Sentinel Policy — Code-System Rights Matrix
Living document. Human-readable rendering of policy/src/sentinel_policy/rights/registry.py's CODE_SYSTEM_RIGHTS -- that module is the authoritative machine-readable source of truth; this file explains the reasoning and citations behind each entry.
These are the M0 spec's own conservative initial product decisions, not substitute legal opinions. A qualified healthcare/software intellectual-property attorney must validate the final classifications before any commercial launch (spec §34) — the five specific questions that review should answer are listed in sentinel-policy-m0-commercial-feasibility-gate-v1.0.688.md.
Rights classes: GREEN (affirmatively cleared, never the default) / YELLOW (partially permitted or unresolved; distribute=false by default) / RED (license required, not currently held) / UNKNOWN (not reviewed — behaves like RED for commercial projection, fail-closed per RIGHTS-001).
| code_system | Owner | Rights class | Reasoning | |---|---|---|---| | CPT | American Medical Association | RED | CMS's own click-through agreement for the Coverage API does not grant Sentinel Signal a commercial redistribution license for CPT content — a separate AMA commercial license is required. AMA's licensing FAQ: https://www.ama-assn.org/practice-management/cpt/cpt-licensing-frequently-asked-questions-faqs. The AMA publishes 2026 royalty schedules (cited Standard CPT rate ~$18.50/user under several distribution models) — informational for a future licensing decision, not something to hard-code into the product. | | CDT | American Dental Association | RED | ADA states CDT commercial use/copying/distribution generally requires a commercial license, and explicitly treats embedded use contributing to generated outputs as licensed use. Not currently extracted by any adapter (no CDT content has ever appeared in affected_codes), classified for completeness ahead of any future dental-content source. | | HCPCS_LEVEL_II | CMS | YELLOW | Non-dental HCPCS Level II. CMS publishes this as a quarterly Public Use File, but M0 does not auto-promote a "Public Use File" label to GREEN — commercial distribution requires explicit review/validation of the exact files/terms first. | | HCPCS_LEVEL_II_CDT | American Dental Association | RED | Dental (D-prefixed) HCPCS Level II codes are ADA/CDT-governed, not CMS/non-dental HCPCS. Real bug found and fixed during M0: the deterministic code extractor's original HCPCS regex ([A-V]\d{4}) matched D-prefixed codes and would have silently mislabeled them non-dental HCPCS (YELLOW) instead of CDT (RED) — fixed in diffengine.py's _extract_codes() before this matrix was written, not after. | | ICD_10_CM | CDC/NCHS | YELLOW | CDC/NCHS distributes official files directly and CDC Stacks labels some official coding-guideline artifacts Public Domain, but M0 does not infer identical rights across every associated artifact (code files vs. guideline prose vs. ancillary maps) without separate confirmation per artifact. | | ICD_10_PCS | CMS | YELLOW | Not currently extracted by any adapter (M2 only implements the NCD vertical slice) — classified for completeness ahead of any future procedure-code-bearing source. | | MS_DRG | CMS | YELLOW | Requires a separate review of the exact CMS data files (identifiers, titles/descriptors, weights, tables, classification files, derived groupings) Sentinel intends to ingest/distribute — not inferred from CMS hosting alone. Not currently extracted by any adapter. | | REVENUE_CODE | American Hospital Association / NUBC | RED | UB-04/NUBC proprietary material. CMS's AHA license language states AHA-copyrighted UB-04 codes/descriptions may not be used in software/products/services/derivative works without AHA permission. Not treated as a generic "public medical code" bucket. | | MODIFIER | (originating system not tracked) | UNKNOWN | Documented gap, not solved speculatively: a modifier's rights depend on which terminology system it originated from (e.g. a CPT-sourced modifier is RED; a plain HCPCS-sourced one might be YELLOW), and extraction does not currently record that provenance. Rather than guess or default to permissive, modifiers fail closed as UNKNOWN. Fixing this properly requires extending extraction_schema.AffectedCode with a modifier_system field and updating the deterministic MODIFIER regex to attribute a source system — deliberately out of scope for M0 (a real future milestone, not a shortcut to take now). |
What's actually been extracted so far (Phase G audit, spec §42)
Queried production directly on 2026-08-20: all 46 ExtractedFact/ ChangeEvent rows in the live database have affected_codes = []. No structured code of any system — restricted or otherwise — has ever been extracted, stored, or distributed. No remediation was needed; this is the audit's finding, not an assumption.