Lifecycle, program, automation, documentation, and governance surfaces.
Orthopaedic lifecycle operations
Close the operational loop around implanted hardware without inventing a clinical decision.
A staff-first exception and automation layer for lifecycle evidence, documentation, access, coordination, and governance. Existing product routes remain intact; this manifest only composes them.
- Composition
- Manifest, not UI fork
- Review model
- Automatic preparation · one final human review
- Modules
- 6 bounded contracts
Shared architecture
One shell around independent engines
Capability composition
Module ledger
Role-aware presentation
Same engine state, different decisions
Exceptions, cited evidence, planning readiness, and the final clinical boundary.
Workflow metrics are not imaging interpretations or treatment recommendations.Bounded preparation completes before a final human decision surface.
The manifest exposes no clinical write capability.
Connection truth
Code, connection, and authorization are separate states
This ledger covers the public repository only. Implemented means a tested local code path—not a sandbox result, customer connection, clinical validation, or production authorization.
AccessGUDID device identity lookup
A patient-free, credential-free, read-only AccessGUDID lookup is implemented; registry identity does not prove patient use.
- Standard
- NLM AccessGUDID Device Lookup API
- Version
- API v3
- Current runtime
- Public read-only
- Direction
- Read
A public registry match can enrich device identity; it cannot establish that the device was implanted in a patient or support a clinical decision.
- Conservative device-identifier normalization
- Bounded same-origin proxy with one credential-free upstream GET
- Exact returned-identifier verification
- Timeout, redirect, content-type, and byte limits
- mapping and conformance
- positive control canary
- monitoring and rollback
Administrative reminder calendar
A calendar adapter boundary is documented; no customer calendar is connected and no reminder is created.
- Standard
- Customer-approved calendar API
- Version
- Customer-specific
- Current runtime
- Not connected
- Direction
- Write
No calendar transport, customer identity mapping, reminder creation, patient contact, or appointment booking is implemented.
- Human-reviewed reminder intent contract
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- privacy security approval
- clinical operational approval
- monitoring and rollback
Claim status exchange
A claim-status adapter boundary is documented; no payer or clearinghouse status exchange is implemented.
- Standard
- X12 276/277 or approved clearinghouse API
- Version
- Customer-licensed implementation guide
- Current runtime
- Not connected
- Direction
- Request / response
No clearinghouse or payer endpoint is connected; synthetic status labels are not payer responses.
- Claim-status handoff contract
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- data completeness study
- privacy security approval
- clinical operational approval
- monitoring and rollback
Coder-approved claim handoff
A claim-handoff boundary is documented; Synorthopic performs zero claim or clearinghouse submissions.
- Standard
- X12 837 or customer billing-system contract
- Version
- Customer-licensed implementation guide
- Current runtime
- Not connected
- Direction
- Write
No claim creation, charge posting, clearinghouse submission, correction, or account adjustment is implemented.
- Evidence-ID-only coding handoff
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- privacy security approval
- clinical operational approval
- monitoring and rollback
Customer implant catalog
A fingerprinted patient-free catalog contract is implemented; no customer catalog is loaded or verified in this release.
- Standard
- Synorthopic customer catalog artifact
- Version
- v1
- Current runtime
- Local exchange only
- Direction
- Local exchange
The public release includes only a fictional example; no customer catalog is loaded or approved.
- Strict catalog schema validation
- Exact identifier matching
- Artifact fingerprint inspection
- No patient data in catalog records
- customer registration
- mapping and conformance
- positive control canary
- privacy security approval
- clinical operational approval
- monitoring and rollback
DICOMweb planning handoff
A DICOMweb planning-handoff boundary is documented; no PACS or planning system is connected.
- Standard
- DICOM PS3.18 DICOMweb
- Version
- Customer conformance statement required
- Current runtime
- Not connected
- Direction
- Request / response
No PACS connection, image retrieval, image interpretation, implant sizing, trajectory, approach, or surgical plan is implemented.
- Planning-source manifest contract
- Surgeon question contract
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- data completeness study
- privacy security approval
- clinical operational approval
- monitoring and rollback
Customer EHR chart navigation
A customer-private chart-navigation broker is implemented; no customer chart link is configured or live-verified.
- Standard
- Customer-approved chart-link broker
- Version
- Customer-specific
- Current runtime
- Not connected
- Direction
- Read
The broker contract is implemented, but no customer chart-link configuration or live navigation has been verified.
- Encrypted patient anchor at rest
- Human POST redirect
- Navigation audit event
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- data completeness study
- privacy security approval
- clinical operational approval
- monitoring and rollback
Enterprise document repository
An enterprise-document adapter boundary is documented; no customer repository is connected.
- Standard
- Customer-approved document repository API
- Version
- Customer-specific
- Current runtime
- Not connected
- Direction
- Request / response
No SharePoint, Box, Drive, or other enterprise document tenant is connected.
- Document reference and attachment-manifest contracts
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- privacy security approval
- clinical operational approval
- monitoring and rollback
External immutable audit destination
An external audit-sink contract and patient-free probe are implemented; no customer sink is configured or verified.
- Standard
- Customer-controlled append-only audit sink
- Version
- v1 contract
- Current runtime
- Not connected
- Direction
- Write
The sink and probe interfaces are implemented, but no external destination, schedule, monitoring, or independent archive is loaded.
- Patient-free destination probe
- Monotonic export sequence
- HMAC cursor integrity
- Retry-safe export contract
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- privacy security approval
- clinical operational approval
- monitoring and rollback
Human-approved FHIR administrative Task
A human-gated FHIR Task write contract is implemented and synthetic-tested; external EHR writes are disabled.
- Standard
- HL7 FHIR R4 Task customer profile
- Version
- FHIR 4.0.1; customer profile required
- Current runtime
- Synthetic only
- Direction
- Write
The write path is exercised only with synthetic transports; public and read-only deployments enable no EHR writes.
- Human approval capability gate
- Conditional create and idempotency
- Read-after-write verification
- Aggregate receipt only
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- privacy security approval
- clinical operational approval
- monitoring and rollback
FHIR Bulk Data cohort discovery
A resumable FHIR Bulk Data client is implemented and synthetic-tested; no customer export is connected or verified.
- Standard
- HL7 FHIR Bulk Data Access
- Version
- STU 2.0.0 / FHIR R4
- Current runtime
- Synthetic only
- Direction
- Read
Only synthetic Group and NDJSON transports are verified; no customer Bulk Data endpoint or cohort has been used.
- Group export discovery
- Manifest allowlisting and HMAC binding
- Bounded NDJSON processing
- Encrypted resumable checkpoints
- Pause on patient-read failure
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- data completeness study
- privacy security approval
- clinical operational approval
- monitoring and rollback
HL7 event ingestion
An allowlisted HL7 event consumer is implemented for synthetic traffic; no hospital feed is connected or verified.
- Standard
- Customer-profiled HL7 v2 event feed
- Version
- Customer-specific
- Current runtime
- Synthetic only
- Direction
- Read
The hosted route accepts only explicitly attested synthetic traffic; no hospital HL7 feed or production interface is connected.
- Signed webhook validation
- Tenant partitioning
- Replay and duplicate suppression
- Encrypted synthetic payload handling
- Dead-letter and retry contracts
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- data completeness study
- privacy security approval
- clinical operational approval
- monitoring and rollback
Synorthopic human coding review handoff
A de-identified evidence-linked coding handoff is implemented; a qualified human selects every final code.
- Standard
- Synorthopic evidence-ID-only coding handoff
- Version
- orthoscrub.synoptic-coding-handoff.v1
- Current runtime
- Local exchange only
- Direction
- Local exchange
The handoff is a local de-identified artifact; no coding system, EHR charge router, or billing system is connected.
- Evidence-ID-only serialization
- Documentation-gap separation
- Human final-code authority
- No licensed descriptors
- customer registration
- mapping and conformance
- positive control canary
- privacy security approval
- clinical operational approval
- licensed content authorization
- monitoring and rollback
Eligibility and benefits exchange
An eligibility adapter boundary is documented; no clearinghouse or payer eligibility connection is implemented.
- Standard
- X12 270/271 or approved eligibility API
- Version
- Customer-licensed implementation guide
- Current runtime
- Not connected
- Direction
- Request / response
No eligibility request is transmitted and no displayed synthetic benefit state is a coverage verification or guarantee.
- Eligibility request and response domain contract
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- data completeness study
- privacy security approval
- clinical operational approval
- monitoring and rollback
Prior-authorization evidence exchange
Prior-authorization packet preparation is local; no payer transport, policy service, submission, or response integration is implemented.
- Standard
- Da Vinci CRD/DTR/PAS/CDex or X12 278
- Version
- PAS 2.2.1; customer-profiled companion guides
- Current runtime
- Not connected
- Direction
- Request / response
Local packet preparation does not implement payer policy retrieval, attestation, submission, response, or medical-necessity determination.
- Criterion-by-criterion evidence matrix
- Documentation-gap detection
- Attachment manifest
- Human submission gate
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- privacy security approval
- clinical operational approval
- monitoring and rollback
SMART Backend Services read
A least-privilege SMART Backend Services client is implemented and synthetic-tested; no customer connection is registered or verified.
- Standard
- SMART Backend Services + FHIR R4
- Version
- SMART App Launch 2.2.0
- Current runtime
- Synthetic only
- Direction
- Read
Only asymmetric synthetic transports are verified; no customer client registration, signing key, cohort, or live read exists.
- Private-key JWT assertion
- RS384 and ES384 signing profiles
- Exact scope allowlist
- Short-lived token validation
- Bounded patient and cohort reads
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- data completeness study
- privacy security approval
- clinical operational approval
- monitoring and rollback
SMART interactive chart-context read
A read-only SMART chart-context flow is implemented and synthetic-tested; no customer EHR is registered, connected, or verified.
- Standard
- SMART App Launch + FHIR R4
- Version
- SMART App Launch 2.2.0
- Current runtime
- Synthetic only
- Direction
- Read
The authorization and read path is synthetic-tested; no customer app registration, credentials, chart launch, or live FHIR read exists.
- Authorization Code with PKCE S256
- State, issuer, redirect, and replay checks
- Read-only scope enforcement
- Bounded token and FHIR response handling
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- data completeness study
- privacy security approval
- clinical operational approval
- monitoring and rollback
Private SpineCPT candidate handoff
A patient-free private SpineCPT handoff contract is implemented; the licensed engine is not bundled, connected, or publicly verified.
- Standard
- Synorthopic SpineCPT private-provider contract
- Version
- lookup request/response v1
- Current runtime
- Local exchange only
- Direction
- Local exchange
No SpineCPT source, license key, terminology library, live service, or proprietary descriptor is present in this repository.
- Patient-free request schema
- Request-bound response validation
- Candidate and file-size limits
- Licensed-content rejection
- Human final-code authority
- customer registration
- mapping and conformance
- positive control canary
- privacy security approval
- clinical operational approval
- licensed content authorization
- monitoring and rollback
Workforce review notifications
A workforce-notification boundary is documented; no customer channel is connected and no message is sent.
- Standard
- Customer-approved messaging or email API
- Version
- Customer-specific
- Current runtime
- Not connected
- Direction
- Write
No Teams, Slack, email, SMS, voice, or other notification channel is connected; no patient outreach is permitted.
- Human-reviewed notification intent contract
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- privacy security approval
- clinical operational approval
- monitoring and rollback
Customer workforce OIDC
A tenant-bound workforce OIDC and server-side session contract is implemented; no customer identity provider is connected or live-verified.
- Standard
- OpenID Connect Core 1.0 + Authorization Code with PKCE
- Version
- OIDC Core 1.0
- Current runtime
- Not connected
- Direction
- Request / response
The OIDC and session contracts are implemented, but no customer identity provider, client registration, login, or session lifecycle is mounted or verified.
- Authorization Code and PKCE S256
- Issuer, audience, nonce, state, and browser binding
- Encrypted one-time login transaction
- Server-side idle and absolute session expiry
- Actor revocation
- customer registration
- customer endpoint configuration
- least privilege authorization
- mapping and conformance
- positive control canary
- privacy security approval
- clinical operational approval
- monitoring and rollback
Automation truth
Models, deterministic checks, and action authority are separate states
This ledger records the public repository release. Implemented means tested code exists; it does not mean a model is enabled, customer data is allowed, performance is validated, or the software may act externally.
Customer review routing policy
A deterministic review-routing policy is implemented and locally tested; it does not make or record a clinical or administrative disposition.
- Contract
- orthoscrub.customer-review-agent-plan.v1
- Engine
- Repository deterministic code
- Identifier
- customer-review-agent
- Current runtime
- Local deterministic
- Release decision
- local deterministic only
- Test dataset
- customer-review-agent-synthetic-fixtures.v1
An authorized human reviewer makes and records the final disposition outside this policy.
Inspect controls and operating envelope
- Exact contract and enum validation
- Fixed route selection
- Public registry facts remain untrusted
- Source conflict
- Evidence gap
- Unsupported identity state
- Recording a disposition
- Closing a chart
- Writing to an EHR
- Promoting public data into chart truth
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Use the existing human review queue without the generated route.
GuidedLoop source-field proposal model
An archived, de-identified proposal boundary is implemented; public model invocation is disabled and no proposal becomes a trusted field automatically.
- Contract
- guidedloop.source-compiler.v1
- Engine
- OpenAI API boundary
- Identifier
- gpt-5.6-luna deployment default
- Current runtime
- Research archive
- Release decision
- research archive only
- Test dataset
- guidedloop-deidentified-synthetic-fixtures.v2
A human explicitly accepts each verified field before record creation.
Inspect controls and operating envelope
- Direct-identifier rejection before invocation
- API key plus explicit de-identified processing gate required
- Shared client bounds configuration, request and response bytes, redirects, content type, timeout, and failures
- Tool-free structured output
- Shared source-level instruction quarantine before candidate acceptance
- Exact quote and substring verification after response
- Direct identifier detected
- Unsupported field
- Missing exact quote
- Calculating dates not stated in source
- Clinical inference
- External tools or actions
- Processing directly identified text
- Subgroups: not established
- Overrides: local test only
- Incidents: not established
- Rollback: Use the deterministic offline parser or manual GuidedLoop entry.
GuidedLoop exact-quote verifier
A deterministic exact-quote verifier is implemented for the archived GuidedLoop workflow; it does not establish clinical truth.
- Contract
- guidedloop.source-compiler.v1
- Engine
- Repository deterministic code
- Identifier
- guided-loop-extraction-verifier
- Current runtime
- Research archive
- Release decision
- research archive only
- Test dataset
- guidedloop-deidentified-synthetic-fixtures.v1
A human accepts a verified candidate before it becomes a lifecycle field.
Inspect controls and operating envelope
- Allowed field
- Verbatim quote
- Value substring
- Explicit date format
- Quote mismatch
- Value mismatch
- Ambiguous or calculated date
- Inferring a missing fact
- Creating a lifecycle record
- External action
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Discard candidates and use manual GuidedLoop entry.
Hardware attribution shadow rules
A locked, evaluation-only hardware attribution ruleset is locally tested; it cannot change operational or patient state.
- Contract
- orthoscrub.orthopaedic-site-rules.v1
- Engine
- Repository deterministic code
- Identifier
- orthoscrub.orthopaedic-site-rules.v1
- Current runtime
- Research archive
- Release decision
- research archive only
- Test dataset
- hardware-attribution-shadow-synthetic-v1
Results are available only for research review and never enter the operational queue.
Inspect controls and operating envelope
- Locked patterns
- Specificity ordering
- Exact laterality safeguards
- Ambiguous site
- Missing laterality
- Conflicting evidence
- Assigning a patient device
- Changing inventory
- Writing to an EHR
- Subgroups: not established
- Overrides: local test only
- Incidents: not established
- Rollback: Disable shadow analysis; retain exact-site production safeguards.
Hardware lifecycle language rules
Deterministic lifecycle-language rules are implemented and synthetic-tested; they do not infer treatment need or clinical state.
- Contract
- orthoscrub.hardware-lifecycle-language.v1
- Engine
- Repository deterministic code
- Identifier
- hardware-lifecycle-language
- Current runtime
- Synthetic fixture
- Release decision
- local demo only
- Test dataset
- hardware-lifecycle-language-synthetic-v1
A reviewer sees the exact source quote before accepting lifecycle evidence.
Inspect controls and operating envelope
- Locked phrases
- Negation handling
- Explicit YYYY-MM-DD dates only
- Negated language
- Uncertain phrasing
- No explicit lifecycle statement
- Inferring intent
- Recommending removal
- Closing follow-up
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Display the source without lifecycle-language flags.
Hardware review resolution rules
Fixed review-reason and next-evidence rules are implemented and synthetic-tested; final resolution remains human-owned.
- Contract
- orthoscrub.hardware-review-resolution.v1
- Engine
- Repository deterministic code
- Identifier
- hardware-review-resolution
- Current runtime
- Synthetic fixture
- Release decision
- local demo only
- Test dataset
- hardware-review-resolution-synthetic-v1
A human reviewer selects and records the final resolution.
Inspect controls and operating envelope
- Closed reason enum
- Closed task enum
- Valid reason-task pairing
- Unsupported reason-task pair
- Invalid reconciliation contract
- Final disposition
- Chart closure
- EHR write
- Patient contact
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Return the case to the unclassified human review queue.
Hardware source-evidence proposal model
A bounded hardware proposal-provider contract is implemented; model invocation is disabled in the public release and every candidate requires deterministic and human review.
- Contract
- orthoscrub.hardware-reconciliation.v2
- Engine
- OpenAI API boundary
- Identifier
- gpt-5.6-terra deployment default
- Current runtime
- Not enabled
- Release decision
- disabled in public release
- Test dataset
- hardware-scrub-messy-synthetic-fixtures.v6
A human reviews reverified candidates before any accepted review record exists.
Inspect controls and operating envelope
- Source, batch, quote, and candidate limits
- API key plus explicit de-identified processing gate required
- Shared client bounds configuration, request and response bytes, redirects, content type, timeout, and failures
- Tool-free structured output
- Shared source-level instruction quarantine before candidate acceptance
- Exact quote and value verification after response
- Missing source quote
- Unsupported field
- Source conflict
- Input over limit
- Creating a trusted fact
- Clinical recommendation
- Patient contact
- EHR or payer action
- Subgroups: not established
- Overrides: local test only
- Incidents: not established
- Rollback: Use the deterministic offline extractor and manual evidence selection.
Hardware source-evidence verifier
A deterministic exact-quote verifier is implemented and synthetic-tested; it verifies source correspondence, not clinical truth.
- Contract
- orthoscrub.hardware-reconciliation.v2
- Engine
- Repository deterministic code
- Identifier
- hardware-source-verifier
- Current runtime
- Synthetic fixture
- Release decision
- local demo only
- Test dataset
- hardware-scrub-messy-synthetic-fixtures.v5
A reviewer selects among verified candidates and resolves conflicts.
Inspect controls and operating envelope
- Known source
- Allowed field
- Exact quote
- Exact value substring
- Bounded lengths
- Quote mismatch
- Value mismatch
- Unknown source
- Unsupported field
- Promoting patient-device association
- Clinical inference
- External action
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Reject all candidates and require manual source review.
Implant identity matching rules
Patient-free identity consolidation and bounded lookup rules are locally tested; registry matches remain untrusted review evidence.
- Contract
- orthoscrub.customer-implant-identity.v1
- Engine
- Repository deterministic code
- Identifier
- customer-implant-identity
- Current runtime
- Local deterministic
- Release decision
- local deterministic only
- Test dataset
- implant-identity-synthetic-fixtures.v1
A reviewer decides whether any match is relevant to the supplied chart evidence.
Inspect controls and operating envelope
- Patient-free allowlist
- Exact identifier normalization
- Single bounded lookup
- Conflict preservation
- Conflicting chart identity
- Ambiguous catalog matches
- No safe exact lookup key
- Sending patient identifiers
- Inferring implantation
- Promoting registry data into chart truth
- Subgroups: not established
- Overrides: local test only
- Incidents: not established
- Rollback: Disable enrichment and retain only the source-backed chart identity.
Implant lifecycle closure rules
Deterministic lifecycle program rules are implemented and synthetic-tested; closure and clinical decisions remain human-owned.
- Contract
- synorthopic.lifecycle-closure-program.v1
- Engine
- Repository deterministic code
- Identifier
- lifecycle-closure-program
- Current runtime
- Synthetic fixture
- Release decision
- local demo only
- Test dataset
- lifecycle-closure-synthetic-program-v1
Only a human-selected, evidence-backed disposition may close an episode.
Inspect controls and operating envelope
- Closed state enums
- Disposition transition rules
- Identity-tier validation
- Missing human disposition
- Insufficient evidence
- Unsupported transition
- Removal recommendation
- Autonomous closure
- Patient contact
- EHR or payer write
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Return the episode to needs-clinician-review without closure.
Limb Relay mobility packet rules
An archived deterministic mobility-packet ruleset is synthetic-tested; it does not create or change clinical instructions.
- Contract
- boast-mobility-2024-prototype / 2024-08
- Engine
- Repository deterministic code
- Identifier
- boast-mobility-2024-prototype
- Current runtime
- Research archive
- Release decision
- research archive only
- Test dataset
- limb-relay-synthetic-packets.v1
A clinician reviews the packet against the original postoperative instructions.
Inspect controls and operating envelope
- Direct-identifier screening
- Allowed terminology
- Source field correspondence
- Direct identifier detected
- Conflicting instruction
- Unsupported terminology
- Generating clinical instructions
- Changing a care plan
- External communication
- Subgroups: not established
- Overrides: local test only
- Incidents: not established
- Rollback: Use the original postoperative documents without a normalized packet.
Operations module assessment rules
Eight deterministic evidence-readiness modules are implemented and synthetic-tested; all downstream decisions and actions remain human-owned.
- Contract
- synorthopic.operations-module-assessment.v1
- Engine
- Repository deterministic code
- Identifier
- orthopedic-operations-modules
- Current runtime
- Synthetic fixture
- Release decision
- local demo only
- Test dataset
- operations-messy-simulation.v1
The responsible operational user reviews each prepared output before any downstream action.
Inspect controls and operating envelope
- Known evidence types
- Fixed required-evidence maps
- Closed status enum
- Missing required evidence
- Disabled module
- Unsupported evidence type
- Clinical decision
- Final coding
- Coverage decision
- Imaging interpretation
- External write
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Show the verified source checklist without module readiness assessment.
Messy-source normalization rules
Deterministic messy-source normalization is implemented and synthetic-tested; ambiguity is quarantined rather than inferred away.
- Contract
- synorthopic.operations-source-normalization.v1
- Engine
- Repository deterministic code
- Identifier
- operations-source-normalization
- Current runtime
- Synthetic fixture
- Release decision
- local demo only
- Test dataset
- operations-messy-source-packet.v1
Quarantined records and conflicts remain visible for human reconciliation.
Inspect controls and operating envelope
- Case binding
- Verification state
- Alias map
- Duplicate rules
- Length and record limits
- Wrong case
- Unverified record
- Conflicting duplicate
- Unknown evidence type
- Inventing missing evidence
- Resolving clinical conflict
- Using wrong-case records
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Discard normalized output and review the original synthetic packet.
Supervised operations run policy
A deterministic supervised-run policy is implemented for synthetic data: preparation is automatic, one final human review remains, and no external action occurs.
- Contract
- synorthopic.operations-supervised-run-bundle.v1
- Engine
- Repository deterministic code
- Identifier
- operations-supervised-run
- Current runtime
- Synthetic fixture
- Release decision
- local demo only
- Test dataset
- operations-supervised-run-synthetic.v1
One final human review is required after all automatic preparation stages complete.
Inspect controls and operating envelope
- Input contract compatibility
- Verified evidence only
- All eight modules present
- Fixed step order
- Contract mismatch
- Unverified evidence
- Missing module assessment
- Intermediate external action
- Automatic final approval
- EHR or payer write
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Bypass automation and review each module assessment directly.
Revenue-cycle preparation rules
Deterministic revenue-cycle preparation is implemented and synthetic-tested; coding, medical necessity, coverage, and submission remain human and external-system responsibilities.
- Contract
- orthoscrub.revenue-cycle-packet.v1
- Engine
- Repository deterministic code
- Identifier
- revenue-cycle-preparation
- Current runtime
- Synthetic fixture
- Release decision
- local demo only
- Test dataset
- revenue-cycle-synthetic-fixtures.v1
A qualified coder, biller, or clinician reviews the packet and owns every final decision and submission.
Inspect controls and operating envelope
- Evidence-ID citation
- Catalog allowlist
- Candidate and input limits
- Human authority markers
- Missing reviewed evidence
- Unsupported catalog candidate
- Unmet payer evidence
- Final coding
- Medical-necessity decision
- Claim or authorization submission
- EHR write
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Export the reviewed evidence without generated coding or payer preparation.
RevisionBoard source-evidence proposal model
An archived de-identified proposal-provider contract is implemented; public model invocation is disabled and outputs cannot become trusted facts automatically.
- Contract
- revisionboard.agent-proposal.v1
- Engine
- OpenAI API boundary
- Identifier
- gpt-5.6-sol deployment default
- Current runtime
- Research archive
- Release decision
- research archive only
- Test dataset
- revisionboard-agentic-synthetic-fixtures.v2
A human acceptance request mechanically reverifies every selected fact.
Inspect controls and operating envelope
- Shared source-level instruction quarantine before fact or action-nomination acceptance
- Prompt checksum
- API key plus explicit de-identified processing gate required
- Shared client bounds configuration, request and response bytes, redirects, content type, timeout, and failures
- Tool-free structured output
- Post-response exact quote verification
- Prompt injection
- Missing exact quote
- Unsupported fact or action kind
- Input over limit
- Diagnosis
- Treatment recommendation
- Patient contact
- Tool use
- External action
- Subgroups: not established
- Overrides: local test only
- Incidents: not established
- Rollback: Use deterministic research fixtures and manual source review.
RevisionBoard exact-quote verifier
An archived deterministic source verifier is implemented; it verifies exact correspondence and does not establish clinical truth.
- Contract
- revisionboard.agent-proposal.v1
- Engine
- Repository deterministic code
- Identifier
- agentic-extraction-verifier
- Current runtime
- Research archive
- Release decision
- research archive only
- Test dataset
- revisionboard-agentic-synthetic-fixtures.v1
Only a human-selected candidate may be reverified for acceptance.
Inspect controls and operating envelope
- Allowed kind
- Named source
- Exact quote
- Exact value
- Explicit observed date
- Quote mismatch
- Value mismatch
- Date mismatch
- Unsupported kind
- Inference
- Automatic action
- Clinical recommendation
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Reject candidates and use manual research annotation.
Specimen report proposal model
An archived specimen proposal-provider contract is implemented; public model invocation is disabled and no clinical interpretation is produced.
- Contract
- revisionboard.specimen-ledger.v1
- Engine
- OpenAI API boundary
- Identifier
- gpt-5.6-sol deployment default
- Current runtime
- Research archive
- Release decision
- research archive only
- Test dataset
- specimen-ledger-synthetic-fixtures.v2
A human accepts each mechanically verified report event before ledger entry.
Inspect controls and operating envelope
- Shared source-level instruction quarantine before candidate acceptance
- API key plus explicit de-identified processing gate required
- Shared client bounds configuration, request and response bytes, redirects, content type, timeout, and failures
- Tool-free structured output
- Exact report-state and quote verification
- Prompt injection
- Uncertain mapping
- Missing exact quote
- Input over limit
- Clinical interpretation
- Diagnosis
- Treatment recommendation
- Action nomination
- External action
- Subgroups: not established
- Overrides: local test only
- Incidents: not established
- Rollback: Use manual specimen ledger entry from the source report.
Specimen report exact-quote verifier
An archived deterministic specimen verifier is implemented; it confirms source correspondence without interpreting clinical meaning.
- Contract
- revisionboard.specimen-ledger.v1
- Engine
- Repository deterministic code
- Identifier
- specimen-ledger-verifier
- Current runtime
- Research archive
- Release decision
- research archive only
- Test dataset
- specimen-ledger-synthetic-fixtures.v1
A human accepts each verified event before it enters the deterministic ledger.
Inspect controls and operating envelope
- Allowed identifiers
- Exact quote
- Report-state match
- Observed-date match
- Value correspondence
- Specimen mismatch
- Quote mismatch
- State mismatch
- Date mismatch
- Clinical interpretation
- Ledger write without human acceptance
- External action
- Subgroups: not applicable
- Overrides: local test only
- Incidents: not established
- Rollback: Reject the event and use manual specimen ledger entry.
Security architecture
Trust boundaries and activation gates
This repository control map separates active public demonstration flows from customer-controlled PHI paths. It is not a certification, compliance determination, or authorization to process patient data.
Customer PHI production authorization: No. Independent penetration test, customer backup restore, external audit archive, and customer risk acceptance are not complete in this release.
Inspect the data-flow map
- Public demonstration request and responseActive public
public data / synthetic clinical data / no external actionpublic-browserpublic-worker - Public synthetic case persistenceActive public
synthetic clinical data / operational no patient data / no external actionpublic-workerpublic-d1 - Patient-free public registry lookupActive public
public data / no external actionpublic-workerpublic-registries - Authenticated private reviewer sessionCustomer configuration required
customer phi / customer confidential non phi / no external actioncustomer-reviewercustomer-runtime - Customer workforce identity exchangeCustomer configuration required
credential material / customer confidential non phi / no external actioncustomer-runtimeworkforce-idp - Tenant-scoped customer workflow persistenceCustomer configuration required
customer phi / customer confidential non phi / no external actioncustomer-runtimecustomer-postgres - Least-privilege EHR readCustomer configuration required
customer phi / no external actioncustomer-runtimehospital-ehr - Human-authorized administrative EHR Task handoffCustomer configuration required
customer phi / customer confidential non phi / external actioncustomer-runtimehospital-ehr - Independent operational audit exportCustomer configuration required
operational no patient data / customer confidential non phi / external actioncustomer-runtimeexternal-audit - Patient-free private SpineCPT lookupImplemented, disabled
licensed reference data / customer confidential non phi / no external actioncustomer-runtimeprivate-spinecpt - Optional bounded model inferenceImplemented, disabled
customer phi / customer confidential non phi / no external actioncustomer-runtimemodel-provider - Accountable human review and final decisionCustomer configuration required
customer phi / customer confidential non phi / no external actionaccountable-humancustomer-runtime
Controls still required for activation
- Customer retention and deletion operationcustomer required
No customer-specific deletion exercise exists in the public repository.
- Customer backup and disaster recovery operationcustomer required
Repository release recovery does not prove customer PHI database recovery.
- Independent penetration test and remediation reviewexternal required
No independent penetration-test report is complete in this repository.
Residual risks that block activation
- Malicious chart text or model output attempts to bypass policyhigh residual risk
Untrusted text becomes an instruction, hides uncertainty, or initiates a forbidden action.
- Model-provider egress discloses or retains PHI outside approvalhigh residual risk
Sensitive context reaches an unapproved host, region, log, retention path, or subcontractor.
- Audit evidence is lost, reordered, replayed, or alteredhigh residual risk
The runtime cannot prove which actor, evidence, policy, or external action occurred.
- Customer records cannot be restored or deleted according to policyhigh residual risk
A backup is unusable, keys are unavailable, or retention diverges across systems.
Brand, navigation, roles, copy, and module visibility live in a schema-checked manifest.
Evidence, rules, coding, and workflow state are tested without rendering React.
EHR, payer, PACS, UDI, and messaging transports implement narrow ports.
Every module declares what it can prepare, who reviews it, and what it cannot do.