Ravi Patel, Customer Admin

NP-200 system security design review

NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007

PRJ-2026-0042-DRV-0001Threat review
Threat workbench

Cloud telemetry stream exposes PHI to unauthorized reader

PRJ-2026-0042-TV-000131Treatment plannedMedium

  1. Proposed (passed)
  2. Confirmed (passed)
  3. Assessed (passed)
  4. Treatment planned (current)
  5. Mitigation pending (pending)
  6. Verified (pending)
  7. Closed (pending)

Infusion telemetry (DS-003, PHI-bearing) uploaded to the multi-tenant ingestion service could be read by an over-privileged internal consumer or a mis-scoped tenant token, disclosing patient-associable infusion patterns.

Deterministic ruleConfidence medium

Actor: Over-privileged internal service or attacker with a leaked scoped token; remote.

Elements
AE-000061Cloud telemetry ingestion serviceAE-000051NimbusLink Gateway edge service
Flows
DF-000081Telemetry upload
Sources
SRC-0001VSDX page 5 connector 12SRC-0004drawio edge gw-edge->cloud-ingest
Function
Telemetry confidentiality (PHI)