Smile With Style | Office OS readiness checklist614-428-8002

24-hour readiness plan

GCS storage is implemented. Real PHI launch is locked behind a short approval checklist.

Codee can safely continue building the Office OS flow now. The backend accepts demo/no-PHI signed packets into private GCS, blocks production PHI unless the launch flag is turned on, and keeps Brevo email disabled until the office approves staff process and message language.

Done

Private GCS packet, record, index, and audit writes are implemented through server-side credentials.

Locked

Production PHI submission is blocked until the backend PHI launch flag is intentionally enabled.

Gated

Brevo email is disabled by default and turns on only after staff/client approval.

Left

BAA, approved template, retention, access policy, staff training, and go-live sign-off.

Official implementation status

What is active now.

This is the practical launch board. It separates technical work already implemented from the minimum administrative approvals still required before real patient information goes live.

ItemStatusApplied nowRemaining action
Private GCS storage Implemented Signed HTML packet, record JSON, review index, and audit metadata write to private GCS paths through the backend. Confirm final production bucket/retention naming with the office.
No browser keys Implemented Public pages submit to the backend only. Service credentials stay server-side. Keep this rule permanent.
PHI launch lock Implemented Production PHI mode is rejected unless `OFFICE_OS_PHI_ENABLED=1` or `CODEE_OFFICE_OS_PHI_ENABLED=1` is set. Enable only after BAA, training, retention, access policy, and client approval.
Brevo email gate Implemented Email is disabled unless `OFFICE_OS_EMAIL_ENABLED=1` or `CODEE_OFFICE_OS_EMAIL_ENABLED=1` is set. Approve sender, email copy, support contact, and staff procedure before enabling.
Authenticated staff review Foundation ready Protected backend review endpoint resolves private metadata and short-lived signed file URLs. Replace shared token review with final staff accounts/MFA before PHI.
Final PDF packet Demo implemented The backend now generates a signed PDF packet for the Edge upload bridge and stores a private copy with the signed packet metadata. Replace demo wording with the office's approved contract and finalize PDF layout before live patient use.
BAA and policy packet Approval page ready Vendor/bucket approval page can be signed and stored in private GCS now as a readiness record. Execute final legal BAA path, breach-response contact, and privacy/security policy approval before ePHI.
Staff training Client/admin Training topics are listed in the launch checklist. Run a 30-45 minute session and mark the staff roster complete.

Minimal items left

What Smile With Style gives us for a 24-hour turnaround.

Once these are supplied, Codee can move from demo/no-PHI storage into a controlled production launch path.

1

Approved contact

Name and email for the person allowed to approve Office OS, storage, staff access, and email wording.

2

Staff roster

Names and roles for sender, reviewer, admin, export/archive, and support contact.

3

Contract language

Final attorney/practice-approved agreement or written approval to keep the demo as non-PHI only.

4

Retention rule

How long signed packets stay stored, who can archive, and who can delete/export.

5

Vendor / BAA path

Use the vendor approval page to sign managed-bucket authorization now; final legal BAA remains required before ePHI.

Open vendor approval

6

Brevo approval

Sender name, sender email, message copy, and approval to enable review-link email.