OpenEMR, with a key nobody holds. A patient's name, Social Security number, address, phone and email are sealed before they ever reach the database, encrypted with a key that is never assembled anywhere, not even to decrypt. The key lives as threshold shares across the Tide network, so the classic breach, someone walking off with your medical database or a backup, turns up nothing readable.
- Your database holds only ciphertext. A stolen medical database or a leaked backup reveals no names, SSNs or contact details, and you cannot even search for an SSN.
- There is no standing key to steal. The key is never whole, not in this app and not on any single server.
- Reads are governed, not assumed. A quorum grants the reading role. Revoke it and reads stop everywhere, at once, even for an administrator.
- Clinical workflow still works. Dates and coded fields stay in the clear, so scheduling and reports are unaffected.
- Nothing else changes. OpenEMR works exactly as it does upstream, and sealing stays off until you turn it on.
Sealing is off until you point OpenEMR at a minidauth sidecar; unconfigured, it behaves exactly like upstream.
-
Bring up the backend. In a checkout of minidauth:
cp operators.example.json operators.json docker compose -f docker-compose.yml -f docker-compose.seal.yml up -d # create a vendor key once (a licensed step; see that repo's docs/running.md) ./bootstrap.shThis runs the sealing sidecar on
http://localhost:3021and writes a signing key to./keys/usertoken.key. Full detail: minidauth's docs/sealing.md. -
Widen the sealed columns. minidauth stores ciphertext in place, which is longer than the upstream
varchar(255), so the sealed demographics columns move totext. Once, against your database:ALTER TABLE patient_data DROP INDEX idx_patient_name; ALTER TABLE patient_data MODIFY fname text, MODIFY lname text, MODIFY mname text, MODIFY ss text, MODIFY street text, MODIFY city text, MODIFY postal_code text, MODIFY phone_home text, MODIFY phone_cell text, MODIFY email text;
-
Point OpenEMR at it. Set these in its environment, then start OpenEMR as usual:
MINIDAUTH_SEAL_URL=http://localhost:3021 MINIDAUTH_SEAL_SIGNING_KEY_FILE=/absolute/path/to/minidauth/keys/usertoken.key
Now patient names, SSNs, addresses, phones and emails are sealed before they reach the database.
-
Grant a reader. Sealed fields open only for a user the quorum granted the
crm-readerrole. Grant it to an OpenEMR user by their id (users.id), from the minidauth checkout:DEMO_UID=<openemr user id> ./bootstrap.sh
Revoke it in minidauth and their reads go dark, even for an administrator, with no change to OpenEMR.
OpenEMR is a Free and Open Source electronic health records and medical practice management application. It features fully integrated electronic health records, practice management, scheduling, electronic billing, internationalization, free support, a vibrant community, and a whole lot more. It runs on Windows, Linux, Mac OS X, and many other platforms.
OpenEMR is a leader in healthcare open source software and comprises a large and diverse community of software developers, medical providers and educators with a very healthy mix of both volunteers and professionals. Join us and learn how to start contributing today!
Already comfortable with git? Check out CONTRIBUTING.md for quick setup instructions and requirements for contributing to OpenEMR by resolving a bug or adding an awesome feature π.
Community and Professional support can be found here.
Extensive documentation and forums can be found on the OpenEMR website that can help you to become more familiar about the project π.
Report these on the Issue Tracker. If you are unsure if it is an issue/bug, then always feel free to use the Forum and Chat to discuss about the issue πͺ².
Check out SECURITY.md
Check out API_README.md
Check out DOCKER_README.md
Check out FHIR_README.md
If using OpenEMR directly from the code repository, then the following commands will build OpenEMR (Node.js version 24.* is required) :
composer install --no-dev
npm install
npm run build
composer dump-autoload -oThis project exists thanks to all the people who have contributed. [Contribute].
Thanks to our ONC Certification Major Sponsors!