TFD Transcript Reuse

ADR 0069 · Implemented in the monolith · Deployment and recipient approval required

TFD Transcript Reuse ADR 0069 · Implemented in the monolith · Deployment and recipient approval required Owner transcripts · Sales / Clinical protected source · Architecture component · Implemented Owner transcripts Sales / Clinical protected source Implemented De-identification · Local transform · PHI until release · Architecture component · Implemented De-identification Local transform · PHI until release Implemented Release decision · Safe Harbor / expert evidence · Architecture component · Implemented Release decision Safe Harbor / expert evidence Implemented Derived index · Approved text · pgvector · Architecture component · Implemented Derived index Approved text · pgvector Implemented Review required · No index or external disclosure · Architecture component · Implemented Review required No index or external disclosure Implemented Authorized retrieval · Actor · purpose · current grants · Architecture component · Implemented Authorized retrieval Actor · purpose · current grants Implemented Domain assessments · Sales · Clinical · Delivery · Architecture component · Implemented Domain assessments Sales · Clinical · Delivery Implemented Legend Database Security Backend

Protected source boundary

  • • Identified originals and reversible mappings remain with their owner; no shared clinical source copy.
  • • Sales owns original sales transcript revisions. Clinical owns private-care transcripts; Delivery owns scheduling and VIT service-quality assessments.
  • • Transcription of raw media requires a separately approved PHI processing path.

Release gate

  • • Masking produces a candidate, never an automatic HIPAA certification.
  • • Review the entire recipient payload, metadata and identifying narrative. Ambiguity fails closed.
  • • A release pins source revision, transformed hash, method, policy, purpose and recipient.

Reuse and revocation

  • • Only reviewed released text reaches the shared index or de-identified provider route. Legacy identified Sales egress requires a separate expiring approval.
  • • Internal source links stay restricted. Free-text queries stay local; semantic similarity uses approved stored vectors.
  • • Source corrections and revocations atomically invalidate assessments, remove derivatives and cancel jobs. Lease/generation checks prevent stale worker publication.
  • • Implemented in the repository; production activation and representative review are still required. Existing Sales embeddings are excluded and not certified.