Security, privacy and audit requirements
Security, privacy, consent, audit and access control
See file 05; requirements repeated here as functional IDs.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0879Does AuroraMed enforce access as role AND relationship AND purpose AND context AND consent AND risk AND quota for every read, write, print and export?
The security, privacy, consent, audit and access control part of the specification (REQ-2201) says the system must enforce access as role AND relationship AND purpose AND context AND consent AND risk AND quota for every read, write, print and export. The pilot covers part of this. The rest is designed, not built. Pilot detail: Role (tier) + scope class (panel/unit/dept) + assignment; no purpose/context/consent or central PDP. Acceptance check: denied request leaves audit record with decision trace.
C0880Does AuroraMed support RBAC, ABAC and ReBAC with a central policy decision point and local enforcement points?
How would it be tested? The specification says policy decision under 50 ms p95 (still an open decision). That is the check for REQ-2202: the system must support RBAC, ABAC and ReBAC with a central policy decision point and local enforcement points. The pilot covers part of this. The rest is designed, not built. Where the code stands: Role (tier) + scope class (panel/unit/dept) + assignment; no purpose/context/consent or central PDP. Parts of it are explicitly marked as open in the specification.
C0881Does AuroraMed provide break-glass emergency access with reason code, time limit, notifications and mandatory review?
The pilot covers part of this. The rest is designed, not built. In the pilot: Break-glass with reason, time limit, security alert to privacy officers and mandatory review queue; compartments are flags pending legal review. For reference, REQ-2203 (a top-priority requirement, all three tiers) says the system must provide break-glass emergency access with reason code, time limit, notifications and mandatory review. Check: review queue populated within 1 minute of event.
C0882Does AuroraMed segment sensitive data into compartments with separate keys and policies (psychotherapy, SUD, HIV/STI, reproductive health, genetic, minors, VIP)?
The system must segment sensitive data into compartments with separate keys and policies (psychotherapy, SUD, HIV/STI, reproductive health, genetic, minors, VIP). That is REQ-2204, a top-priority requirement for all three tiers. This is on the design side of the line. Nothing in v0.2.0 does it. Test in the specification: compartment access without purpose refused.
C0883Does AuroraMed provide HIPAA privacy operations: accounting of disclosures, ROI, amendments, restrictions, breach workflow?
The pilot covers part of this. The rest is designed, not built. Pilot detail: Disclosure log + access report only; no ROI/amendments/restrictions/breach workflow. REQ-2205 says the system must provide HIPAA privacy operations: accounting of disclosures, ROI, amendments, restrictions, breach workflow. Its acceptance check: accounting report for a test patient complete.
C0884Does AuroraMed provide patient-facing access reports and consent directives (opt-in/opt-out for HIE, research)?
REQ-2206 is a top-priority requirement for all three tiers: the system must provide patient-facing access reports and consent directives (opt-in/opt-out for HIE, research). Not yet. It is designed in the specification and not built in the pilot. To verify it, the specification says opt-out honored at data release.
C0885Does AuroraMed support data segmentation for privacy (HL7 DS4P labels)?
The security, privacy, consent, audit and access control part of the specification (REQ-2207) says the system must support data segmentation for privacy (HL7 DS4P labels). Designed, not built: there is no code for this in the pilot. Acceptance check: labels attached to outbound documents.
C0886Does AuroraMed provide de-identification, pseudonymization and tokenization services?
How would it be tested? The specification says safe Harbor identifier list removed in test. That is the check for REQ-2208: the system must provide de-identification, pseudonymization and tokenization services. This is on the design side of the line. Nothing in v0.2.0 does it.
C0887Does AuroraMed support LGPD, GDPR, HIPAA and Peru Ley 29733 configurations including subject-rights workflows?
No. The specification describes it, but the pilot does not include it. For reference, REQ-2209 (a top-priority requirement, all three tiers) says the system must support LGPD, GDPR, HIPAA and Peru Ley 29733 configurations including subject-rights workflows. Check: each right has a workflow per file 05.