Security, privacy and audit requirements
Identity, authentication and single sign-on
FIDO2, badge, SSO, provisioning.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0888Does AuroraMed authenticate workforce with FIDO2 hardware key plus badge (or PIN plus badge) and phishing-resistant flows?
The pilot covers part of this. The rest is designed, not built. In the pilot: TOTP MFA (RFC 6238) with recovery codes for T7+ roles; no FIDO2/badge. For reference, REQ-2251 (a top-priority requirement, all three tiers) says the system must authenticate workforce with FIDO2 hardware key plus badge (or PIN plus badge) and phishing-resistant flows. Check: sMS OTP is not offered.
C0889Does AuroraMed enforce session binding, idle timeouts, walk-away lock and single concurrent session per identity?
The system must enforce session binding, idle timeouts, walk-away lock and single concurrent session per identity. That is REQ-2252, a top-priority requirement for all three tiers. The pilot covers part of this. The rest is designed, not built. What v0.2.0 does today: Idle lock screen, session list/revoke, partial-session gating; no device binding and no single-session rule. Test in the specification: second concurrent session is denied.
C0890Does AuroraMed integrate with directory services via SAML/OIDC/LDAP/SCIM for provisioning where a customer has one?
No. The specification describes it, but the pilot does not include it. REQ-2253 says the system must integrate with directory services via SAML/OIDC/LDAP/SCIM for provisioning where a customer has one. Its acceptance check: deprovisioning removes access within a minute.
C0891Does AuroraMed support badge tap-and-go (NFC/UWB) authentication and CCOW-style context sharing?
REQ-2254 is a high-priority requirement for the medium and large tiers: the system must support badge tap-and-go (NFC/UWB) authentication and CCOW-style context sharing. Not yet. It is designed in the specification and not built in the pilot. To verify it, the specification says badge tap authenticates within budget.
C0892Does AuroraMed verify provider identity (NPI, DEA, licence) at credentialing?
The identity, authentication and single sign-on part of the specification (REQ-2255) says the system must verify provider identity (NPI, DEA, licence) at credentialing. Designed, not built: there is no code for this in the pilot. Acceptance check: licence lookup result stored.
C0893Does AuroraMed support patient authentication via wallet passkeys and government IdPs?
How would it be tested? The specification says passkey sign-in. That is the check for REQ-2256: the system must support patient authentication via wallet passkeys and government IdPs. This is on the design side of the line. Nothing in v0.2.0 does it.
C0894Does AuroraMed support service account authorization with mTLS SVIDs?
No. The specification describes it, but the pilot does not include it. For reference, REQ-2257 (a top-priority requirement, all three tiers) says the system must support service account authorization with mTLS SVIDs. Check: certificates expire within one hour.