LevelUp.Health.Audit 0.1.0

There is a newer prerelease version of this package available.
See the version list below for details.
dotnet add package LevelUp.Health.Audit --version 0.1.0
                    
NuGet\Install-Package LevelUp.Health.Audit -Version 0.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="LevelUp.Health.Audit" Version="0.1.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="LevelUp.Health.Audit" Version="0.1.0" />
                    
Directory.Packages.props
<PackageReference Include="LevelUp.Health.Audit" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add LevelUp.Health.Audit --version 0.1.0
                    
#r "nuget: LevelUp.Health.Audit, 0.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package LevelUp.Health.Audit@0.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=LevelUp.Health.Audit&version=0.1.0
                    
Install as a Cake Addin
#tool nuget:?package=LevelUp.Health.Audit&version=0.1.0
                    
Install as a Cake Tool

LevelUp.Health.Audit

PHI-access audit skeleton for the LevelUp.Health backend packages (the asclepius P2 plane). Lifted faithfully from ares-elite/aegis-api's Compliance code: the IEndpointFilter that records every PHI touch, the audit event + sink service, the bounded-channel batching flusher and its BackgroundService, the PII-stripped DCR ingestion entry, and the managed-identity Data-Collection-Rule (DCR) ingestion client.

This package is Result-free — it does not depend on LevelUp.Health.Abstractions. It references the ASP.NET shared framework (Microsoft.AspNetCore.App) for IEndpointFilter / HttpContext / BackgroundService and Azure.Identity for the DCR managed-identity bearer token.

What's here

Namespace Types
LevelUp.Health.Audit.Middleware PhiAccessAuditFilter (the IEndpointFilter)
LevelUp.Health.Audit.Contracts IPhiEndpointRegistry, PhiEndpointMapping, IPhiAuditService, IPhiAuditIngestionClient, PhiAuditIngestionEntry
LevelUp.Health.Audit.Models PhiAuditEvent, PhiAuditActions (one generic break-glass constant)
LevelUp.Health.Audit.Services PhiAuditService, PhiAuditIngestionFlusher, PhiAuditIngestionHostedService, DcrPhiAuditIngestionClient, DcrIngestionAuthenticationHandler
LevelUp.Health.Audit.Configuration PhiAuditIngestionSettings, AuditApiKeyOptions
LevelUp.Health.Audit PhiAuditServiceCollectionExtensions (AddPhiAccessAudit, AddPhiAuditDcrIngestion)

Seams (what the consumer fills)

The package ships no routes and no clinical audit verbs — those are Ares domain. Two seams:

  • IPhiEndpointRegistry — the port that maps (routePattern, httpMethod) → PhiEndpointMapping?. Ares' 33 hardcoded /Patient, /api/v1/drill-sessions, /api/v1/evaluations, /api/v1/admin/* routes do not ship. PhiAccessAuditFilter depends only on this port. The consuming app implements it (e.g. a small in-memory table) to declare which of its endpoints touch PHI.
  • Audit action is a string — carried by PhiEndpointMapping.Action and PhiAuditEvent.Action. There is no fixed enum of clinical verbs to fork; any vocabulary works. The only behavioural escalation that keys off an action is emergency break-glass (logged at Critical), keyed off the shared PhiAuditActions.BreakGlassAccess label.

Consuming it

// 1. Register your route→PHI map and the audit pipeline.
builder.Services.AddSingleton<IPhiEndpointRegistry, MyPhiEndpointRegistry>();
builder.Services.AddPhiAccessAudit();

// 2. (Optional) stream a PII-stripped copy to an Azure Monitor DCR custom table.
//    Opt-in: disabled / unconfigured ⇒ the hosted flush service never starts.
builder.Services.AddPhiAuditDcrIngestion(builder.Configuration);

// 3. Attach the filter to the PHI endpoints.
app.MapGet("/Patient/{patientId}", GetPatient)
   .AddEndpointFilter<PhiAccessAuditFilter>();

The filter calls next() first, then records — so the audit event carries the real response status. It never throws into the request path: a missing mapping, a missing sink, or a failed DCR flush all leave the request served (fail-open for the request; logging is the primary record).

Configuration

PhiAuditIngestionSettings (section Monitor) — DceEndpoint, DcrImmutableId, Enabled, plus StreamName (default Custom-PHIAudit_CL) and ApiVersion (default 2023-01-01). Ingestion is opt-in: IsConfigured() must be true (enabled + endpoint + rule id) for the hosted service to run.

AuditApiKeyOptions (section PhiAudit:ApiKey) — HeaderName (default X-API-Key), the header the filter reads for the audited-user fallback when there is no authenticated JWT identity.

HIPAA controls preserved

PhiAuditIngestionEntry intentionally omits IpAddress and UserAgent (HIPAA minimum-necessary); PhiAuditService.ToIngestionEntry strips them before transmission. The DCR client carries no Azure.Monitor.Ingestion dependency — a plain HttpClient + System.Net.Http.Json POST with a https://monitor.azure.com/.default managed-identity bearer token.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.3.0-preview.1 79 8/14/2026
0.2.0-rc.1 2,050 8/20/2026
0.2.0-preview.3 74 8/18/2026
0.2.0-preview.2 82 8/14/2026
0.2.0-preview.1 76 8/14/2026
0.1.0 1,219 7/17/2026
0.1.0-rc.1 153 7/15/2026
0.1.0-preview.2 84 7/10/2026
0.1.0-preview.1 188 6/26/2026