Security, privacy and audit requirements
Privacy operations and patient rights
LGPD/HIPAA/GDPR/Ley 29733 workflows.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0911Does AuroraMed provide workflows for access, correction/amendment, deletion/anonymization (crypto-erasure), portability, consent revocation, restriction/objection, information about sharing, and complaints?
The privacy operations and patient rights part of the specification (REQ-4301) says the system must provide workflows for access, correction/amendment, deletion/anonymization (crypto-erasure), portability, consent revocation, restriction/objection, information about sharing, and complaints. No. The specification describes it, but the pilot does not include it. Acceptance check: each workflow has SLA timers from the active profile.
C0912Does AuroraMed target records-request fulfilment materially faster than the 72-hour norm through the consent flow; legal-review steps are not compressed?
How would it be tested? The specification says measured time from verified request to package delivery is reported. That is the check for REQ-4302: the system must target records-request fulfilment materially faster than the 72-hour norm through the consent flow; legal-review steps are not compressed. Not yet. It is designed in the specification and not built in the pilot.
C0913When a record is corrected, is the original erased?
Designed, not built: there is no code for this in the pilot. For reference, REQ-4303 (a top-priority requirement, all three tiers) says corrections must be append-only amendments; the original remains for legal retention. Check: original retrievable by HIM.
C0914Would the system track breach-notification deadlines?
Breach workflow must compute regulatory clocks from the active profile and track notifications. That is REQ-4304, a top-priority requirement for all three tiers. This is on the design side of the line. Nothing in v0.2.0 does it. Test in the specification: clock started on incident declaration.
C0915Does AuroraMed maintain records of processing (ROPA) and support DPIA/RIPD artifacts?
No. The specification describes it, but the pilot does not include it. REQ-4305 says the system must maintain records of processing (ROPA) and support DPIA/RIPD artifacts. Its acceptance check: rOPA generated from registry.