NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
Cloud telemetry stream exposes PHI to unauthorized reader
PRJ-2026-0042-TV-000131Treatment plannedMedium
- Proposed (passed)
- Confirmed (passed)
- Assessed (passed)
- Treatment planned (current)
- Mitigation pending (pending)
- Verified (pending)
- Closed (pending)
Infusion telemetry (DS-003, PHI-bearing) uploaded to the multi-tenant ingestion service could be read by an over-privileged internal consumer or a mis-scoped tenant token, disclosing patient-associable infusion patterns.
Deterministic ruleConfidence medium
Actor: Over-privileged internal service or attacker with a leaked scoped token; remote.
- Read tokens scoped wider than tenant need.
- Telemetry retained with patient-associable identifiers.
- Obtain a token with fleet-wide read scope.
- Query ingestion topics across tenants or sites.
- Correlate telemetry to patients via timing and location fields.
- Flows
- DF-000081Telemetry upload
- Function
- Telemetry confidentiality (PHI)
Inherent
MediumL3 × I3
Residual
LowL2 × I2
Factors (1 to 5)
Exploitability3
Impact: confidentiality3
Impact: integrity1
Impact: availability1
Impact: authenticity2
Detectability3
| Category | Value | Share |
|---|---|---|
| Exploitability | 3 | 23% |
| Impact: confidentiality | 3 | 23% |
| Impact: integrity | 1 | 8% |
| Impact: availability | 1 | 8% |
| Impact: authenticity | 2 | 15% |
| Detectability | 3 | 23% |
Safety consequence: NoneScope: Shared clinical environmentUncertainty: Medium
- Exploitability
- 3/5
- Requires token leakage or over-scoped internal consumer; both plausible in multi-tenant estate.
- Impact: confidentiality
- 3/5
- Patient-associable infusion patterns disclosed.
- Impact: integrity
- 1/5
- Read-only exposure.
- Impact: availability
- 1/5
- None.
- Impact: authenticity
- 2/5
- Data consumed outside authorized audience.
- Safety consequence
- None
- No therapy effect.
- Affected scope
- Shared clinical environment
- Cross-tenant read reaches multiple sites.
- Detectability
- 3/5
- Access logging exists at the ingestion tier.
- Uncertainty
- Medium
- Cloud IAM review pending; conservative factor values held.
Medium 9 = L3 x I3; privacy-relevant (PHI), treatment adopted (REM-219).
- Responsible implementer
- Owen Blake (Cloud Platform Engineer)
- Accountable manager
- Tomas Novak
- Independent security reviewer
- Priya Raman
- Risk owner
- Marcus Chen
- Target date
- 03 Jul 2026
- Disposition
- Confirmed by Marcus Chen, 15 Apr 2026
- Treatment adopted (passed)
- Implemented (current)
- Evidence accepted (pending)
- Retest passed (pending)
- Closed (pending)
- REM-218Telemetry field-level redaction before uploadRejected
- REM-219Tenant-scoped read tokens and mTLS on telemetry consumersAdopted
- VOB-000219Telemetry consumer scope enforcement testPendingdue 31 Jul 2026
EvidenceNot requestedRetestNot scheduled
- Treatment decidedTomas Novak · REM-218 rejected (breaks fleet analytics contract); REM-219 scoped read tokens + mTLS adopted.
- ConfirmedMarcus Chen
- Proposed by deterministic rule DST-DISC-01 (run TMR-0009)system