Requirements explained (from the specification)
Security, privacy and audit requirements
Access control, identity, keys, audit, break-glass, privacy operations and consent requirements.
Security, privacy, consent, audit and access control (9)
See file 05; requirements repeated here as functional IDs.
- Does AuroraMed enforce access as role AND relationship AND purpose AND context AND consent AND risk AND quota for every read, write, print and export? Pilot
- Does AuroraMed support RBAC, ABAC and ReBAC with a central policy decision point and local enforcement points? Pilot
- Does AuroraMed provide break-glass emergency access with reason code, time limit, notifications and mandatory review? Pilot
- Does AuroraMed segment sensitive data into compartments with separate keys and policies (psychotherapy, SUD, HIV/STI, reproductive health, genetic,… Designed
- Does AuroraMed provide HIPAA privacy operations: accounting of disclosures, ROI, amendments, restrictions, breach workflow? Pilot
- Does AuroraMed provide patient-facing access reports and consent directives (opt-in/opt-out for HIE, research)? Designed
All 9 answers in this section →
Identity, authentication and single sign-on (7)
FIDO2, badge, SSO, provisioning.
- Does AuroraMed authenticate workforce with FIDO2 hardware key plus badge (or PIN plus badge) and phishing-resistant flows? Pilot
- Does AuroraMed enforce session binding, idle timeouts, walk-away lock and single concurrent session per identity? Pilot
- Does AuroraMed integrate with directory services via SAML/OIDC/LDAP/SCIM for provisioning where a customer has one? Designed
- Does AuroraMed support badge tap-and-go (NFC/UWB) authentication and CCOW-style context sharing? Designed
- Does AuroraMed verify provider identity (NPI, DEA, licence) at credentialing? Designed
- Does AuroraMed support patient authentication via wallet passkeys and government IdPs? Designed
All 7 answers in this section →
Key management (6)
Hierarchy, HSM, rotation, ceremonies.
- How are encryption keys arranged, from the root key down to the data key? Designed
- Where would root and master keys be kept? Designed
- How would key ceremonies be run and recorded? Designed
- How often would encryption keys be rotated? Designed
- Which password hashing method does the specification call for? Designed
- Is the cryptography designed to be swapped out later, for example for post-quantum methods? Designed
Audit (7)
Audit trail, batching and anchoring.
- Which events does the audit trail record, and what does each entry contain? Pilot
- How would audit records be chained, batched and anchored to the ledger? Designed
- Can anyone edit or delete audit records once written? Pilot
- Could a patient see who has looked at their record? Pilot
- Would the system detect snooping and unusual access patterns? Designed
- How long would audit records be kept? Designed
All 7 answers in this section →
Break-glass and emergency access (3)
BG tokens.
- What has to happen when someone breaks the glass on a chart? Designed
- What can a person not do while in break-glass mode? Pilot
- Does break-glass still work when the network is down? Designed
Privacy operations and patient rights (5)
LGPD/HIPAA/GDPR/Ley 29733 workflows.
- Does AuroraMed provide workflows for access, correction/amendment, deletion/anonymization (crypto-erasure), portability, consent revocation,… Designed
- Does AuroraMed target records-request fulfilment materially faster than the 72-hour norm through the consent flow; legal-review steps are not… Designed
- When a record is corrected, is the original erased? Designed
- Would the system track breach-notification deadlines? Designed
- Does AuroraMed maintain records of processing (ROPA) and support DPIA/RIPD artifacts? Designed
Consent management (6)
Consent capture, scope, revocation, enforcement.
- What does a patient's consent record contain? Designed
- When is consent checked, and what happens offline? Designed
- How does consent work for children, guardians, proxies and representatives? Designed
- Are substance-use, psychotherapy and reproductive-health records handled separately? Designed
- Does AuroraMed provide a consent dashboard showing active consents, recipients, last access and revocation? Designed
- Does the strict Latin America tier bundle consent together? Designed