Files and artifacts

File-like endpoints need stronger evidence than ordinary JSON records because they can expose PHI, raw payer/EHR data, signed URLs, storage keys, or generated legal/financial artifacts.

Metadata first

Until content class, scanning, ownership, retention, and URL policy are approved, public examples should show only opaque IDs and safe metadata.

Current rules

TopicCurrentRule
Content classesDocuments, PDFs, reports, transcripts, recordings, OCR output, EDI, and remittance artifacts are not fully classified.Use metadata-only examples.
OwnershipTenant and owner resource checks must be proven per route.Never expose storage keys as public identifiers.
Download URLsSigned URL behavior is not globally approved.Do not publish signed URL examples until file governance closes.
RetentionRetention, expiration, legal hold, and deletion are endpoint-specific or unresolved.Avoid lifecycle promises without release evidence.
Raw payloadsRaw EDI, payer/EHR payloads, transcripts, and document contents are sensitive.Do not place raw contents in examples or troubleshooting.

Content classes

ClassExamplesPublication
Metadata-only recordFile ID, filename label, content type, size, checksum status, created timestamp, owning workflow ID.Allowed only when tenant ownership and PHI-safe fields are documented.
Upload requestDocument attachments, support files, ADR packets, credentialing documents.Blocked until content class, scanning, limits, ownership, and retention rules are approved.
Generated artifactPDFs, reports, statements, appeal packets, GFE artifacts, OCR output.Blocked from retrieval examples until E4 and endpoint-specific release evidence close.
Raw exchange payloadEDI, remittance details, payer/EHR responses, transcripts, audio, portal captures.Do not include raw contents in docs, examples, logs, tickets, or troubleshooting snippets.

Safe metadata fields

FieldRule
idUse an opaque QuickRCM file or artifact ID. Do not expose bucket names, object keys, paths, or storage provider internals.
contentTypeShow broad MIME type only when it does not reveal sensitive document content beyond the endpoint purpose.
sizeBytesSafe as metadata when route ownership and upload limits are documented.
checksumSafe as an integrity value when not used as a storage lookup secret.
workflowResourceIdSafe only if the referenced patient, claim, job, batch, or case ID belongs to the authenticated tenant.
downloadUrlBlocked until proxy or presigned URL policy is approved for that content class.

Lifecycle requirements before publication

TopicRule
ScanningPublic upload docs must say whether malware, file-type, size, and content validation happen before use.
Access checksEvery retrieval must verify tenant ownership and referenced workflow ownership before returning metadata or bytes.
RetentionDo not promise expiration, deletion, legal hold, or archival behavior until the endpoint declares it.
ErrorsReturn sanitized messages. Do not include storage keys, signed URLs, raw vendor payloads, document text, or stack traces.