministic and probabilistic patient matching with configurable weights and phonetic/fuzzy name matching, and shall present candidates with scores. | Pilot Partly built | C0551 |
| REQ-0205 | The system shall support two-identifier verification prompts at registration, order entry, specimen collection, medication administration and transfusion. | Designed Not built | C0552 |
| REQ-0206 | The system shall support unknown-patient (Doe) registration with temporary identity, later merge to a real identity, and full reversal (unmerge). | Pilot Partly built | C0553 |
| REQ-0207 | Merge and unmerge shall require two-person approval and shall emit ADT A40/A37 (or FHIR Linkage/Patient replaced-by) to interfaces. | Pilot Partly built | C0554 |
| REQ-0208 | The system shall support name history: legal, chosen, previous, alias, with pronouns and display rules. | Pilot Partly built | C0555 |
| REQ-0209 | The system shall record sex and gender data as separate fields (administrative sex, sex for clinical use, gender identity, sexual orientation) with a declined option. | Designed Not built | C0556 |
| REQ-0210 | The system shall record race, ethnicity and language with multi-select, declined option and interpreter need. | Designed Not built | C0557 |
| REQ-0211 | The system shall link mothers and newborns and multiple-birth siblings with permanent links that only HIM can change. | Designed Not built | C0558 |
| REQ-0212 | The system shall support related persons: emergency contacts, guarantors, guardians, proxies with scope, period and authority document. | Designed Not built | C0559 |
| REQ-0213 | The system shall support VIP/restricted/confidential patient flags with hidden-flag option and access requirement of relationship or break-glass. | Pilot Partly built | C0560 |
| REQ-0214 | The system shall support registration alerts and flags (infection, behavioral, safety) with expiry and review dates. | Designed Not built | C0561 |
| REQ-0215 | The system shall capture patient photos with consent, strip metadata, and use them only for identity verification per policy. | Designed Not built | C0562 |
| REQ-0216 | The system shall optionally support biometric identification (palm-vein, fingerprint, iris) as an opt-in per jurisdiction profile, storing templates only. | Designed Not built | C0563 |
| REQ-0217 | The system shall provide a duplicate-record worklist and overlay/overlap resolution tools for HIM. | Designed Not built | C0564 |
| REQ-0218 | The system shall support IHE PIX/PDQ/PIXm/PDQm and FHIR Patient $match for identity queries subject to consent and policy. | Designed Not built | C0565 |
| REQ-0219 | The system shall create and maintain cross-sphere patient linkage only through consented BridgeLinkage records. | Designed Not built | C0566 |
| REQ-0220 | The system shall provide demographic data quality dashboards (missing DOB, invalid identifiers, address failures). | Pilot Partly built | C0567 |
| REQ-0221 | The system shall standardize addresses with country-specific formats and code tables (USPS, CEP/IBGE, DANE, INEGI, UBIGEO). | Designed Not built | C0568 |
| REQ-0222 | The system shall scan and OCR insurance and identification cards into structured fields with human confirmation. | Designed Not built | C0569 |
| REQ-0223 | The system shall support patient-side identity proofing at IAL2-style assurance for wallet enrollment (in person or remote). | Designed Not built | C0570 |
| REQ-0224 | The system shall mask national identifiers by default and require purpose for unmasking, auditing each unmasking. | Pilot Built at MVP scope | C0571 |
| REQ-0225 | The system shall record deceased status and propagate suppression to scheduling and outreach. | Designed Not built | C0572 |
Registration, ADT, bed management and patient access (22)
Front-desk, encounter, admission/transfer/discharge, bed and transport workflows.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-0301 | The system shall register outpatient, emergency, inpatient, observation, home-visit and virtual encounters with class, type, location and participants. | Pilot Partly built | C0573 |
| REQ-0302 | The system shall support pre-registration and digital/kiosk check-in with identity and consent capture. | Designed Not built | C0574 |
| REQ-0303 | The system shall support ED quick registration, mass-casualty registration and unknown-patient shortcuts. | Designed Not built | C0575 |
| REQ-0304 | The system shall support admission, transfer, discharge, cancel-admit, cancel-transfer and cancel-discharge with correct state transitions. | Designed Not built | C0576 |
| REQ-0305 | The system shall emit and consume HL7 v2 ADT events and FHIR Encounter changes. | Designed Not built | C0577 |
| REQ-0306 | The system shall provide a bed board and census with bed status (available, occupied, cleaning, blocked) and isolation/acuity matching. | Designed Not built | C0578 |
| REQ-0307 | The system shall provide a transfer center for inbound/outbound transfers including EMTALA documentation and acceptance recording. | Designed Not built | C0579 |
| REQ-0308 | The system shall track observation status with Two-Midnight clocks and notice issuance (MOON). | Designed Not built | C0580 |
| REQ-0309 | The system shall record coverage with multiple payers, priority order and eligibility verification (X12 270/271, real-time and batch). | Designed Not built | C0581 |
| REQ-0310 | The system shall capture required notices and acknowledgments (NPP, consent to treat, financial policy, IM, MOON, ABN) with signature and delivery proof. | Designed Not built | C0582 |
| REQ-0311 | The system shall support electronic signature capture (pad, tablet) with evidence and hash of the displayed document. | Designed Not built | C0583 |
| REQ-0312 | The system shall capture advance directive and code status with document link. | Designed Not built | C0584 |
| REQ-0313 | The system shall calculate patient estimates and Good Faith Estimates when charge data exist. | Designed Not built | C0585 |
| REQ-0314 | The system shall support financial clearance and financial assistance screening with sliding-fee schedules. | Designed Not built | C0586 |
| REQ-0315 | The system shall track waiting-room status and arrival-to-rooming workflow with display boards that show minimal identifiers. | Designed Not built | C0587 |
| REQ-0316 | The system shall issue wristbands and labels (Code 128 / 2D) with two identifiers and allergy alert marks. | Pilot Partly built | C0588 |
| REQ-0317 | The system shall produce After-Visit Summaries and discharge instructions in the patient's language. | Designed Not built | C0589 |
| REQ-0318 | The system shall support visitor management and visit restrictions. | Designed Not built | C0590 |
| REQ-0319 | The system shall support patient transport requests and tracking inside the facility. | Designed Not built | C0591 |
| REQ-0320 | The system shall audit all registration edits with old/new values encrypted. | Pilot Partly built | C0592 |
| REQ-0321 | The system shall run front-end claim edits at registration. | Designed Not built | C0593 |
| REQ-0322 | The system shall support Brazil SUS registration data (AIH/BPA), CNS lookup and CADSUS integration and equivalent country adapters. | Designed Not built | C0594 |
Scheduling and access management (15)
Appointments, resources, waitlists, reminders.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-0351 | The system shall provide provider templates, visit types, durations and overbooking rules with effective dating. | Designed Not built | C0595 |
| REQ-0352 | The system shall schedule multi-resource appointments (provider, room, equipment). | Designed Not built | C0596 |
| REQ-0353 | The system shall support recurring series, group appointments and block scheduling with release rules. | Designed Not built | C0597 |
| REQ-0354 | The system shall provide waitlist management with automatic fill. | Designed Not built | C0598 |
| REQ-0355 | The system shall provide online self-scheduling through the patient portal/wallet with rules per visit type. | Designed Not built | C0599 |
| REQ-0356 | The system shall send reminders by SMS, email, voice, push and WhatsApp where allowed, honoring per-channel contact consent. | Designed Not built | C0600 |
| REQ-0357 | The system shall check referral and authorization requirements before scheduling. | Designed Not built | C0601 |
| REQ-0358 | The system shall detect double booking and require override permission with reason. | Designed Not built | C0602 |
| REQ-0359 | The system shall enforce no-show and late-cancel policies with configurable rules. | Designed Not built | C0603 |
| REQ-0360 | The system shall publish and consume HL7 SIU S12-S26 and FHIR Appointment/Schedule/Slot. | Designed Not built | C0604 |
| REQ-0361 | The system shall provide schedule utilization and access analytics (third-next-available, fill rate). | Designed Not built | C0605 |
| REQ-0362 | The system shall support recall and preventive-care outreach lists. | Designed Not built | C0606 |
| REQ-0363 | The system shall support telehealth visit scheduling and link generation. | Designed Not built | C0607 |
| REQ-0364 | The system shall support provider absence management with automatic rebooking suggestions. | Designed Not built | C0608 |
| REQ-0365 | The system shall provide a regulation-queue adapter for national referral systems such as SISREG. | Designed Not built | C0609 |
Clinical documentation and the chart (37)
Problem-oriented chart, notes, templates, signatures, amendments.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-0401 | The system shall present a patient header/banner with identifiers, age, sex, allergies, code status, isolation and restricted flags on every chart screen. | Pilot Partly built | C0610 |
| REQ-0402 | The system shall provide a chart summary/snapshot with problems, meds, allergies, vitals, recent results and care team. | Pilot Partly built | C0611 |
| REQ-0403 | The system shall manage the problem list (active/resolved/inactive) with SNOMED CT or ICD-10-CM/CIE-10 coding and verification status. | Designed Placeholder only | C0612 |
| REQ-0404 | The system shall record medical, surgical, family and social history with coded and free-text entries. | Designed Not built | C0613 |
| REQ-0405 | The system shall manage allergy/intolerance lists with reaction, severity, criticality and explicit no-known-allergies assertion. | Designed Placeholder only | C0614 |
| REQ-0406 | The system shall record vital signs and flowsheets with LOINC-mapped rows and UCUM units. | Pilot Partly built | C0615 |
| REQ-0407 | The system shall support clinical notes of all types in file 01 with structured sections and free text. | Pilot Partly built | C0616 |
| REQ-0408 | The system shall provide templates, smart phrases and macros with variable substitution that cannot execute code. | Designed Not built | C0617 |
| REQ-0409 | The system shall support voice dictation with review before filing; audio is not retained beyond policy. | Designed Not built | C0618 |
| REQ-0410 | The system shall optionally support ambient AI documentation as draft notes under section AI. | Designed Not built | C0619 |
| REQ-0411 | The system shall support copy-forward with visible change highlighting and provenance. | Designed Not built | C0620 |
| REQ-0412 | The system shall support note signing, cosigning, attestation and teaching-physician statements. | Designed Not built | C0621 |
| REQ-0413 | The system shall support addenda, amendments and entered-in-error marking without deleting original content. | Designed Not built | C0622 |
| REQ-0414 | The system shall support late entries with both event time and entry time displayed. | Designed Not built | C0623 |
| REQ-0415 | The system shall capture structured data through discrete forms and questionnaires (FHIR Questionnaire/SDC). | Designed Not built | C0624 |
| REQ-0416 | The system shall provide document management: scanning, indexing, OCR, categories, encounter links and fax intake. | Designed Not built | C0625 |
| REQ-0417 | The system shall capture clinical photographs and wound images with annotation, measurement scale and consent. | Designed Not built | C0626 |
| REQ-0418 | The system shall provide body diagrams with vector annotations. | Designed Not built | C0627 |
| REQ-0419 | The system shall provide validated clinical calculators with versioned formulas. | Designed Not built | C0628 |
| REQ-0420 | The system shall provide a clinical inbox with pooled and delegated queues for results, messages, refill requests and referrals; every item has an owner. | Designed Not built | C0629 |
| REQ-0421 | The system shall generate result-notification letters and templates. | Designed Not built | C0630 |
| REQ-0422 | The system shall support letters, forms and correspondence templates and FMLA/disability forms. | Designed Not built | C0631 |
| REQ-0423 | The system shall generate and consume C-CDA documents and represent notes as FHIR DocumentReference/Composition. | Designed Not built | C0632 |
| REQ-0424 | The system shall support Open Notes / Cures Act sharing with exceptions and documented reasons. | Designed Not built | C0633 |
| REQ-0425 | The system shall segment psychotherapy notes and 42 CFR Part 2 records into separate compartments. | Designed Not built | C0634 |
| REQ-0426 | The system shall document interpreter use. | Designed Not built | C0635 |
| REQ-0427 | The system shall support clinical coding of encounters (ICD-10-CM, CPT/HCPCS, CIE-10 and country equivalents) with encoder integration. | Designed Not built | C0636 |
| REQ-0428 | The system shall provide a longitudinal timeline view across encounters and external sources. | Pilot Partly built | C0637 |
| REQ-0429 | The system shall support external/outside record reconciliation and incorporation. | Designed Not built | C0638 |
| REQ-0430 | The system shall provide assessments and scores (pain, falls, pressure injury, nutrition) with versioned instruments. | Designed Not built | C0639 |
| REQ-0431 | The system shall provide care team management and patient-provider relationships that drive access policy. | Pilot Partly built | C0640 |
| REQ-0432 | The system shall provide patient lists with minimum-necessary query enforcement. | Pilot Partly built | C0641 |
| REQ-0433 | The system shall provide rounding, handoff and sign-out tools. | Designed Not built | C0642 |
| REQ-0434 | The system shall provide pathways/protocols and order sets under clinical governance. | Designed Not built | C0643 |
| REQ-0435 | The system shall provide CDI query and response workflows. | Designed Not built | C0644 |
| REQ-0436 | The system shall support digital signature with ICP-Brasil certificates where the profile requires. | Designed Not built | C0645 |
| REQ-0437 | The system shall provide patient education library integration with language and reading-level metadata. | Designed Not built | C0646 |
Orders and CPOE (19)
Order entry, sets, communication, tracking, prior authorization.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-0501 | The system shall provide CPOE for medications, labs, imaging, procedures, referrals, nursing, diet, therapy, DME, blood and isolation. | Designed Placeholder only | C0647 |
| REQ-0502 | The system shall require ordering authority by role and licensure and shall restrict order types per role. | Pilot Partly built | C0648 |
| REQ-0503 | The system shall support order sets, panels, quick orders and preference lists with versioning. | Designed Not built | C0649 |
| REQ-0504 | The system shall support ask-at-order-entry questions. | Designed Not built | C0650 |
| REQ-0505 | The system shall support verbal/telephone orders with read-back and cosign deadlines. | Designed Not built | C0651 |
| REQ-0506 | The system shall support protocol/standing/pended/future/recurring orders. | Designed Not built | C0652 |
| REQ-0507 | The system shall track order status from ordered to final with a defined state machine. | Designed Not built | C0653 |
| REQ-0508 | The system shall emit and consume HL7 v2 orders/results and FHIR ServiceRequest/Task/DiagnosticReport. | Designed Not built | C0654 |
| REQ-0509 | The system shall check duplicate orders, medical necessity and authorization requirements. | Designed Not built | C0655 |
| REQ-0510 | The system shall show appropriate-use criteria for advanced imaging where required. | Designed Not built | C0656 |
| REQ-0511 | The system shall optionally display cost of care at order entry. | Designed Not built | C0657 |
| REQ-0512 | The system shall reconcile orders at transfer, admission and discharge. | Designed Not built | C0658 |
| REQ-0513 | The system shall verify consent before blood product orders. | Designed Not built | C0659 |
| REQ-0514 | The system shall support referral/consult orders with closed-loop tracking. | Designed Not built | C0660 |
| REQ-0515 | The system shall support DME/home-health/SNF orders with face-to-face documentation. | Designed Not built | C0661 |
| REQ-0516 | The system shall support electronic lab ordering to external networks and bi-directional interfaces. | Designed Not built | C0662 |
| REQ-0517 | The system shall support electronic prior authorization (X12 278, Da Vinci PAS, NCPDP ePA) and real-time prescription benefit. | Designed Not built | C0663 |
| REQ-0518 | The system shall provide order entry on approved mobile devices. | Designed Not built | C0664 |
| REQ-0519 | The system shall mark AI-generated order suggestions as drafts requiring explicit signature. | Designed Not built | C0665 |
Results management and diagnostic reporting (10)
Result review, acknowledgment, critical values, trending.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-0601 | The system shall provide a results inbox with acknowledgment and sign-off tracking. | Pilot Partly built | C0666 |
| REQ-0602 | The system shall record critical-value notification with read-back and callback documentation. | Pilot Partly built | C0667 |
| REQ-0603 | The system shall route results to ordering, PCP and covering providers with rules. | Designed Not built | C0668 |
| REQ-0604 | The system shall track pending results at discharge and assign owners. | Designed Not built | C0669 |
| REQ-0605 | The system shall release results to the patient per Cures Act rules with configurable delay for sensitive types. | Designed Not built | C0670 |
| REQ-0606 | The system shall provide trending/graphing, reference ranges by age/sex and delta checks. | Designed Not built | C0671 |
| REQ-0607 | The system shall incorporate outside lab results discretely with LOINC mapping. | Designed Not built | C0672 |
| REQ-0608 | The system shall link reports to images (DiagnosticReport to ImagingStudy). | Designed Not built | C0673 |
| REQ-0609 | The system shall support pathology synoptic reporting and genomic/molecular results. | Designed Not built | C0674 |
| REQ-0610 | The system shall ingest point-of-care results with operator and QC checks. | Designed Not built | C0675 |
Pharmacy, medication management and e-prescribing (22)
Medication orders, verification, dispensing, eMAR, prescribing, controlled substances.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-0701 | The system shall provide medication ordering with RxNorm coding, dose/route/frequency/indication and duration. | Designed Not built | C0676 |
| REQ-0702 | The system shall check drug-drug, drug-allergy, duplicate therapy, dose range, renal/hepatic and age/weight rules using a licensed knowledge base. | Designed Not built | C0677 |
| REQ-0703 | The system shall support weight/BSA and pediatric dosing calculators with recency checks on weight. | Designed Not built | C0678 |
| REQ-0704 | The system shall provide pharmacist verification queues. | Designed Not built | C0679 |
| REQ-0705 | The system shall provide eMAR with barcode medication administration. | Designed Placeholder only | C0680 |
| REQ-0706 | The system shall integrate IV pumps and dispensing cabinets via standards. | Designed Not built | C0681 |
| REQ-0707 | The system shall maintain medication lists with reconciliation at transitions. | Pilot Partly built | C0682 |
| REQ-0708 | The system shall retrieve external medication history (NCPDP RxHistory / Surescripts). | Designed Not built | C0683 |
| REQ-0709 | The system shall e-prescribe via NCPDP SCRIPT with version negotiation between 2017071 and 2023011 and shall use 2023011 exclusively for Part D by 2028-01-01. | Designed Not built | C0684 |
| REQ-0710 | The system shall support EPCS with DEA-required identity proofing, two-factor signing and audit. | Designed Not built | C0685 |
| REQ-0711 | The system shall query PDMP as required and record purpose. | Designed Not built | C0686 |
| REQ-0712 | The system shall check formulary/benefit (NCPDP F&B v60) and real-time benefit (RTPB v13). | Designed Not built | C0687 |
| REQ-0713 | The system shall support controlled-substance inventory, witness waste and diversion analytics. | Designed Not built | C0688 |
| REQ-0714 | The system shall support IV compounding, hazardous drug and non-sterile records. | Designed Not built | C0689 |
| REQ-0715 | The system shall support pharmacy inventory with par levels and recalls. | Designed Not built | C0690 |
| REQ-0716 | The system shall support antimicrobial stewardship, MTM and ADE reporting. | Designed Not built | C0691 |
| REQ-0717 | The system shall support specialty and discharge pharmacy workflows and refill requests. | Designed Not built | C0692 |
| REQ-0718 | The system shall support Brazil controlled prescriptions and digital prescribing rules. | Designed Not built | C0693 |
| REQ-0719 | The system shall support chemotherapy regimens with dose banding and independent double check. | Designed Not built | C0694 |
| REQ-0720 | The system shall support anticoagulation, insulin and TPN protocols. | Designed Not built | C0695 |
| REQ-0721 | The system shall support 340B tracking and split billing where applicable. | Designed Not built | C0696 |
| REQ-0722 | The system shall support drug shortage substitutions. | Designed Not built | C0697 |
Clinical decision support and alerts (10)
Rules, alerts, models, governance.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-0801 | The system shall provide rule-based alerts (drug, allergy, duplicate, dose, best-practice) with interruptive and non-interruptive modes. | Designed Not built | C0698 |
| REQ-0802 | The system shall record alert overrides with coded reasons and provide alert analytics. | Designed Not built | C0699 |
| REQ-0803 | The system shall support CDS Hooks and FHIR clinical reasoning (PlanDefinition, ActivityDefinition, CQL). | Designed Not built | C0700 |
| REQ-0804 | The system shall provide early-warning scores (NEWS, MEWS) and sepsis screening with model version display. | Designed Not built | C0701 |
| REQ-0805 | The system shall expose decision-support intervention source attributes for predictive models as required for certification. | Designed Not built | C0702 |
| REQ-0806 | The system shall provide health-maintenance reminders and immunization forecasting (CDC CDSi). | Designed Not built | C0703 |
| REQ-0807 | The system shall provide sound-alike/look-alike (Tall Man) display. | Designed Not built | C0704 |
| REQ-0808 | The system shall support pharmacogenomic decision support. | Designed Not built | C0705 |
| REQ-0809 | The system shall provide suicide risk screening alerts, SDOH screening and radiation dose alerts. | Designed Not built | C0706 |
| REQ-0810 | The system shall govern AI/predictive tools with a model inventory, validation and monitoring before enablement. | Designed Not built | C0707 |
Nursing and inpatient care (10)
Nursing documentation, tasks, restraints, LDA, handoff.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-0901 | The system shall provide nursing assessment flowsheets and care plans coded with NANDA-I/NIC/NOC or local equivalents. | Designed Not built | C0708 |
| REQ-0902 | The system shall provide task lists by due time with overdue escalation. | Designed Not built | C0709 |
| REQ-0903 | The system shall integrate bedside devices (monitors, ventilators, ECG) via IEEE 11073/IHE PCD-01. | Designed Not built | C0710 |
| REQ-0904 | The system shall document restraint/seclusion per regulatory requirements including time limits and monitoring. | Designed Not built | C0711 |
| REQ-0905 | The system shall document intake/output, LDA, wounds, falls and isolation. | Pilot Partly built | C0712 |
| REQ-0906 | The system shall provide shift handoff reports. | Designed Not built | C0713 |
| REQ-0907 | The system shall support virtual nursing/sitter sessions without retaining video by default. | Designed Not built | C0714 |
| REQ-0908 | The system shall support electronic whiteboards with minimal identifiers. | Designed Not built | C0715 |
| REQ-0909 | The system shall support case management, discharge planning and utilization review tools. | Designed Not built | C0716 |
| REQ-0910 | The system shall support SEP-1 and inpatient eCQM abstraction. | Designed Not built | C0717 |
Emergency department (9)
Triage, tracking, ED workflows, time metrics.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-1001 | The system shall provide ED triage using ESI, CTAS or Manchester with site-selected scale. | Designed Not built | C0718 |
| REQ-1002 | The system shall provide an ED tracking board with configurable statuses and time clocks. | Designed Not built | C0719 |
| REQ-1003 | The system shall support provider-in-triage, fast-track and quick registration. | Designed Not built | C0720 |
| REQ-1004 | The system shall provide ED order sets for chest pain, stroke, sepsis, trauma. | Designed Not built | C0721 |
| REQ-1005 | The system shall track stroke and STEMI time metrics. | Designed Not built | C0722 |
| REQ-1006 | The system shall ingest EMS prehospital data (NEMSIS/ePCR). | Designed Not built | C0723 |
| REQ-1007 | The system shall document EMTALA screening and transfer. | Designed Not built | C0724 |
| REQ-1008 | The system shall provide ED throughput analytics. | Designed Not built | C0725 |
| REQ-1009 | The system shall support Brazilian Pronto Atendimento risk classification. | Designed Not built | C0726 |
Inpatient, critical care, surgery and anesthesia (11)
Hospital medicine, ICU, periop.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-1101 | The system shall support admission H&P, hospital course auto-summary and discharge summary workflows. | Designed Not built | C0727 |
| REQ-1102 | The system shall support critical care flowsheets, ICU scores and bundles. | Designed Not built | C0728 |
| REQ-1103 | The system shall integrate telemetry/ECG alarm management. | Designed Not built | C0729 |
| REQ-1104 | The system shall support ECMO, CRRT and dialysis documentation. | Designed Not built | C0730 |
| REQ-1105 | The system shall support transplant and palliative documentation. | Designed Not built | C0731 |
| REQ-1106 | The system shall support surgical case booking, preference cards, counts, time-outs and intraoperative records. | Designed Not built | C0732 |
| REQ-1107 | The system shall track implants with UDI. | Designed Not built | C0733 |
| REQ-1108 | The system shall support operative notes with synoptic templates and anesthesia records with device integration. | Designed Not built | C0734 |
| REQ-1109 | The system shall support PACU documentation with recovery scores. | Designed Not built | C0735 |
| REQ-1110 | The system shall support OR scheduling optimization and block utilization analytics. | Designed Not built | C0736 |
| REQ-1111 | The system shall support sterile processing instrument tracking integration. | Designed Not built | C0737 |
Radiology, imaging, PACS/RIS and DICOM (14)
Ordering to reporting for imaging; on-site image store.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-1201 | The system shall provide RIS worklists, protocoling and reading queues. | Designed Not built | C0756 |
| REQ-1202 | The system shall provide DICOM Modality Worklist and MPPS for modalities. | Designed Not built | C0757 |
| REQ-1203 | The system shall receive DICOM C-STORE, support C-FIND/C-MOVE/C-GET and Storage Commitment over TLS with AE allow-lists. | Designed Not built | C0758 |
| REQ-1204 | The system shall implement DICOMweb QIDO-RS, WADO-RS, STOW-RS and UPS-RS. | Designed Not built | C0759 |
| REQ-1205 | The system shall store DICOM SR, RDSR, GSPS and KOS objects and render them. | Designed Not built | C0760 |
| REQ-1206 | The system shall reconcile patient identity between modality and ADT (IHE PIR) before filing. | Designed Not built | C0761 |
| REQ-1207 | The system shall provide a zero-footprint enterprise viewer inside the terminal live feed. | Designed Not built | C0762 |
| REQ-1208 | The system shall integrate VNA/PACS and image exchange (CD import, cloud share) with quarantine and AV scanning. | Designed Not built | C0763 |
| REQ-1209 | The system shall support structured reporting (RSNA RadReport, BI-RADS and other -RADS systems) and follow-up recommendation tracking. | Designed Not built | C0764 |
| REQ-1210 | The system shall record radiation dose and provide dose alerts. | Designed Not built | C0765 |
| REQ-1211 | The system shall support mammography tracking and MQSA reporting. | Designed Not built | C0766 |
| REQ-1212 | The system shall communicate critical imaging results with closed-loop acknowledgment. | Designed Not built | C0767 |
| REQ-1213 | The system shall support teleradiology and AI image triage as clearly labeled decision support. | Designed Not built | C0768 |
| REQ-1214 | The system shall support contrast, pregnancy and renal screening at imaging scheduling. | Designed Not built | C0769 |
Laboratory, pathology, microbiology and blood bank (14)
LIS functions on-site.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-1301 | The system shall provide lab order entry with specimen requirements and AOE. | Designed Not built | C0770 |
| REQ-1302 | The system shall support barcode specimen collection, accessioning, tracking and chain of custody. | Designed Not built | C0771 |
| REQ-1303 | The system shall interface with analyzers via ASTM E1381/E1394 (LIS2-A2) and CLSI AUTO/POCT1. | Designed Not built | C0772 |
| REQ-1304 | The system shall provide autoverification, delta checks, reflex testing and add-on orders under lab-director-approved rules. | Designed Not built | C0773 |
| REQ-1305 | The system shall support QC (Levey-Jennings, Westgard) and proficiency testing. | Designed Not built | C0774 |
| REQ-1306 | The system shall support CLIA/CAP/COLA compliance records. | Designed Not built | C0775 |
| REQ-1307 | The system shall support microbiology workflows with AST/MIC interpretation and antibiogram. | Designed Not built | C0776 |
| REQ-1308 | The system shall support anatomic pathology (gross, histology, cytology, frozen) and digital pathology integration. | Designed Not built | C0777 |
| REQ-1309 | The system shall support molecular/genomic workflows and variant reporting with HGVS/HGNC. | Designed Not built | C0778 |
| REQ-1310 | The system shall support blood bank typing, crossmatch, inventory, ISBT 128 labeling and bedside verification. | Designed Not built | C0779 |
| REQ-1311 | The system shall support outreach and send-out lab management. | Designed Not built | C0780 |
| REQ-1312 | The system shall report to public health (ELR, newborn screening). | Designed Not built | C0781 |
| REQ-1313 | The system shall maintain the lab test catalog with LOINC mappings, and lab inventory, workload and TAT dashboards. | Designed Not built | C0782 |
| REQ-1314 | The system shall support HL7 LOI/LRI and eDOS profiles. | Designed Not built | C0783 |
Cardiology, oncology, obstetrics, pediatrics, behavioral, dental, ophthalmology, rehab (9)
Specialty content packs.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-1401 | The system shall support ECG management, cath lab, echo, device clinic and registry data collection. | Designed Not built | C0738 |
| REQ-1402 | The system shall support oncology regimens, staging (AJCC), infusion scheduling, radiation oncology integration, tumor boards and cancer registry feeds. | Designed Not built | C0739 |
| REQ-1403 | The system shall support prenatal, labor and delivery, fetal monitoring, newborn and postpartum documentation. | Designed Not built | C0740 |
| REQ-1404 | The system shall support pediatrics: growth charts, immunization schedule, weight-based safeguards, developmental screening and adolescent confidentiality. | Designed Not built | C0741 |
| REQ-1405 | The system shall support Latin American perinatal records (Historia Clínica Perinatal CLAP, Cartão da Gestante). | Designed Not built | C0742 |
| REQ-1406 | The system shall support behavioral health: safety plans, group therapy, measurement-based care, involuntary hold documentation and 42 CFR Part 2 consent management. | Designed Not built | C0743 |
| REQ-1407 | The system shall support dental charting with tooth numbering and CDT coding. | Designed Not built | C0744 |
| REQ-1408 | The system shall support ophthalmology exam data and device integration. | Designed Not built | C0745 |
| REQ-1409 | The system shall support rehabilitation, home health, hospice and long-term care assessments (IRF-PAI, OASIS, MDS). | Designed Not built | C0746 |
Population health, registries and quality measurement (5)
Cohorts, registries, quality reports.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-1501 | The system shall build cohorts and registries from structured data without exporting identifiers unless authorized. | Designed Not built | C0751 |
| REQ-1502 | The system shall compute eCQMs with CQL and value sets and produce QRDA I/III. | Designed Not built | C0752 |
| REQ-1503 | The system shall provide risk stratification and gaps-in-care lists. | Designed Not built | C0753 |
| REQ-1504 | The system shall support immunization registry reporting and query. | Designed Not built | C0754 |
| REQ-1505 | The system shall produce the reports in the reference catalogs through the report engine using registry-defined report definitions. | Designed Not built | C0755 |
Care management, care coordination and referral (4)
Referral loops, care plans, community resources.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-1601 | The system shall manage referrals with loop closure and status tracking across internal and external recipients. | Designed Not built | C0747 |
| REQ-1602 | The system shall support care plans, care teams and shared goals with patient view. | Designed Not built | C0748 |
| REQ-1603 | The system shall support SDOH screening, community resource referral and Gravity value sets. | Designed Not built | C0749 |
| REQ-1604 | The system shall support transitions of care (C-CDA/Direct/HIE) with reconciliation. | Designed Not built | C0750 |
Patient portal, wallet and telehealth (8)
Patient-facing surfaces (app, portal, wallet).
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-1701 | The system shall provide a patient portal and wallet app for records view, messages, scheduling, forms, payments, proxy access and consent. | Designed Not built | C0802 |
| REQ-1702 | The system shall present a patient-visible access history derived from ledger audit batches. | Designed Not built | C0803 |
| REQ-1703 | The system shall support patient-initiated records requests with identity verification and automatic fulfilment through the consent flow. | Designed Not built | C0804 |
| REQ-1704 | The system shall support proxy/guardian access with scoped views and age-based transitions (adolescent). | Designed Not built | C0805 |
| REQ-1705 | The system shall support secure telehealth video visits (WebRTC) with recording off by default and consent capture. | Designed Not built | C0806 |
| REQ-1706 | The system shall support remote patient monitoring and wearable data intake flagged as patient-reported. | Designed Not built | C0807 |
| REQ-1707 | The system shall provide SMART Health Cards / Links for vaccination and summary data. | Designed Not built | C0808 |
| REQ-1708 | The system shall support patient payment (card, PIX, local methods) via certified processors that never store card data in the record. | Designed Not built | C0809 |
Revenue cycle, billing and payer connectivity (7)
Charges, claims, remittance, denials.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-1801 | The system shall capture charges from documentation and orders with charge master validation. | Designed Not built | C0810 |
| REQ-1802 | The system shall generate and submit X12 837P/837I/837D with SNIP-style edits and receive 999/277CA/835. | Designed Not built | C0811 |
| REQ-1803 | The system shall support 270/271, 276/277 and 278 transactions. | Designed Not built | C0812 |
| REQ-1804 | The system shall post remittances (835), manage denials/appeals and patient statements. | Designed Not built | C0813 |
| REQ-1805 | The system shall support Brazil TISS XML guides with digital signature and SUS billing; Colombia RIPS/FEV/CUV; Mexico CFDI; other country billing adapters. | Designed Not built | C0814 |
| REQ-1806 | The system shall support price transparency files and Good Faith Estimates. | Designed Not built | C0815 |
| REQ-1807 | The system shall support payer-platform functions: contract modeling, eligibility, prior authorization APIs (CMS-0057-F). | Designed Not built | C0816 |
Supply chain, HR and facilities (4)
Materials, staffing, credentialing, environment of care.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-1901 | The system shall manage materials, inventory, par levels and implant/consignment tracking. | Designed Not built | C0817 |
| REQ-1902 | The system shall support GS1 barcodes (GTIN, SSCC, DataMatrix). | Designed Not built | C0818 |
| REQ-1903 | The system shall manage workforce credentialing, licensure, certifications and expiry alerts. | Designed Not built | C0819 |
| REQ-1904 | The system shall record environment-of-care logs, life-safety tests, equipment maintenance and radiation safety records. | Designed Not built | C0820 |
Analytics, reporting and data warehouse (3)
Reports and dashboards under minimum necessary.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-2001 | The system shall provide a report engine with role-limited definitions, scheduling and small-cell suppression. | Designed Not built | C0821 |
| REQ-2002 | The system shall provide operational dashboards (census, throughput, utilization, quality). | Designed Not built | C0822 |
| REQ-2003 | The system shall provide research/analytics extracts only as limited datasets or de-identified datasets under DUA and approval. | Designed Not built | C0823 |
Interoperability and exchange (13)
Standards-based exchange (details in file 04).
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-2101 | The system shall provide an interface engine supporting MLLP/TCP, HTTPS, SFTP, SOAP and message queues with transformation, routing, retry and dead-letter queues. | Designed Not built | C0784 |
| REQ-2102 | The system shall implement the HL7 v2 message families and segments in file 04 with configurable profiles. | Designed Not built | C0785 |
| REQ-2103 | The system shall implement FHIR R4 (4.0.1) REST server, search, operations, US Core 6.1.0 profiles and SMART App Launch 2.0.0. | Designed Not built | C0786 |
| REQ-2104 | The system shall implement FHIR Bulk Data export subject to quorum approval and limiter rules. | Designed Not built | C0787 |
| REQ-2105 | The system shall create, receive and reconcile C-CDA R2.1 documents and support EHI export. | Designed Not built | C0788 |
| REQ-2106 | The system shall support IHE XDS.b, XCA, XCPD, PIX/PDQ, ATNA, MHD profiles. | Designed Not built | C0789 |
| REQ-2107 | The system shall support TEFCA (QHIN participant/subparticipant) using document query and Facilitated FHIR with UDAP security and Exchange Purpose codes. | Designed Not built | C0790 |
| REQ-2108 | The system shall support Carequality and CommonWell connectivity through a partner or direct implementation. | Designed Not built | C0791 |
| REQ-2109 | The system shall support Direct Secure Messaging. | Designed Not built | C0792 |
| REQ-2110 | The system shall support X12 and NCPDP transactions in file 04. | Designed Not built | C0793 |
| REQ-2111 | The system shall support DICOM, IEEE 11073, POCT1, ASTM device interfaces. | Designed Not built | C0794 |
| REQ-2112 | The system shall provide LatAm interfaces: RNDS (BR), IHCE/RDA (CO), NOM-024 (MX), RENIPRESS/SIS (PE), FONASA (CL), Receta electrónica (AR) as adapters. | Designed Not built | C0795 |
| REQ-2113 | The system shall provide conformance-tooling hooks (validators, ONC/Inferno, HL7 validator) in CI. | Designed Not built | C0796 |
Security, privacy, consent, audit and access control (9)
See file 05; requirements repeated here as functional IDs.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-2201 | The system shall enforce access as role AND relationship AND purpose AND context AND consent AND risk AND quota for every read, write, print and export. | Pilot Partly built | C0879 |
| REQ-2202 | The system shall support RBAC, ABAC and ReBAC with a central policy decision point and local enforcement points. | Pilot Partly built | C0880 |
| REQ-2203 | The system shall provide break-glass emergency access with reason code, time limit, notifications and mandatory review. | Pilot Partly built | C0881 |
| REQ-2204 | The system shall segment sensitive data into compartments with separate keys and policies (psychotherapy, SUD, HIV/STI, reproductive health, genetic, minors, VIP). | Designed Not built | C0882 |
| REQ-2205 | The system shall provide HIPAA privacy operations: accounting of disclosures, ROI, amendments, restrictions, breach workflow. | Pilot Partly built | C0883 |
| REQ-2206 | The system shall provide patient-facing access reports and consent directives (opt-in/opt-out for HIE, research). | Designed Not built | C0884 |
| REQ-2207 | The system shall support data segmentation for privacy (HL7 DS4P labels). | Designed Not built | C0885 |
| REQ-2208 | The system shall provide de-identification, pseudonymization and tokenization services. | Designed Not built | C0886 |
| REQ-2209 | The system shall support LGPD, GDPR, HIPAA and Peru Ley 29733 configurations including subject-rights workflows. | Designed Not built | C0887 |
Identity, authentication and single sign-on (7)
FIDO2, badge, SSO, provisioning.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-2251 | The system shall authenticate workforce with FIDO2 hardware key plus badge (or PIN plus badge) and phishing-resistant flows. | Pilot Partly built | C0888 |
| REQ-2252 | The system shall enforce session binding, idle timeouts, walk-away lock and single concurrent session per identity. | Pilot Partly built | C0889 |
| REQ-2253 | The system shall integrate with directory services via SAML/OIDC/LDAP/SCIM for provisioning where a customer has one. | Designed Not built | C0890 |
| REQ-2254 | The system shall support badge tap-and-go (NFC/UWB) authentication and CCOW-style context sharing. | Designed Not built | C0891 |
| REQ-2255 | The system shall verify provider identity (NPI, DEA, licence) at credentialing. | Designed Not built | C0892 |
| REQ-2256 | The system shall support patient authentication via wallet passkeys and government IdPs. | Designed Not built | C0893 |
| REQ-2257 | The system shall support service account authorization with mTLS SVIDs. | Designed Not built | C0894 |
Infrastructure, downtime, administration and support (9)
See file 07.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-2301 | The system shall run on the single-cabinet on-site server with local operation independent of the internet. | Designed Placeholder only | C0857 |
| REQ-2302 | The system shall provide downtime mode with read-only emergency data set and paper downtime forms. | Designed Not built | C0858 |
| REQ-2303 | The system shall provide backup, restore and DR per file 07 tiers. | Designed Not built | C0859 |
| REQ-2304 | The system shall provide interface monitoring, application performance monitoring and audit dashboards. | Designed Not built | C0860 |
| REQ-2305 | The system shall support scheduled maintenance with signed updates and rollback. | Designed Not built | C0861 |
| REQ-2306 | The system shall provide data migration tooling: MPI cleanup, C-CDA/HL7 replay, chart abstraction, archive viewer. | Designed Not built | C0862 |
| REQ-2307 | The system shall provide training environments, proficiency tracking and support portals. | Designed Not built | C0863 |
| REQ-2308 | The system shall support printing and label infrastructure (Zebra ZPL, PDF, direct-attached printers). | Designed Not built | C0864 |
| REQ-2309 | The system shall support peripherals: barcode scanners, badge readers, signature pads, card readers, cameras where allowed. | Designed Not built | C0865 |
Mobile, bedside and point-of-care (4)
Tablets and handhelds.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-2351 | The system shall provide sealed tablet terminals as thin clients displaying a server-rendered live feed with no persistent data. | Pilot Partly built | C0866 |
| REQ-2352 | The system shall provide bedside barcode scanning and mobile documentation on approved devices with server-rendered display. | Designed Not built | C0867 |
| REQ-2353 | The system shall support offline-first capture only through the on-site server and local wired/wireless LAN; no PHI is stored on mobile devices. | Designed Not built | C0868 |
| REQ-2354 | The system shall support mobile secure messaging and push notifications through the system-wide messaging service. | Pilot Partly built | C0869 |
AI, ambient documentation and automation (4)
Draft-only AI.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-2401 | AI features shall be off by default, enabled per facility with model inventory entry and validation evidence. | Designed Not built | C0870 |
| REQ-2402 | AI outputs shall be labeled, cited to source elements, and never auto-filed or auto-signed. | Designed Not built | C0871 |
| REQ-2403 | AI inference shall run on-site or in a customer-approved region; PHI shall not be used to train models without separate written approval. | Designed Not built | C0872 |
| REQ-2404 | The system shall log AI inputs/outputs by reference hash and model version. | Designed Not built | C0873 |
Research and clinical trials (2)
IRB, consent, trials.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-2451 | The system shall support research consent (eConsent), IRB documents, participant recruitment, CTMS integration, biospecimen tracking and clinical-trial billing separation. | Designed Not built | C0824 |
| REQ-2452 | The system shall support research datasets (limited/de-identified/OMOP) under DUA. | Designed Not built | C0825 |
Public health reporting (3)
Registries and surveillance.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-2501 | The system shall support eCR (eICR/RR), ELR, syndromic surveillance, IIS, cancer, trauma, stroke, cardiac, PDMP, NHSN, vital records and NEMSIS reporting as configured by jurisdiction. | Designed Not built | C0826 |
| REQ-2502 | The system shall receive HAN/public-health alerts. | Designed Not built | C0827 |
| REQ-2503 | The system shall support DHIS2 aggregate export (ADX/DXF2) and OpenMRS/Bahmni/FHIR exchange for low-resource deployments. | Designed Not built | C0828 |
Regulatory, compliance and certification support (3)
Compliance evidence.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-2551 | The system shall maintain a compliance calendar of licenses, accreditations, certificates, drills and filings with expiry alerts. | Designed Not built | C0829 |
| REQ-2552 | The system shall support information-blocking exception documentation and Cures Act tooling. | Designed Not built | C0830 |
| REQ-2553 | The system shall support ONC certification test data and real-world testing evidence. | Designed Not built | C0831 |
Federated ledger, spheres, tokens, wallets, bridges (15)
Only hashes, consent and audit on the ledger.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-3001 | The ledger shall store only: salted record commitments, consent tokens and metadata, audit batch roots, authority/transfer records, wallet and token state, node presence, alerts and tombstones. Patient content, names, national ids and raw clinical values shall never be written. | Designed Not built | C0922 |
| REQ-3002 | Each clinic or clinic network shall be one sphere with its own ledger channel, membership registry and governance keys. | Designed Not built | C0923 |
| REQ-3003 | The system shall implement the token types ID, ROLE, CONS, GRANT, XFER, BRG-A/BRG-B, NODE, ALERT, BG and DELEG with the semantics in design 11.5, all non-transferable except through protocol operations. [Recommended: types from design 11.5; owner must confirm the final list] | Designed Not built | C0924 |
| REQ-3004 | The system shall support mintable wallets of classes W-P, W-D, W-S, W-N, W-B, W-G with minting by quorum, identity binding, expiry and rate limits. | Designed Not built | C0925 |
| REQ-3005 | Sensitive ledger actions shall require multi-key corroboration by a role-diverse policy; the numeric threshold is [Open] (the design example is 2-of-{clinical lead, privacy officer, security officer}). | Designed Not built | C0926 |
| REQ-3006 | Bridges between spheres shall use exactly two mirrored bridge tokens with history on both sides, two-phase commit with time locks and defined failure states. | Designed Not built | C0927 |
| REQ-3007 | Session risk bands (0-3) may use keystroke cadence, location and timestamp; keystroke cadence shall be a review flag only and never a sole lockout trigger. | Designed Not built | C0928 |
| REQ-3008 | Consent tokens shall be signed by the patient wallet (or delegate) over canonical bytes including the hash of the rendered text and shall be revocable with immediate ledger effect. | Designed Not built | C0929 |
| REQ-3009 | Record commitments shall be H(salt‖digest) with per-record 128-bit+ random salts held off-ledger. | Designed Not built | C0930 |
| REQ-3010 | Patient pseudonyms shall be HMAC(K_sphere, id‖r_patient) so that destroying r_patient severs linkage. | Designed Not built | C0931 |
| REQ-3011 | Cryptographic erasure shall destroy DEK, salts and r_patient by quorum, write a tombstone and verify undecryptability. | Designed Not built | C0932 |
| REQ-3012 | The ledger client shall queue writes when the ledger is unreachable and append them in order on reconnect; care shall not depend on ledger availability. | Designed Not built | C0933 |
| REQ-3013 | Signature algorithm identifiers shall be carried in every ledger message to allow crypto agility including hybrid PQC. | Designed Not built | C0934 |
| REQ-3014 | Ledger technology is baseline Hyperledger Fabric; the system shall isolate the ledger behind a service interface so that a signed hash-chained log with threshold anchors can replace it for single-owner spheres. | Designed Not built | C0935 |
| REQ-3015 | Home nodes and node presence tokens shall provide liveness attestation and out-of-schedule flagging to all nodes. | Designed Not built | C0936 |
Sync, backup, read limiter and safe degradation (14)
Cloud sync and clinic-to-clinic sync; limiter; pause.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-3101 | The on-site database shall be the operational primary; the cloud copy is an encrypted backup replica. | Designed Not built | C0937 |
| REQ-3102 | The sync agent shall produce signed, hash-chained, encrypted change bundles with gapless sequence numbers, replay protection and resumable upload. | Designed Not built | C0938 |
| REQ-3103 | The sync pathway shall support cloud sync and, where allowed by profile and consent, clinic-to-clinic sync. | Designed Not built | C0939 |
| REQ-3104 | A read-side limiter on a node en route to the server shall limit reads and pulls (not writes) using oscillating time windows. Window length, oscillation pattern and per-role/per-terminal quotas are [Open]. | Designed Not built | C0940 |
| REQ-3105 | Tripping the limiter shall pause only cloud sync and clinic-to-clinic sync; local operation shall continue unaffected. | Designed Not built | C0941 |
| REQ-3106 | Any integrity alarm shall also pause sync (safe-degrade). | Designed Not built | C0942 |
| REQ-3107 | Resuming sync after a pause shall require multi-key corroboration and an audit entry. | Designed Not built | C0943 |
| REQ-3108 | The system shall pad bundle sizes and add batching jitter as a limited traffic-analysis countermeasure. | Designed Not built | C0944 |
| REQ-3109 | The system shall implement 3-2-1-1-0 backup tiers T0-T5 with immutable copy and offline copy, and shall anchor backup ranges on the ledger. | Designed Not built | C0945 |
| REQ-3110 | Restore shall run in an isolated environment with signature/chain verification and dual authorization for promotion. | Designed Not built | C0946 |
| REQ-3111 | Erasure requests shall propagate as tombstone bundles and key destruction events. | Designed Not built | C0947 |
| REQ-3112 | The scroll-rate lock shall require re-authentication when history-tab throughput exceeds the threshold [Open], computed server-side by information rendered, with different weights for HISTORY and RESULTS_TRIAGE. | Designed Not built | C0948 |
| REQ-3113 | Emergency mode shall relax history limits with full logging and no password prompt for patients in a declared emergency. | Designed Not built | C0949 |
| REQ-3114 | Bulk export by an individual shall be disabled; bulk operations shall run only through the quorum-approved Bulk Operation Workflow. | Designed Not built | C0950 |
Offline behavior and printing (7)
Local operation, offline printing.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-3201 | When sync or server transfer is down, the on-site main computer shall continue full clinical operation and shall be able to print records. | Designed Not built | C0951 |
| REQ-3202 | Printing shall use a wired, non-networked printer directly attached to the main computer (or print server on the closed LAN with no route outside). | Designed Not built | C0952 |
| REQ-3203 | Every print job shall be an audit event with user, hashed patient reference, time and terminal, queued locally while offline and appended to the ledger on reconnect. | Designed Not built | C0953 |
| REQ-3204 | Printed pages shall carry a watermark with user and time; the exact format is [Open]. | Designed Not built | C0954 |
| REQ-3205 | Print rate limiting shall be enforced per user and terminal; values are [Open] (design example 50 prints/day per user, PROPOSED). | Designed Not built | C0955 |
| REQ-3206 | Printing of C4 compartment content shall require purpose and step-up. | Designed Not built | C0956 |
| REQ-3207 | Printed downtime reports shall be locked, sealed, logged and shredded on refresh. | Designed Not built | C0957 |
On-site server, sealed terminals, hardware profile (7)
Physical system.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-3301 | One closed-loop server per small hospital in a single cabinet; larger sites use multi-node clusters. | Designed Not built | C0958 |
| REQ-3302 | Terminals shall be sealed, input-only thin clients that store nothing and show a live feed, with waterproof rubber case, hinged waterproof keyboard, cooling fins and sleeved USB. | Designed Not built | C0959 |
| REQ-3303 | Terminal USB shall be electrically gated: allow-listed VID/PID, HID/CCID classes only, disabled in strict tier. | Designed Not built | C0960 |
| REQ-3304 | Camera-resistant screens shall use side-angle privacy filtering and the refresh-pattern measure; effectiveness against real cameras is untested and shall not be claimed until measured. | Designed Not built | C0961 |
| REQ-3305 | Terminals shall attest to the server at boot and per session (TPM/secure element) and refuse to render on mismatch. | Designed Not built | C0962 |
| REQ-3306 | Tamper switches shall zeroize keys and alert. | Designed Not built | C0963 |
| REQ-3307 | Equipment sold by AuroraMed shall be tracked as assets with serial, warranty and installed location. | Designed Not built | C0964 |
Server-to-server transfer, three streams (5)
Secret-shared, decoy-padded transfer.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-3401 | Server-to-server clinical data transfer shall use three simultaneous streams with interleaved decoy traffic and secret sharing so no single stream carries decryptable content. | Designed Not built | C0965 |
| REQ-3402 | The transfer shall use AES-256-GCM or ChaCha20-Poly1305 for data and hybrid X25519 + ML-KEM for key exchange. | Designed Not built | C0966 |
| REQ-3403 | The system shall document that decoys provide traffic-analysis resistance and not confidentiality or quantum resistance. | Designed Not built | C0967 |
| REQ-3404 | Transfer shall be authorized by an authority record and ledger transaction before any data leaves; the package commitment is recorded on both sides. | Designed Not built | C0968 |
| REQ-3405 | Transfer anomalies (stall, rate deviation, decoy ratio mismatch) shall abort the transfer and alert. | Designed Not built | C0969 |
Analog timing layer (4)
Least mature component.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-3501 | The analog timing layer, if built, shall be a separate optional module confined to one shielded room or booth with dual-key refreshing codes, delay paths and a home node. | Designed Not built | C0970 |
| REQ-3502 | Out-of-schedule signals shall be flagged to all nodes. | Designed Not built | C0971 |
| REQ-3503 | The layer shall never be the only lock, shall tolerate clock drift with configured windows, shall provide emergency break-glass, and shall use redundant home nodes. | Designed Not built | C0972 |
| REQ-3504 | Construction, refresh interval and delay values are [Open]; hardware is untested and no security claim shall be made about it. | Designed Not built | C0973 |
Tiers, entitlements and commercial features (4)
Prices scale by tier; contact us for pricing.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-3601 | The system shall implement entitlement records for the small, medium and large tiers (pricing not published). | Designed Not built | C0853 |
| REQ-3602 | The small tier shall be designed for about 20 patients maximum; how the limit is enforced (hard cap, soft alert) is [Open]. | Designed Not built | C0854 |
| REQ-3603 | Tier shall not reduce legal-minimum privacy or security controls. | Pilot Partly built | C0855 |
| REQ-3604 | Support-reserve or support fee for small tier is [Open]; the software shall support recording a support fee if adopted. | Designed Not built | C0856 |
Transport orders (Elyria integration) (5)
Only integration with Elyria Drone Shipping.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-3701 | Clinics shall be able to create transport orders from a terminal for Elyria Drone Shipping, a separate company, through a defined external interface. | Designed Not built | C0797 |
| REQ-3702 | The order shall carry cargo class, origin, destination, requested time and handling requirements only; no PHI beyond the minimum needed (for example a specimen accession number) unless a BAA and profile allow. | Designed Not built | C0798 |
| REQ-3703 | Chain-of-custody events (pickup, handoff, delivery, temperature excursion, incident) shall be audit events and shown on the order. | Designed Not built | C0799 |
| REQ-3704 | Specimens and blood shall be enabled only when Elyria certified cold-chain capability is configured. | Designed Not built | C0800 |
| REQ-3705 | Results shall return to the clinic through the normal results interface. | Designed Not built | C0801 |
System-wide platform services (4)
Common services.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-3801 | The system shall provide a common event bus, job scheduler, notification service, document renderer (PDF/A) and search index, all running on-site. | Pilot Partly built | C0849 |
| REQ-3802 | Global search shall respect the read limiter, minimum necessary, and audit each query with criteria hashed. | Designed Not built | C0850 |
| REQ-3803 | The system shall provide a generic clinical timeline/event store from which patient-visible access history and audit reports are derived. | Designed Not built | C0851 |
| REQ-3804 | The system shall provide time synchronization (NTS/PPS) with skew alarms. | Designed Not built | C0852 |
System-wide instant messaging (7)
Internal only.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-4001 | Instant messaging shall be system-wide only: a message can be sent only to another workforce user or group of the same deployment/sphere. External addresses shall be impossible by construction. | Pilot Built at MVP scope | C0977 |
| REQ-4002 | The IM shall support direct, group/channel and patient-linked threads with membership rules per file 06. | Pilot Partly built | C0978 |
| REQ-4003 | The IM shall run on-site and work with the WAN down. | Designed Placeholder only | C0979 |
| REQ-4004 | IM shall carry delivery, read and acknowledgment receipts and audit MSG_READ events. | Pilot Partly built | C0980 |
| REQ-4005 | IM attachments shall be scanned and limited by class; PHI images follow media rules. | Designed Not built | C0981 |
| REQ-4006 | IM retention shall be configurable by class within legal minimums; clinical content in patient-linked threads follows the clinical retention rule. | Designed Not built | C0982 |
| REQ-4007 | IM shall never suppress or delay a code alert; presence DND shall not affect code alerts. | Pilot Built at MVP scope | C0983 |
Memo Desk (6)
In-house long-form correspondence inbox.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-4101 | Memo Desk shall provide an internal long-form correspondence inbox with subject, rich text body, attachments, threads, folders, priority, due date and confidentiality level. | Pilot Partly built | C0984 |
| REQ-4102 | Memo Desk shall be internal only, signed by the sender session, and shall support shared pool inboxes with owners. | Pilot Partly built | C0985 |
| REQ-4103 | Memo Desk shall support formal notices with read-required acknowledgment recorded as a signature. | Pilot Partly built | C0986 |
| REQ-4104 | Memo Desk shall support legal hold on threads and retention classes. | Designed Placeholder only | C0987 |
| REQ-4105 | Memo Desk shall support delegation and coverage rules with expiry. | Designed Not built | C0988 |
| REQ-4106 | Memo Desk shall not be used for urgent clinical notifications; it shall show a banner recommending the alert path for urgent items. | Pilot Built at MVP scope | C0989 |
Code and clinical alert notifications (12)
Codes, critical results, emergency/urgent/standard pings.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-4201 | The system shall support alert classes CODE, CLINICAL-CRITICAL (lab, imaging, blood), PING-EMERGENCY, PING-URGENT and PING-STANDARD with defined priority levels, ack rules and escalation. | Pilot Built at MVP scope | C0990 |
| REQ-4202 | Code alerts shall be configurable per facility: name, color, meaning, script, audience, sound, lockdown and integration actions. No code meaning shall be hard-coded as universal. | Pilot Partly built | C0991 |
| REQ-4203 | The system shall ship a default code library (Code Blue, Red, Pink, Purple, Silver, Active Shooter/Imminent Threat, Gray, Black, Orange, Yellow, Green, White, Triage, Amber, Rapid Response, Stroke, STEMI, Trauma, Sepsis, Massive Transfusion) as editable templates with no asserted universal meaning. | Pilot Built at MVP scope | C0992 |
| REQ-4204 | Imminent Threat / Active Shooter alerts shall have the highest priority, override all DND and screen locks, support silent (non-audible) mode, and be cancellable only by two authorized roles. | Pilot Partly built | C0993 |
| REQ-4205 | Code alerts shall work with the WAN and cloud unavailable, using only the on-site server and local network. | Designed Placeholder only | C0994 |
| REQ-4206 | Critical lab/imaging/blood alerts shall reach the responsible clinician with acknowledgment tracking and escalation to an alternate if not acknowledged within the configured time [Open]. | Pilot Partly built | C0995 |
| REQ-4207 | Alert delivery shall be at-least-once with de-duplication, ordered per alert, with delivery receipts, and shall fall back across channels (terminal, tablet, pager/radio/phone gateway where installed). | Pilot Partly built | C0996 |
| REQ-4208 | Alert payloads to non-terminal channels (pager, SMS) shall contain no PHI by default. | Designed Not built | C0997 |
| REQ-4209 | Alert actions shall be audit events: send, delivered, read, ack, escalate, cancel, all-clear. | Pilot Built at MVP scope | C0998 |
| REQ-4210 | The system shall support code drills that reuse the alert path with a DRILL flag and record timings. | Pilot Partly built | C0999 |
| REQ-4211 | Alert acknowledgment on sealed tablets shall be one-touch with accessibility support (large targets, audible, vibration where the device has it). | Pilot Partly built | C1000 |
| REQ-4212 | Alert policy changes shall require dual control and be versioned. | Pilot Partly built |
Privacy operations and patient rights (5)
LGPD/HIPAA/GDPR/Ley 29733 workflows.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-4301 | The system shall provide workflows for access, correction/amendment, deletion/anonymization (crypto-erasure), portability, consent revocation, restriction/objection, information about sharing, and complaints. | Designed Not built | C0911 |
| REQ-4302 | The system shall target records-request fulfilment materially faster than the 72-hour norm through the consent flow; legal-review steps are not compressed. | Designed Not built | C0912 |
| REQ-4303 | Corrections shall be append-only amendments; the original remains for legal retention. | Designed Not built | C0913 |
| REQ-4304 | Breach workflow shall compute regulatory clocks from the active profile and track notifications. | Designed Not built | C0914 |
| REQ-4305 | The system shall maintain records of processing (ROPA) and support DPIA/RIPD artifacts. | Designed Not built | C0915 |
Consent management (6)
Consent capture, scope, revocation, enforcement.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-4401 | Consent shall be captured per purpose, data category, recipient class, duration and revocability, with the rendered text hash signed by the patient or authorized representative. | Designed Not built | C0916 |
| REQ-4402 | Consent shall be enforced at read time by the policy engine using the ledger consent state, with a local cached copy for offline use bounded by staleness limit [Open]. | Designed Not built | C0917 |
| REQ-4403 | Consent shall support minors, guardians, proxies, HCPOA, deceased-patient personal representatives and adolescent confidential-care rules by profile. | Designed Not built | C0918 |
| REQ-4404 | Consent for 42 CFR Part 2 records, psychotherapy notes and reproductive-health-sensitive data shall be separate, purpose-specific and revocable. | Designed Not built | C0919 |
| REQ-4405 | The system shall provide a consent dashboard showing active consents, recipients, last access and revocation. | Designed Not built | C0920 |
| REQ-4406 | The LatAm strict tier shall use granular, specific, revocable consent per purpose and shall not rely on bundled consent. | Designed Not built | C0921 |
Audit (7)
Audit trail, batching and anchoring.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-4501 | Every access, change, print, export, consent, authentication, admin, alert and break-glass event shall generate an audit record with actor, role, terminal, purpose, patient pseudonym, object type, action, outcome, time and correlation id. | Pilot Partly built | C0901 |
| REQ-4502 | Audit records shall be hash-chained per node, batched into Merkle trees and the batch root anchored to the ledger at an interval [Open]. | Designed Not built | C0902 |
| REQ-4503 | Audit storage shall be append-only with WORM tier and no update or delete interface for any role. | Pilot Partly built | C0903 |
| REQ-4504 | Audit shall provide a patient-facing accounting-of-disclosures and access-history view without exposing workforce personal data beyond profile rules. | Pilot Partly built | C0904 |
| REQ-4505 | Audit analytics shall detect snooping (VIP, coworker, neighbor, family), volume anomalies, off-hours access and repeated denials, producing review items with SLA. | Designed Not built | C0905 |
| REQ-4506 | Audit retention shall meet the longest applicable profile requirement; HIPAA documentation retention is 6 years [verify scope]. | Designed Not built | C0906 |
| REQ-4507 | Auditors shall have read-only access by scoped, time-boxed role and their queries shall be audited. | Pilot Partly built | C0907 |
Key management (6)
Hierarchy, HSM, rotation, ceremonies.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-4601 | Keys shall follow the hierarchy Root -> Master KEK -> Sphere KEK -> Compartment KEK -> DEK with envelope encryption. | Designed Not built | C0895 |
| REQ-4602 | Root and master keys shall be in an HSM or equivalent secure element; large tier requires FIPS 140-validated HSM [verify level]; small tier may use a TPM-sealed or smartcard-based custody. | Designed Not built | C0896 |
| REQ-4603 | Key ceremonies shall be scripted, witnessed, logged, with split custody (Shamir) and documented recovery. | Designed Not built | C0897 |
| REQ-4604 | Keys shall be rotated on schedule and on compromise; rotation intervals are [Open] with design proposals. | Designed Not built | C0898 |
| REQ-4605 | Password hashing shall use Argon2id with at least 64 MiB memory and t>=3, or an equivalent tuned for the server. | Designed Not built | C0899 |
| REQ-4606 | Cryptographic modules shall support agility, including hybrid X25519+ML-KEM-768 for key establishment; ML-DSA signatures are optional and [Open]. | Designed Not built | C0900 |
Break-glass and emergency access (3)
BG tokens.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-4701 | A break-glass access shall require an attested reason, produce an immediate audit and alert to the privacy officer, grant scope limited to the patient and duration <=4 h, and be reviewed within 24 h (72 h max). | Designed Not built | C0908 |
| REQ-4702 | Break-glass shall not allow bulk export, print of C4, or changes to security settings. | Pilot Partly built | C0909 |
| REQ-4703 | Break-glass shall work offline using locally signed BG tokens later reconciled to the ledger. | Designed Not built | C0910 |
Downtime and business continuity (3)
Safe-mode ladder L0-L5.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-4801 | The system shall provide the safe-mode ladder L0 normal through L5 paper/downtime, with defined entry conditions and UI banners. | Designed Not built | C0974 |
| REQ-4802 | The system shall generate downtime reports (census, MAR, orders, allergies, medications, problem list, code status, contact list) at schedule and on demand, to the directly attached printer. | Designed Not built | C0975 |
| REQ-4803 | The system shall provide back-entry of downtime paper records with reconciliation and audit flag. | Designed Not built | C0976 |
Terminal and tablet user experience (5)
Thin-client UX.
| ID | Requirement | Pilot status | Answer |
|---|---|---|---|
| REQ-4901 | Terminal UI shall be usable with gloves and quick-touch: min 48 px targets, high contrast, large-text mode, and no PHI cached in the browser. | Pilot Partly built | C0874 |
| REQ-4902 | The tablet UI shall provide role-based home, patient list, alert tray, messaging and Memo Desk access with an always-visible alert banner area. | Pilot Partly built | C0875 |
| REQ-4903 | The terminal shall show a live on-screen watermark (user, terminal, time) and lock on idle timers (2, 5, 10 min by area, PROPOSED). | Designed Not built | C0876 |
| REQ-4904 | The terminal UI shall support proximity badge tap-in/out and fast user switching within the session policy. | Designed Not built | C0877 |
| REQ-4905 | The UI shall support Spanish, Portuguese (BR) and English, with locale-specific date/number/units, and shall not machine-translate clinical content silently. | Designed Not built | C0878 |