Provenx PROVENANCE CHAIN
ModalityOK CT
ManufacturerOK GE MEDICAL SYSTEMS
ModelOK RHAPSODE
InstitutionOK JFK IMAGING CENTER
StationOK CT01_OC0
Study DateOK 20040826
Acquisition DateOK 19970430
Body PartMISSING [MISSING]
Magnetic FieldMISSING [MISSING]
Slice ThicknessOK 5.000000
RowsMISSING [MISSING]
ColumnsMISSING [MISSING]
GOVERNED FORENSIC REPORT
# OSHI-5 VESTIGE — FORENSIC IMAGING PROVENANCE REPORT
**Classification:** Chain of Custody Authentication
**Report Type:** DICOM Metadata Governance Analysis
**Governing Protocol:** USPTO 19/571,156
**System:** Oshi-5 VESTIGE Forensic Imaging Module
**Report Generated:** Session Runtime
**Instance Reference:** SOP `1.3.6.1.4.1.5962.1.1.1.1.2.20040826185059.5457`
---
> ⚠️ **GOVERNANCE SCOPE DECLARATION**
> This report authenticates documentation provenance and flags metadata integrity gaps only. Oshi-5 VESTIGE does **not** render clinical diagnoses, interpret anatomical findings, or provide medical opinions. All findings below are documentation and chain of custody determinations exclusively.
---
## SECTION 1 — CHAIN OF CUSTODY ASSESSMENT
| Attribute | Value |
|---|---|
| **Overall CoC Score** | **82% — MODERATE** |
| **Authentication Status** | ⚠️ CONDITIONAL — Cannot fully authenticate |
| **Modality Confirmed** | CT (SOP Class `1.2.840.10008.5.1.4.1.1.2` — CT Image Storage ✓) |
| **Institution on Record** | JFK IMAGING CENTER |
| **Acquiring Device** | GE MEDICAL SYSTEMS / RHAPSODE / Station `CT01_OC0` |
| **Software Version** | 05 |
| **Transfer Syntax** | `1.2.840.10008.1.2.4.90` — JPEG 2000 Lossless |
| **Instance Number** | 2 |
| **Slice Thickness** | 5.0 mm |
| **Pixel Spacing** | 0.661468 × 0.661468 mm |
### CoC Integrity Tier: **YELLOW-RED COMPOSITE**
The file presents sufficient hardware provenance (manufacturer, model, station, institution) to establish partial custody origin. However, critical custodial chain links — referring physician, operator identity, and performing physician — are absent, and a **significant temporal anomaly** is present that prevents unconditional provenance authentication. The file **cannot be certified as unmodified** under current documentation state.
---
## SECTION 2 — PROVENANCE AUTHENTICATION STATUS
### 2A. Verified Provenance Elements ✅
| Provenance Element | Status | Notes |
|---|---|---|
| Study Instance UID | ✅ PRESENT | Structurally well-formed |
| Series Instance UID | ✅ PRESENT | Consistent UID root with study |
| SOP Instance UID | ✅ PRESENT | Consistent UID root family |
| SOP Class UID | ✅ PRESENT | Valid CT Image Storage class |
| Manufacturer | ✅ PRESENT | GE MEDICAL SYSTEMS |
| Device Model | ✅ PRESENT | RHAPSODE |
| Station Name | ✅ PRESENT | CT01_OC0 |
| Institution Name | ✅ PRESENT | JFK IMAGING CENTER |
| Patient Identity | ✅ PRESENT (masked) | PatientID and Name present |
| Patient Sex | ✅ PRESENT | Recorded as "O" |
### 2B. Authentication Gaps — Provenance Incomplete ❌
| Missing Element | Custodial Impact |
|---|---|
| Patient DOB | Identity corroboration weakened |
| Accession Number | Cannot link to ordering workflow / RIS record |
| Referring Physician | Order origination unverifiable |
| Performing Physician | Examination responsibility unverifiable |
| Operator Name | Technologist custody link broken |
| Series Description | Series intent undocumented |
| Body Part | Anatomical scope undocumented |
| Institution Address | Facility location unverifiable |
| Rows / Columns | Image matrix dimensions unrecorded in metadata |
| Bits Allocated | Field contains non-standard Unicode character `\u0010` — **value is suspect** |
### 2C. Bits Allocated Field — Anomaly Flag 🔴
The `bitsAllocated` field contains `\u0010` (Unicode control character — Data Link Escape). For CT Image Storage, the expected standard value is `16` (16-bit allocation). The presence of a raw control character in this numeric field indicates a **possible encoding error, file corruption, or non-standard write process** at this tag. This tag must be resolved prior to any institutional acceptance workflow.
---
## SECTION 3 — NSI FINDINGS (NULL/SUSPECT IDENTIFIER ANALYSIS)
**NSI Module Status:** Active
**Missing Tags Detected:** 10 of assessed fields
**Critical Custodial Tags Missing:** 3
---
### NSI-001 🟡 YELLOW — Referring Physician (Tag 0008,0090)
> **Finding:** Field is MISSING.
>
> **Custodial Impact:** The referring physician tag establishes the originating clinical custody link — i.e., who authorized this imaging study and from which clinical context the order originated. Without this field, the document chain cannot be traced back to an ordering provider, and RIS/order correlation is impossible.
>
> **Authentication Consequence:** Partial. Provenance from acquisition device forward is traceable, but upstream custodial origin (order provenance) is broken.
>
> **Recommended Action:** Retrieve from originating RIS/EMR system and supplement metadata through documented amendment process with audit trail.
---
### NSI-002 🟡 YELLOW — Operator Name (Tag 0008,1070)
> **Finding:** Field is MISSING.
>
> **Custodial Impact:** The operator name (technologist) represents the human custodian present at point of acquisition. This is a critical link in physical chain of custody — establishing who operated the device, positioned the subject, and initiated the scan.
>
> **Authentication Consequence:** Device-level provenance is established (station, manufacturer), but the human operator link is absent. In legal or regulatory review contexts, this gap may be cited as a custodial deficiency.
>
> **Recommended Action:** Retrieve from acquisition log or site staffing records for the recorded acquisition datetime. Supplement via governed amendment with source documentation.
---
### NSI-003 🟡 YELLOW — Performing Physician (Tag 0008,1050)
> **Finding:** Field is MISSING.
>
> **Custodial Impact:** Establishes which physician supervised or performed the study. Absence weakens the human-accountability chain at the point of imaging.
>
> **Recommended Action:** Retrieve from departmental records corresponding to study date and supplement with audit documentation.
---
### NSI-004 ⚪ INFORMATIONAL — Accession Number (Tag 0008,0050)
> **Finding:** Field is MISSING.
>
> **Custodial Impact:** Accession number is the primary RIS linkage key. Without it, this DICOM object cannot be formally cross-referenced against an institutional ordering record, workflow history, or billing audit trail.
>
> **Recommended Action:** Attempt retrieval from RIS archive using Study Instance UID as lookup key.
---
### NSI-005 ⚪ INFORMATIONAL — Series Description / Body Part (Tags 0008,103E / 0018,0015)
> **Finding:** Both fields MISSING.
>
> **Custodial Impact:** Absence does not break chain of custody directly but reduces document completeness and impedes archival classification integrity.
>
> **Recommended Action:** Populate from acquisition log or protocol records if available.
---
## SECTION 4 — DRI TEMPORAL INTEGRITY ANALYSIS
**DRI Module Status:** Active
**Temporal Anomaly Detected:** YES
**Severity:** 🔴 RED
---
### DRI-001 🔴 RED — Multi-Date Temporal Inconsistency
> **Finding:** CRITICAL TEMPORAL INCONSISTENCY DETECTED
**Dates Present in Metadata:**
| DICOM Tag | Field Name | Value Recorded |
|---|---|---|
| 0008,0020 | Study Date | **20040826** (August 26, 2004) |
| 0008,0030 | Study Time | 18:50:59 |
| 0020,000D | Study Instance UID (embedded date) | **20040826185059** ✓ (consistent with Study Date) |
| 0008,0021 | Series Date | **19970430** (April 30, 1997) |
| 0008,0022 | Acquisition Date | **19970430** (April 30, 1997) |
| 0008,0023 | Content Date | **19970430** (April 30, 1997) |
| 0008,0032 | Acquisition Time | 11:29:36 |
| 0008,0033 | Content Time | 11:30:08 |
---
**Temporal Discrepancy Summary:**
```
STUDY DATE: 2004-08-26 ──────────────────────────┐
│
SERIES DATE: 1997-04-30 ──────────────────────────┤ DELTA: ~7 YEARS, 4 MONTHS
ACQUISITION DATE: 1997-04-30 ──────────────────────────┤
CONTENT DATE: 1997-04-30 ──────────────────────────┘
```
**A delta of approximately 2,676 days (≈7.3 years) exists between the Study Date and the Series/Acquisition/Content dates.**
---
### DRI Temporal Analysis — Possible Explanations
The following scenarios are documented for investigative purposes. DRI does not determine which scenario applies — that determination requires institutional review:
| Scenario | Description | CoC Implication |
|---|---|---|
| **A — Retrospective Digitization** | Original film study from 1997 was digitized/imported into DICOM format in 2004. The Study Date reflects the import event; Series/Acquisition/Content dates reflect original acquisition. | Potentially legitimate — requires digitization workflow documentation to verify |
| **B — Post-Acquisition File Modification** | The DICOM file was modified after original creation, altering the Study Date while leaving Series/Acquisition/Content dates unchanged (or vice versa). | Chain of custody compromise — file may not represent unaltered original |
| **C — System Clock Error at Acquisition** | Device system clock was misconfigured at time of original acquisition, producing erroneous dates. | Possible but does not explain a 7+ year gap through standard clock drift |
| **D — Dataset Assembly Error** | Study wrapper metadata was applied from a different study or template, creating a date collision. | Administrative error — requires source verification |
**Scenario A (retrospective digitization) is the most operationally plausible given the 7-year gap**, but it **cannot be assumed** without corroborating documentation. Scenarios B and D represent custodial integrity risks that must be formally ruled out before this file can be accepted as unmodified.
---
### DRI-002 🟡 YELLOW — Study Description Anomaly
> **Finding:** Study Description field contains `"e+1"` — this is an atypical, non-descriptive value that does not conform to standard protocol description conventions.
>
> **Custodial Impact:** May indicate a data entry error, truncated field, or test/demo dataset.
>
> **Recommended Action:** Cross-reference against original acquisition protocol records. If this is a known test or reference dataset (e.g., NEMA phantom data), document that context explicitly in custody records.
---
### DRI-003 🟡 YELLOW — UID Root Analysis
> **Finding:** All UIDs share the root `1.3.6.1.4.1.5962.*` — this OID root is **associated with NEMA/Pixelmed test DICOM datasets** used for software development and standards validation purposes.
>
> **Custodial Impact:** If this file originates from a test/reference dataset library, it should be explicitly flagged as such and excluded from production clinical archives. Mixing test datasets with clinical DICOM archives is a data governance risk.
>
> **Authentication Consequence:** This does not necessarily indicate fraud or modification, but it **does affect provenance classification**. The file may be a publicly distributed DICOM test object rather than a clinical production file.
>
> **Recommended Action:** Verify dataset origin. If confirmed as a reference/test dataset, classify and tag accordingly in the archive management system.
---
## SECTION 5 — RECOMMENDATIONS FOR FORENSIC COMPLETENESS
**Priority Tier System:**
- 🔴 **P1 — Immediate** (blocks authentication)
- 🟡 **P2 — Required** (required for full CoC certification)
- ⚪ **P3 — Recommended** (improves completeness)
---
### 🔴 P1 — Resolve Temporal Inconsistency (DRI-001)
Obtain documentary evidence to explain the 2004 / 1997 date split. Required documentation may include:
- Digitization workflow records (if Scenario A)
- Import manifest or legacy migration logs
- Original film acquisition records from 1997 (if applicable)
- Device calibration / clock logs from acquisition station
**Until resolved:** This file should be flagged as **PROVISIONALLY AUTHENTICATED ONLY** and should not be treated as a verified unmodified DICOM object.
---
### 🔴 P1 — Investigate and Correct Bits Allocated Field
The `bitsAllocated` field must be resolved. A control character is not a valid numeric DICOM value. Determine whether this represents:
- A file encoding error
- Corruption at write time
- A non-standard DICOM writer behavior from the source system
Correction must be performed with full audit trail documentation.
---
### 🔴 P1 — Confirm Dataset Classification (Test vs. Clinical)
Given the NEMA-associated UID root (`1.3.6.1.4.1.5962.*`) and the atypical study description (`"e+1"`), formally determine whether this file is:
- A **clinical production file** — requires full missing-field remediation
- A **test / reference dataset** — requires explicit classification tagging and segregation from clinical archives
---
### 🟡 P2 — Supplement Missing Custodial Identity Fields
Through documented amendment process with source traceability, populate:
- Referring Physician (Tag 0008,0090)
- Performing Physician (Tag 0008,1050)
- Operator Name (Tag 0008,1070)
- Accession Number (Tag 0008,0050)
- Patient DOB (Tag 0010,0030)
- Institution Address (Tag 0008,0081)
All amendments must be recorded with: amendment date, amending party identity, source documentation reference, and reason for original absence.
---
### 🟡 P2 — Populate Structural Completeness Fields
- Rows (Tag 0028,0010)
- Columns (Tag 0028,0011)
- Series Description (Tag 0008,103E)
- Body Part Examined (Tag 0018,0015)
---
### ⚪ P3 — Implement UID Provenance Registry Check
Cross-reference Study/Series/SOP Instance UIDs against institutional UID registry to confirm no duplicate UID collision exists with other studies in the archive. Duplicate UIDs represent a data integrity risk in DICOM archive systems.
---
### ⚪ P3 — Document Chain of Custody Transfer Events
If this file was received from an external source (e.g., referral, CD import, digitization vendor), a formal custody transfer log should be created documenting:
- Source entity
- Transfer method
- Received-by identity
- Integrity verification method used at receipt (e.g., hash comparison)
---
## SECTION 6 — AUTHENTICATION SUMMARY
| Domain | Status | Score |
|---|---|---|
| Device / Hardware Provenance | ✅ AUTHENTICATED | High |
| Institutional Identification | ✅ AUTHENTICATED | High |
| UID Structural Integrity | ✅ STRUCTURALLY VALID | High |
| Human Custodial Chain | ⚠️ INCOMPLETE | Low |
| Temporal Integrity | 🔴 ANOMALY PRESENT | Critical |
| Field Completeness | ⚠️ PARTIAL | Moderate |
| Dataset Classification | ⚠️ UNCONFIRMED | Requires Action |
| **Overall CoC Score** | ⚠️ **82% — MODERATE** | **CONDITIONAL** |
---
### Final Authentication Determination:
> ## ⚠️ PROVISIONALLY AUTHENTICATED — CONDITIONAL
>
> **This DICOM file demonstrates sufficient hardware and institutional provenance for partial authentication but cannot be certified as a complete, unmodified chain-of-custody document in its current state.**
>
> **Certification is blocked by:**
> 1