Files and artifacts
File-like endpoints need stronger evidence than ordinary JSON records because they can expose PHI, raw payer/EHR data, signed URLs, storage keys, or generated legal/financial artifacts.
Metadata first
Until content class, scanning, ownership, retention, and URL policy are approved, public examples should show only opaque IDs and safe metadata.
Current rules
| Topic | Current | Rule |
|---|---|---|
| Content classes | Documents, PDFs, reports, transcripts, recordings, OCR output, EDI, and remittance artifacts are not fully classified. | Use metadata-only examples. |
| Ownership | Tenant and owner resource checks must be proven per route. | Never expose storage keys as public identifiers. |
| Download URLs | Signed URL behavior is not globally approved. | Do not publish signed URL examples until file governance closes. |
| Retention | Retention, expiration, legal hold, and deletion are endpoint-specific or unresolved. | Avoid lifecycle promises without release evidence. |
| Raw payloads | Raw EDI, payer/EHR payloads, transcripts, and document contents are sensitive. | Do not place raw contents in examples or troubleshooting. |
Content classes
| Class | Examples | Publication |
|---|---|---|
| Metadata-only record | File ID, filename label, content type, size, checksum status, created timestamp, owning workflow ID. | Allowed only when tenant ownership and PHI-safe fields are documented. |
| Upload request | Document attachments, support files, ADR packets, credentialing documents. | Blocked until content class, scanning, limits, ownership, and retention rules are approved. |
| Generated artifact | PDFs, reports, statements, appeal packets, GFE artifacts, OCR output. | Blocked from retrieval examples until E4 and endpoint-specific release evidence close. |
| Raw exchange payload | EDI, remittance details, payer/EHR responses, transcripts, audio, portal captures. | Do not include raw contents in docs, examples, logs, tickets, or troubleshooting snippets. |
Safe metadata fields
| Field | Rule |
|---|---|
| id | Use an opaque QuickRCM file or artifact ID. Do not expose bucket names, object keys, paths, or storage provider internals. |
| contentType | Show broad MIME type only when it does not reveal sensitive document content beyond the endpoint purpose. |
| sizeBytes | Safe as metadata when route ownership and upload limits are documented. |
| checksum | Safe as an integrity value when not used as a storage lookup secret. |
| workflowResourceId | Safe only if the referenced patient, claim, job, batch, or case ID belongs to the authenticated tenant. |
| downloadUrl | Blocked until proxy or presigned URL policy is approved for that content class. |
Lifecycle requirements before publication
| Topic | Rule |
|---|---|
| Scanning | Public upload docs must say whether malware, file-type, size, and content validation happen before use. |
| Access checks | Every retrieval must verify tenant ownership and referenced workflow ownership before returning metadata or bytes. |
| Retention | Do not promise expiration, deletion, legal hold, or archival behavior until the endpoint declares it. |
| Errors | Return sanitized messages. Do not include storage keys, signed URLs, raw vendor payloads, document text, or stack traces. |