Private GCS packet, record, index, and audit writes are implemented through server-side credentials.
24-hour readiness plan
GCS storage is implemented. Real PHI launch is locked behind a short approval checklist.
Codee can safely continue building the Office OS flow now. The backend accepts demo/no-PHI signed packets into private GCS, blocks production PHI unless the launch flag is turned on, and keeps Brevo email disabled until the office approves staff process and message language.
Production PHI submission is blocked until the backend PHI launch flag is intentionally enabled.
Brevo email is disabled by default and turns on only after staff/client approval.
BAA, approved template, retention, access policy, staff training, and go-live sign-off.
Official implementation status
What is active now.
This is the practical launch board. It separates technical work already implemented from the minimum administrative approvals still required before real patient information goes live.
| Item | Status | Applied now | Remaining action |
|---|---|---|---|
| Private GCS storage | Implemented | Signed HTML packet, record JSON, review index, and audit metadata write to private GCS paths through the backend. | Confirm final production bucket/retention naming with the office. |
| No browser keys | Implemented | Public pages submit to the backend only. Service credentials stay server-side. | Keep this rule permanent. |
| PHI launch lock | Implemented | Production PHI mode is rejected unless `OFFICE_OS_PHI_ENABLED=1` or `CODEE_OFFICE_OS_PHI_ENABLED=1` is set. | Enable only after BAA, training, retention, access policy, and client approval. |
| Brevo email gate | Implemented | Email is disabled unless `OFFICE_OS_EMAIL_ENABLED=1` or `CODEE_OFFICE_OS_EMAIL_ENABLED=1` is set. | Approve sender, email copy, support contact, and staff procedure before enabling. |
| Authenticated staff review | Foundation ready | Protected backend review endpoint resolves private metadata and short-lived signed file URLs. | Replace shared token review with final staff accounts/MFA before PHI. |
| Final PDF packet | Demo implemented | The backend now generates a signed PDF packet for the Edge upload bridge and stores a private copy with the signed packet metadata. | Replace demo wording with the office's approved contract and finalize PDF layout before live patient use. |
| BAA and policy packet | Approval page ready | Vendor/bucket approval page can be signed and stored in private GCS now as a readiness record. | Execute final legal BAA path, breach-response contact, and privacy/security policy approval before ePHI. |
| Staff training | Client/admin | Training topics are listed in the launch checklist. | Run a 30-45 minute session and mark the staff roster complete. |
Minimal items left
What Smile With Style gives us for a 24-hour turnaround.
Once these are supplied, Codee can move from demo/no-PHI storage into a controlled production launch path.
Approved contact
Name and email for the person allowed to approve Office OS, storage, staff access, and email wording.
Staff roster
Names and roles for sender, reviewer, admin, export/archive, and support contact.
Contract language
Final attorney/practice-approved agreement or written approval to keep the demo as non-PHI only.
Retention rule
How long signed packets stay stored, who can archive, and who can delete/export.
Vendor / BAA path
Use the vendor approval page to sign managed-bucket authorization now; final legal BAA remains required before ePHI.
Brevo approval
Sender name, sender email, message copy, and approval to enable review-link email.