Security, privacy and audit requirements
Break-glass and emergency access
BG tokens.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0908What has to happen when someone breaks the glass on a chart?
No. The specification describes it, but the pilot does not include it. REQ-4701 says a break-glass access must require an attested reason, produce an immediate audit and alert to the privacy officer, grant scope limited to the patient and duration <=4 h, and be reviewed within 24 h (72 h max). Its acceptance check: timers verified; unreviewed BG escalates.
C0909What can a person not do while in break-glass mode?
REQ-4702 is a top-priority requirement for all three tiers: break-glass must not allow bulk export, print of C4, or changes to security settings. The pilot covers part of this. The rest is designed, not built. Where the code stands: No bulk export or print of C4 exists in the app, so break-glass cannot do it; not tested as a negative control. To verify it, the specification says attempt refused.
C0910Does break-glass still work when the network is down?
The break-glass and emergency access part of the specification (REQ-4703) says break-glass must work offline using locally signed BG tokens later reconciled to the ledger. Designed, not built: there is no code for this in the pilot. Acceptance check: offline BG appears on ledger after reconnect.