Security, privacy and audit requirements
Consent management
Consent capture, scope, revocation, enforcement.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0916What does a patient's consent record contain?
No. The specification describes it, but the pilot does not include it. REQ-4401 says consent must be captured per purpose, data category, recipient class, duration and revocability, with the rendered text hash signed by the patient or authorized representative. Its acceptance check: consent object contains all listed fields; signature verifies.
C0917When is consent checked, and what happens offline?
REQ-4402 is a top-priority requirement for all three tiers: consent must be enforced at read time by the policy engine using the ledger consent state, with a local cached copy for offline use bounded by staleness limit (still an open decision). Not yet. It is designed in the specification and not built in the pilot. To verify it, the specification says offline consent cache older than limit forces conservative deny except emergency. Parts of it are explicitly marked as open in the specification.
C0918How does consent work for children, guardians, proxies and representatives?
The consent management part of the specification (REQ-4403) says consent must support minors, guardians, proxies, HCPOA, deceased-patient personal representatives and adolescent confidential-care rules by profile. Designed, not built: there is no code for this in the pilot. Acceptance check: adolescent confidential encounter hidden from proxy view.
C0919Are substance-use, psychotherapy and reproductive-health records handled separately?
How would it be tested? The specification says part 2 record not disclosed without matching consent; redisclosure notice attached. That is the check for REQ-4404: consent for 42 CFR Part 2 records, psychotherapy notes and reproductive-health-sensitive data must be separate, purpose-specific and revocable. This is on the design side of the line. Nothing in v0.2.0 does it.
C0920Does AuroraMed provide a consent dashboard showing active consents, recipients, last access and revocation?
No. The specification describes it, but the pilot does not include it. For reference, REQ-4405 (a high-priority requirement, all three tiers) says the system must provide a consent dashboard showing active consents, recipients, last access and revocation. Check: patient revokes and sees effect.
C0921Does the strict Latin America tier bundle consent together?
The LatAm strict tier must use granular, specific, revocable consent per purpose and must not rely on bundled consent. That is REQ-4406, a top-priority requirement for all three tiers. Not yet. It is designed in the specification and not built in the pilot. Test in the specification: bundled consent option absent in strict tier.