Skip to content
 
 

Latest commit

 

History

13,595 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

πŸ”’ This build is minidauth'd

OpenEMR, with a key nobody holds. A patient's name, Social Security number, address, phone and email are sealed before they ever reach the database, encrypted with a key that is never assembled anywhere, not even to decrypt. The key lives as threshold shares across the Tide network, so the classic breach, someone walking off with your medical database or a backup, turns up nothing readable.

  • Your database holds only ciphertext. A stolen medical database or a leaked backup reveals no names, SSNs or contact details, and you cannot even search for an SSN.
  • There is no standing key to steal. The key is never whole, not in this app and not on any single server.
  • Reads are governed, not assumed. A quorum grants the reading role. Revoke it and reads stop everywhere, at once, even for an administrator.
  • Clinical workflow still works. Dates and coded fields stay in the clear, so scheduling and reports are unaffected.
  • Nothing else changes. OpenEMR works exactly as it does upstream, and sealing stays off until you turn it on.

See how it works β†’ minidauth Β· dauth.me

minidauth'd

Running it with minidauth

Sealing is off until you point OpenEMR at a minidauth sidecar; unconfigured, it behaves exactly like upstream.

  1. Bring up the backend. In a checkout of minidauth:

    cp operators.example.json operators.json
    docker compose -f docker-compose.yml -f docker-compose.seal.yml up -d
    # create a vendor key once (a licensed step; see that repo's docs/running.md)
    ./bootstrap.sh

    This runs the sealing sidecar on http://localhost:3021 and writes a signing key to ./keys/usertoken.key. Full detail: minidauth's docs/sealing.md.

  2. Widen the sealed columns. minidauth stores ciphertext in place, which is longer than the upstream varchar(255), so the sealed demographics columns move to text. Once, against your database:

    ALTER TABLE patient_data DROP INDEX idx_patient_name;
    ALTER TABLE patient_data
      MODIFY fname text, MODIFY lname text, MODIFY mname text, MODIFY ss text,
      MODIFY street text, MODIFY city text, MODIFY postal_code text,
      MODIFY phone_home text, MODIFY phone_cell text, MODIFY email text;
  3. Point OpenEMR at it. Set these in its environment, then start OpenEMR as usual:

    MINIDAUTH_SEAL_URL=http://localhost:3021
    MINIDAUTH_SEAL_SIGNING_KEY_FILE=/absolute/path/to/minidauth/keys/usertoken.key

    Now patient names, SSNs, addresses, phones and emails are sealed before they reach the database.

  4. Grant a reader. Sealed fields open only for a user the quorum granted the crm-reader role. Grant it to an OpenEMR user by their id (users.id), from the minidauth checkout:

    DEMO_UID=<openemr user id> ./bootstrap.sh

    Revoke it in minidauth and their reads go dark, even for an administrator, with no change to OpenEMR.

Syntax Status Styling Status Testing Status JS Unit Testing Status PHPStan Rector ShellCheck Docker Compose Linting Dockerfile Linting Isolated Tests Inferno Certification Test Composer Checks Composer Require Checker API Docs Freshness Checks codecov

Backers on Open Collective Sponsors on Open Collective

OpenEMR

OpenEMR is a Free and Open Source electronic health records and medical practice management application. It features fully integrated electronic health records, practice management, scheduling, electronic billing, internationalization, free support, a vibrant community, and a whole lot more. It runs on Windows, Linux, Mac OS X, and many other platforms.

Contributing

OpenEMR is a leader in healthcare open source software and comprises a large and diverse community of software developers, medical providers and educators with a very healthy mix of both volunteers and professionals. Join us and learn how to start contributing today!

Already comfortable with git? Check out CONTRIBUTING.md for quick setup instructions and requirements for contributing to OpenEMR by resolving a bug or adding an awesome feature 😊.

Support

Community and Professional support can be found here.

Extensive documentation and forums can be found on the OpenEMR website that can help you to become more familiar about the project πŸ“–.

Reporting Issues and Bugs

Report these on the Issue Tracker. If you are unsure if it is an issue/bug, then always feel free to use the Forum and Chat to discuss about the issue πŸͺ².

Reporting Security Vulnerabilities

Check out SECURITY.md

API

Check out API_README.md

Docker

Check out DOCKER_README.md

FHIR

Check out FHIR_README.md

For Developers

If using OpenEMR directly from the code repository, then the following commands will build OpenEMR (Node.js version 24.* is required) :

composer install --no-dev
npm install
npm run build
composer dump-autoload -o

Contributors

This project exists thanks to all the people who have contributed. [Contribute].

Sponsors

Thanks to our ONC Certification Major Sponsors!

License

GNU GPL

About

The most popular open source electronic health records and medical practice management solution.

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages