LevelUp.Health.Audit
0.1.0
See the version list below for details.
dotnet add package LevelUp.Health.Audit --version 0.1.0
NuGet\Install-Package LevelUp.Health.Audit -Version 0.1.0
<PackageReference Include="LevelUp.Health.Audit" Version="0.1.0" />
<PackageVersion Include="LevelUp.Health.Audit" Version="0.1.0" />
<PackageReference Include="LevelUp.Health.Audit" />
paket add LevelUp.Health.Audit --version 0.1.0
#r "nuget: LevelUp.Health.Audit, 0.1.0"
#:package LevelUp.Health.Audit@0.1.0
#addin nuget:?package=LevelUp.Health.Audit&version=0.1.0
#tool nuget:?package=LevelUp.Health.Audit&version=0.1.0
LevelUp.Health.Audit
PHI-access audit skeleton for the LevelUp.Health backend packages (the asclepius P2 plane).
Lifted faithfully from ares-elite/aegis-api's Compliance code: the IEndpointFilter that records
every PHI touch, the audit event + sink service, the bounded-channel batching flusher and its
BackgroundService, the PII-stripped DCR ingestion entry, and the managed-identity
Data-Collection-Rule (DCR) ingestion client.
This package is Result-free — it does not depend on LevelUp.Health.Abstractions. It
references the ASP.NET shared framework (Microsoft.AspNetCore.App) for IEndpointFilter /
HttpContext / BackgroundService and Azure.Identity for the DCR managed-identity bearer token.
What's here
| Namespace | Types |
|---|---|
LevelUp.Health.Audit.Middleware |
PhiAccessAuditFilter (the IEndpointFilter) |
LevelUp.Health.Audit.Contracts |
IPhiEndpointRegistry, PhiEndpointMapping, IPhiAuditService, IPhiAuditIngestionClient, PhiAuditIngestionEntry |
LevelUp.Health.Audit.Models |
PhiAuditEvent, PhiAuditActions (one generic break-glass constant) |
LevelUp.Health.Audit.Services |
PhiAuditService, PhiAuditIngestionFlusher, PhiAuditIngestionHostedService, DcrPhiAuditIngestionClient, DcrIngestionAuthenticationHandler |
LevelUp.Health.Audit.Configuration |
PhiAuditIngestionSettings, AuditApiKeyOptions |
LevelUp.Health.Audit |
PhiAuditServiceCollectionExtensions (AddPhiAccessAudit, AddPhiAuditDcrIngestion) |
Seams (what the consumer fills)
The package ships no routes and no clinical audit verbs — those are Ares domain. Two seams:
IPhiEndpointRegistry— the port that maps(routePattern, httpMethod) → PhiEndpointMapping?. Ares' 33 hardcoded/Patient,/api/v1/drill-sessions,/api/v1/evaluations,/api/v1/admin/*routes do not ship.PhiAccessAuditFilterdepends only on this port. The consuming app implements it (e.g. a small in-memory table) to declare which of its endpoints touch PHI.- Audit action is a
string— carried byPhiEndpointMapping.ActionandPhiAuditEvent.Action. There is no fixed enum of clinical verbs to fork; any vocabulary works. The only behavioural escalation that keys off an action is emergency break-glass (logged atCritical), keyed off the sharedPhiAuditActions.BreakGlassAccesslabel.
Consuming it
// 1. Register your route→PHI map and the audit pipeline.
builder.Services.AddSingleton<IPhiEndpointRegistry, MyPhiEndpointRegistry>();
builder.Services.AddPhiAccessAudit();
// 2. (Optional) stream a PII-stripped copy to an Azure Monitor DCR custom table.
// Opt-in: disabled / unconfigured ⇒ the hosted flush service never starts.
builder.Services.AddPhiAuditDcrIngestion(builder.Configuration);
// 3. Attach the filter to the PHI endpoints.
app.MapGet("/Patient/{patientId}", GetPatient)
.AddEndpointFilter<PhiAccessAuditFilter>();
The filter calls next() first, then records — so the audit event carries the real response
status. It never throws into the request path: a missing mapping, a missing sink, or a failed DCR
flush all leave the request served (fail-open for the request; logging is the primary record).
Configuration
PhiAuditIngestionSettings (section Monitor) — DceEndpoint, DcrImmutableId, Enabled, plus
StreamName (default Custom-PHIAudit_CL) and ApiVersion (default 2023-01-01). Ingestion is
opt-in: IsConfigured() must be true (enabled + endpoint + rule id) for the hosted service to run.
AuditApiKeyOptions (section PhiAudit:ApiKey) — HeaderName (default X-API-Key), the header
the filter reads for the audited-user fallback when there is no authenticated JWT identity.
HIPAA controls preserved
PhiAuditIngestionEntry intentionally omits IpAddress and UserAgent (HIPAA minimum-necessary);
PhiAuditService.ToIngestionEntry strips them before transmission. The DCR client carries no
Azure.Monitor.Ingestion dependency — a plain HttpClient + System.Net.Http.Json POST with a
https://monitor.azure.com/.default managed-identity bearer token.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Azure.Identity (>= 1.21.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.3.0-preview.1 | 79 | 8/14/2026 |
| 0.2.0-rc.1 | 2,050 | 8/20/2026 |
| 0.2.0-preview.3 | 74 | 8/18/2026 |
| 0.2.0-preview.2 | 82 | 8/14/2026 |
| 0.2.0-preview.1 | 76 | 8/14/2026 |
| 0.1.0 | 1,219 | 7/17/2026 |
| 0.1.0-rc.1 | 153 | 7/15/2026 |
| 0.1.0-preview.2 | 84 | 7/10/2026 |
| 0.1.0-preview.1 | 188 | 6/26/2026 |