# False-positive ledger for tools/phi_scan.py. Entries are matched lowercase.
# Every entry needs a justification. Adding a real identifier here would be
# a policy violation — entries must be provably public vocabulary.

# Column names from Practice Fusion's OFFICIAL PUBLIC EHI export data
# dictionary v9 (practicefusion.com/ehi-export-documentation, verified
# 2026-06-11). They are >=24 chars, so the deny-list generator's
# opaque-token pass hashed them out of the private predecessor's source;
# they are public schema identifiers, not PHI.
diagnosiscodeequivalents
lastmodifiedbyproviderguid
patientinsuranceplanguid
transactiondisplaydatetimeutc
# patient-guarantor.tsv column (gpdfs:951 consumes it; same v9 dictionary).
billingpatientrelationshipoption

# Synthetic dates of birth of fixture patients "Ada Fixture", "Boris Sample"
# and "Cleo Placeholder" (tests/fixtures/pf_tebra_v9) and "Synthia Probe"
# (tests/unit/test_qa.py). Tests assert rendered chart headers
# ("DOB mm/dd/yyyy"), which legitimately put the DOB marker next to the date;
# the golden rendering snapshot (tests/e2e/goldens/) stores that same
# synthetic chart text verbatim, so the fixture DOBs appear there too.
# 03/15/1988 is the synthetic guarantor "Gus Placeholder" (payment section
# DATE OF BIRTH cell, asserted by the PF-pack payment tests + golden).
03/14/1985
07/04/1952
12/01/2021
01/02/1980
03/15/1988

# Synthetic near-miss dates used by the QA boundary-matching regression
# tests (tests/unit/test_qa.py): they prove a record DOB of 1/2/1980 does
# NOT match a chart showing 11/2/1980.
1/2/1980
11/2/1980

# Synthetic near-miss dates for the boundary-anchored identity regression
# tests (tests/unit/test_identity.py, test_verify_levels.py, test_browserpack.py):
# the same shape as the 1980 pair above, one octave up. They prove a record DOB
# of 1/2/1990 does NOT match a chart showing 11/2/1990 (an unpadded DOB hiding
# inside a longer date) — the wrong-patient collision the shared predicate
# (anastomosis.core.identity) rejects. Fully synthetic; never a real DOB.
1/2/1990
11/2/1990

# Synthetic DOBs for the L0-L6 delivery-verification tests
# (tests/unit/test_verify_{levels,composite}.py). The synthetic patient
# "Synthia Testpatient" has DOB 01/02/1990; the tests render that into a fake
# chart header ("DOB mm/dd/yyyy") and assert L2/L3 match it. The other two are
# the deliberate WRONG-patient DOBs the wrong-chart tests prove are rejected
# (12/31/1965 on a right-name page; 03/04/1975 on a different-patient page).
01/02/1990
12/31/1965
03/04/1975


# Synthea sample C-CDA fixture (tests/fixtures/synthea/) — GUIDs generated
# by the Synthea synthetic-patient simulator (MITRE, Apache-2.0). The data
# is fully synthetic by the project's own statement ('No individual-level
# data was used in creating it'); provenance + license in the fixture
# README. These are Synthea's deterministic per-patient ids, not PHI.
3da68fbe-0b08-2747-00ee-3c459e7d73b8
3da68fbe-0b08-2747-26b9-7d220d57943f
3da68fbe-0b08-2747-339a-0f93da593992
3da68fbe-0b08-2747-4756-7828291dca5a
3da68fbe-0b08-2747-4896-0a30f5636eba
3da68fbe-0b08-2747-51af-09d2403be6d7
3da68fbe-0b08-2747-597c-e0f6e75a4c68
3da68fbe-0b08-2747-6361-641bcddd2868
3da68fbe-0b08-2747-649a-06e4b36b4259
3da68fbe-0b08-2747-7102-fa7f2e8464b0
3da68fbe-0b08-2747-806a-e14daa1e0d66
3da68fbe-0b08-2747-9349-fe12a0625649
3da68fbe-0b08-2747-9f8d-113f65f61ae6
3da68fbe-0b08-2747-a146-16c4459ba196
3da68fbe-0b08-2747-ae2c-55cf62ffea38
3da68fbe-0b08-2747-b50d-b062e56e914b
3da68fbe-0b08-2747-b85d-2f7af9c1957e
3da68fbe-0b08-2747-c114-ca24f5917d6a
3da68fbe-0b08-2747-d23f-6aec7d98e0aa
3da68fbe-0b08-2747-d49f-6c8bf3955adb
3da68fbe-0b08-2747-d4b8-2807b7fa8d91
3da68fbe-0b08-2747-dbbd-0b2f253fdfbc
3da68fbe-0b08-2747-dc0e-437b9970c8cd
3da68fbe-0b08-2747-dcd3-31aa2816d32b
3da68fbe-0b08-2747-e0c9-6a693abacce8
3da68fbe-0b08-2747-e7ab-dd9b19ac6cfc
3da68fbe-0b08-2747-f0e4-d10398ebd4a7
3da68fbe-0b08-2747-f7ef-2241eac48bfe

# The Microsoft Edge WebView2 Runtime's EdgeUpdate "Clients" GUID — a fixed,
# PUBLIC Microsoft product identifier the Windows installer (packaging/
# anastomosis.iss) reads to detect whether WebView2 is present
# (learn.microsoft.com/microsoft-edge/webview2/concepts/distribution). A vendor
# constant, not PHI.
f3017226-fe2a-4295-8bdf-00c3a9a7e4c5
# Windows installer product identity (packaging/anastomosis.iss AppId) — a
# generated application GUID, not a record identifier; stable for the life
# of the product so upgrades find the existing install.
eec2f7c9-06ad-4bc2-91d4-84bbae937b98

# --- Approved opaque content, by FILE hash (default-deny for everything else) -
# The scanner cannot read binary/media content, nor a base64-armored payload
# inside a text file (a `data:...;base64,...` run: the token splitter shreds it
# and every pattern sails through). Both need the file's hash here WITH
# provenance; unlisted, either one fails the scan. The digest covers the whole
# file, so an approval expires the moment the file changes.
# Regenerate a hash after an intentional change: sha256sum <file>.

# assets/icon/icon.ico — generated from the in-repo assets/icon/icon.svg
# master via tools/make_icons.py (project asset, AGPL-3.0-or-later).
sha256:82324091f0b464f5b71ac9f609404a9b2823b7d295e3b334fff054dea79f7f69
# assets/installer/wizard-small.bmp — generated from assets/icon/icon.svg via
# tools/make_icons.py (project asset, AGPL-3.0-or-later).
sha256:0efc9e015446ae3424e9e5e739b9cca715a5575989e293f5a037ee9bb65f4aeb
# assets/installer/wizard.bmp — generated from assets/icon/icon.svg via
# tools/make_icons.py (project asset, AGPL-3.0-or-later).
sha256:3521f68c6bcea421ad8c8d11f93faae576bbfd06559419a9b8144c1743c95308
# src/anastomosis/gui/web/fonts/JetBrainsMonoVF.woff2 — JetBrains Mono
# variable font (JetBrains, SIL OFL-1.1; github.com/JetBrains/JetBrainsMono).
sha256:31ec365b93e4bad6f202ce23352a56d01ca4462b2afc782ed2cf6fa42ca9ac0e
# src/anastomosis/gui/web/fonts/MonaSansVF.woff2 — Mona Sans variable font
# (GitHub, SIL OFL-1.1; github.com/github/mona-sans).
sha256:2affc0f41c81325062c297e46762ebd28effa15a64e56e936403981f3dbd7e7d
# src/anastomosis/reconstruct/ccda_standard/vendor/CDA.xsl — HL7's official
# C-CDA stylesheet, vendored UNMODIFIED at tag v4.1.0-beta.2
# (github.com/HL7/cda-core-xsl, Apache-2.0) and pinned by the same digest in
# vendor/PINNED.md, which documents the verifiable re-vendor command. The two
# base64 runs it carries (lines ~2540 and ~6263) are the stylesheet's OWN
# `data:image/png` toolbar icons, not repository content.
sha256:f1c32f11186cf69d64f874cc4c94eb51ca8f696b54b4b6833fb54c6afdd7acc1
