Conformance Evidence
This table gives reviewers a concise control map. It identifies the claim, the evidence to request, and the regression check that should remain green in CI.
Control |
Evidence |
Automated check |
Authority alignment |
|---|---|---|---|
Raw files are not assistant-readable. |
Agent path validator rejects raw, staging, audit, and snapshot locations. |
|
ICMR confidentiality; HIPAA minimum necessary posture. |
Staging is temporary and restricted. |
|
|
ICMR confidentiality; NIST de-identification operations. |
Direct identifiers are removed or pseudonymized before publish. |
PHI scrub catalog and per-run PHI scrub report. |
|
HIPAA 45 CFR 164.514; DPDPA/SPDI; Aadhaar/ABDM. |
Dates are protected. |
Default date drop/shift behavior; Limited Dataset attestation when precise-date utility is approved. |
|
HIPAA Safe Harbor/Limited Dataset; ICMR privacy. |
Government IDs are blocked. |
Scrub catalog, PHI gate catalog, and PHI gate test results. |
|
Aadhaar Act; ABDM; DPDPA/SPDI. |
Row-level assistant answers are privacy-gated. |
k-anonymity and l-diversity gate behavior. |
|
ICMR confidentiality; re-identification risk reduction. |
PDF content is PHI-safe before LLM use. |
Redact-then-call orchestrator, PHI-free PDF attestation gate for legacy raw-PDF path, and PDF redaction tests. |
|
HIPAA disclosure controls; ICMR confidentiality. |
Audit artifacts do not expose row data. |
Counts-only audit reports and lineage manifest. |
|
IRB/IEC auditability without raw-PHI disclosure. |
Logs and persisted assistant text are redacted. |
Log hygiene filter and at-rest redaction helpers. |
|
HIPAA audit/security safeguards; ICMR confidentiality. |
Reviewed snapshots cannot be served directly. |
Snapshot baseline restores over |
|
Data minimization; stale-baseline disclosure prevention. |
Reviewer Evidence Package
For a submission or audit, attach:
the commit SHA under review,
CI results for tests, lint, typecheck, dependency audit, and docs,
a representative
output/{STUDY}/audit/package with raw PHI withheld,the PHI scrub configuration used for the run,
the PHI-key custody statement without the key value,
any Limited Dataset or PHI-free PDF attestation that enabled a higher-risk mode.
Open Operator Items
These items are study-team responsibilities before production research use:
breach-response runbook,
retention and destruction runbook,
consent-scope or approved-field allowlist when required by the IEC/IRB,
district population-threshold mapping if geography is retained,
narrative/free-text retention approval if narrative fields are ever needed.