Collect
Group de-identified notes, radiology reports, implant logs, and structured device records under opaque, device-specific episode codes so two implants in one patient do not become a false conflict.
Bounded workflow loading
The interface is loading. No clinical action is performed by this state.
Retrospective orthopaedic hardware reconciliation
Synorthopic reviews de-identified operative notes, implant logs, clinic notes, radiology reports, and FHIR device records. It assembles a longitudinal hardware inventory, preserves the exact words that support each episode, surfaces contradictions across adult and pediatric orthopaedics, and hands a human the smallest defensible clinical or administrative decision.
Evidence assembly—not autonomous medicine. It does not prove physical presence from documentation alone, identify hardware from radiographs, infer removal intent, or write to an EHR.
Agent found a follow-up gap
“Hardware: Pectus Support Bar System”
“Plan: remove the Nuss bar on 2026-07-15”
What it actually does
Group de-identified notes, radiology reports, implant logs, and structured device records under opaque, device-specific episode codes so two implants in one patient do not become a false conflict.
Propose hardware name, manufacturer, model, catalog, UDI, site, dates, and lifecycle language—with the exact quote—and retain every explicitly named construct family in a multi-component description.
Merge exact agreement into a patient-level inventory of implant episodes, explicit removals, open temporary loops, and unresolved state—then stop on contradictions.
Confirm evidence, mark unresolved, or label a conflict; save an audit row and jump to the next case from the keyboard.
New · downstream access workflow
The same evidence-bounded workflow now covers adult external fixation, staged antibiotic spacers, trauma hardware, and every other family with an explicit removal plan—not only pediatric implants. It prepares missing-documentation checks, a governed SpineCPT private handoff, and payer-routing steps while keeping final codes, medical necessity, and submission human.
Open access & coding workbenchInteractive workbench
Synthetic examples span guided growth, pediatric and adult trauma, documented removal, revision exchange, growing rods, flexible nails, external fixation, and adult spine instrumentation. Lifecycle-sensitive families receive review priority, but family membership never asserts removal.
Select type-separated NDJSON plus, when available, one de-identified cohort-roster JSON and one completion-manifest JSON. The roster must exactly match the selected Patient resources; when supplied, every clinical resource must also resolve to exactly one matched Patient. Absolute FHIR references require a matching completion-manifest request base. To verify package provenance, also select the matching flattened ES256 JWS JSON and public JWK together. Imports stay in this browser with no upload, persistence, or EHR write. This hosted prototype is not approved for PHI. Exact roster and patient-link agreement do not establish roster authority, EHR authorization, or source completeness. A valid signature still does not establish who owns the supplied key.
Signed EHR-event intakeNo signed EHR queue has been loaded.Synthetic only · exact reviewer allowlist · exact tenant binding · no autonomous disposition
Resolution queue
No saved unresolved or conflicting dispositions are waiting for another evidence pass.
No administrative EHR task has been prepared in this browser session.Longitudinal hardware inventory
Each device row stays separate. Patient-level reports that cannot be tied to exactly one device stay explicitly unassigned, and a same-site multi-device chart becomes an attribution risk instead of a guessed implant. Every row names the next administrative evidence task. Missing removal documentation never becomes proof that hardware remains in the body. Exact serial-bound evidence can still surface a cross-date link candidate without merging episodes.
No-removal rule: “No completed-removal record in this batch” is a documentation finding, not proof of current physical presence. Every inventory row remains human-review required and makes zero EHR writes.
Bounded extraction is readySynthetic cases are loaded. No chart data has left this page.
Case PEDS-HIP-256
Resolve UDI in GUDID to translate the chart-backed DI into manufacturer, brand, model, and catalog evidence.
An exact DI match does not prove that this device was implanted, remains physically present, was intended to be temporary, or was removed. Those claims still need chart evidence and human review.
Broad hardware coverage
Component-aware recognition can preserve several construct families from one source description across pediatric and adult orthopaedics, without pretending every implant is temporary or that this catalog is exhaustive.
EHR connection path
This build now contains the SMART authorization-code + PKCE engine and GET-only FHIR census transport, and can run both end to end against a fictional EHR. Activating them for a real hospital still requires customer registration, approved scopes, a secure tenant-bound session runtime, and site-specific completeness validation. Until then, this is a synthetic integration simulator, not a deployed clinical system.
The chart scrub queue remains usable while this independent module loads. It cannot receive credentials or patient data.
Chart launch uses authorization code + PKCE S256. Retrospective service access uses SMART Backend Services with a one-time private_key_jwt signed by ES384, bounded FHIR Group Bulk Data discovery, multi-patient windows, and HMAC-bound resume checkpoints. The background demonstration encrypts its synthetic manifest in tenant-partitioned D1, acquires a short lease for each window, compare-and-swaps the cursor, and purges the completed row. Both paths finish in the same FHIR queue. Patient-filtered document records can hydrate bounded text notes through authenticated, same-server Binary reads; source URLs are stripped. Neither path returns its token, code, verifier, assertion, private key, raw Patient resources, checkpoint, or patient identifier in the audit.
Not run yet. The demonstration uses a fictional authorization server, fictional records, and in-memory transports.
The reusable launch boundary now keeps private SMART state in an encrypted, tenant-hashed, ten-minute D1 session with atomic one-time callback consumption. A disabled-by-default bridge can now exercise a registered vendor sandbox and return fictional FHIR evidence through a same-origin popup directly into this queue. It is hard-coded to synthetic data and a single configured sandbox tenant; startup also requires a visibly non-production hostname and an explicit synthetic-data attestation. Those configuration checks reduce accidental misuse but do not certify the remote dataset. A live customer deployment still requires authenticated customer-to-tenant mapping, approved key management, monitored exchange, and an approved PHI runtime. This build blocks PHI, does not schedule a clinical job, and is not connected to a hospital.
Pull permitted device and note evidence, run reconciliation, and compare against the incumbent registry. No chart changes.
Launch in patient context, show exact provenance, and let the reviewer finish inside the institution’s authorized workflow.
Create an allow-listed task or structured reconciliation result only after an explicit human action and rollback testing.
Security & compliance readiness
Before any PHI reaches an OpenAI endpoint, the customer must have an applicable BAA and eligible API configuration, including the required retention controls. store: false alone is not a HIPAA program.
The value test
Counts foreground time and actual review-control interactions. Implant identity yield excludes patient-level evidence that has not been safely assigned to a device. The report stays aggregate and local to this browser session.
Measurement starts when the first review is savedNo time or click savings claim is valid without a separately locked incumbent baseline. Unsupported identity, missed-conflict, and lifecycle error rates require independent chart adjudication; interface telemetry cannot estimate them.
No case IDs, patient identifiers, source text, quotes, free text, or registry queries · resets on refresh · 0 EHR writes
Use observed aggregate metrics from the same cohort and the same definitions: structured means UDI, manufacturer + catalog, or manufacturer + model; unresolved/conflict means the final human disposition. A SHA-256 digest detects edits, but is not an external timestamp, independent verification, or permission to claim savings.
No incumbent baseline locked. Enter observed aggregate metrics before the first assisted review.
Aggregate only · no case IDs or source content · local session order can be reset and is not externally timestamped · independent analysis remains mandatory · do not backfill after seeing results
Two reviewers receive source text without Synorthopic's identity, conflict, registry, lifecycle, or final-review output. Both independently apply the same fixed labels. Any disagreement suppresses every error-rate estimate. Patient-level evidence awaiting device attribution is excluded from implant identity and lifecycle scoring and remains separate attribution workload.
Safety rates blocked until independent evidence is completeDownload a source-only assignment, obtain two independent fixed-label reviews, then import both locked result files.
Assignment: source text, local-only, deidentified attestation required, not approved for PHI · reviewer result: fixed labels only · report: aggregate only, no case IDs or evidence · no threshold, causal, efficacy, or autonomous-use claim
This separate study shows two reviewers the device-unassigned record plus every supplied implant episode in the same opaque patient group. It hides Synorthopic's same-site and laterality filter, risk flag, and candidate set. Agreement can measure missed ambiguity, unnecessary review flags, and candidate-device recall without ever assigning the evidence automatically.
Evaluation only: locked ruleset orthoscrub.orthopaedic-site-rules.v1 is measured against the current exact-match rule. It does not alter the queue, assign a device, merge episodes, or infer physical presence.
Attribution rates blocked until independent evidence is completeDownload the separate source-only attribution assignment, obtain two independent fixed-label reviews, then import both locked result files.
Assignment: unassigned source + every supplied same-patient episode, local-only, not approved for PHI · reviewer result: fixed association labels + opaque episode codes · report: aggregate only · 0 automatic assignments, merges, or presence inferences
Share of reviewed records with source-backed UDI, manufacturer + catalog, or manufacturer + model identity.
Median human seconds per case, clicks per case, and percentage completed keyboard-only.
Unsupported identity rate, missed conflicts, and erroneous temporary/removal classifications.
Stop if the current EHR report or registry achieves the same reconciled coverage with comparable setup and review effort.
The queue remains interactive while the bounded model-and-rules evidence ledger loads separately.