Ravi Patel, Customer Admin

NP-200 system security design review

NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007

PRJ-2026-0042-DRV-0001Threat review
Threat workbench

EHR adapter verbose errors leak integration credentials

PRJ-2026-0042-TV-000140Dismissed

  1. Proposed (passed)
  2. Dismissed (blocked)

Proposed: verbose fault responses from the EHR integration adapter might echo connection strings or tokens to gateway logs.

Enrichment proposalConfidence low

Actor: Log reader on gateway host.

Elements
AE-000053Hospital EHR integration adapterAE-000051NimbusLink Gateway edge service
Flows
DF-000083EHR order context
Sources
SRC-0002OpenAPI responses/5xx (adapter contract reference)
Function
Integration credential confidentiality