| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| image-sbom.cdx.json | 2026-09-15 | 1.4 MB | |
| image-sbom.cdx.json.sha256 | 2026-09-15 | 86 Bytes | |
| openmed-image-sbom_f93836209f1ace6b99b50e765dbf2881959401a9.cyclonedx.json | 2026-09-15 | 1.4 MB | |
| openmed-2.5.0-py3-none-any.whl.sigstore.json | 2026-09-15 | 11.2 kB | |
| openmed-2.5.0.tar.gz.sigstore.json | 2026-09-15 | 11.2 kB | |
| python-distributions.intoto.json | 2026-09-15 | 11.0 kB | |
| release-artifact-digests.txt | 2026-09-15 | 184 Bytes | |
| release-source.json | 2026-09-15 | 194 Bytes | |
| sbom.cdx.json | 2026-09-15 | 8.9 kB | |
| OpenMed v2.5.0 source code.tar.gz | 2026-09-15 | 41.0 MB | |
| OpenMed v2.5.0 source code.zip | 2026-09-15 | 43.2 MB | |
| README.md | 2026-09-15 | 21.6 kB | |
| Totals: 12 Items | 87.1 MB | 1 | |
OpenMed 2.5: Clinical Context. Local Control.
OpenMed 2.5 brings clinical privacy and extraction previews, richer FHIR and OMOP exports, safer document intake, and new privacy-policy and audit tools to the Python SDK. It preserves the v2.3 family-based model-registry API while adding an explicit API for managing separate model tiers and formats.
This release covers changes since v2.3.0. Python 3.10+ remains supported, and the core dependency set is unchanged.
Clinical text and privacy
- Clinical-preserving de-identification, in preview.
ClinicalPrivacyProcessorcombines explicit language, category, and role controls with document-level review status. Theclinical_preserveprofile targets identifiers while retaining clinical context such as diagnoses, medications, doses, and measurements. Full-document ONNX batching preserves source offsets and input order, with bounded cancellation and per-document outcomes. - More structured clinical evidence. Context, medication instructions, quantities, measurements, relations, and temporal analysis retain links to the original text. Ambiguous or incomplete quantities are withheld. German clinical-context, date, address, and term-preservation handling gains additional regression coverage.
- Persian language-pack support. The
fapack adds Persian patterns, Eastern-digit normalization, Jalali date handling, and Iranian national-ID surrogate support. Persian is also available in the REST language enum. Its default model route remains a compatibility placeholder; this release does not supply newly qualified dedicated Persian weights. - Consistent locale handling. Structural language-tag normalization and stricter alias validation make language and locale selection more explicit.
Clinical-preserving processing is opt-in and remains a preview. No language/model route is clinically qualified by default; applications must establish qualification for their intended data, language, policy, and runtime.
FHIR, OMOP, and terminology
- A consistent FHIR export entry point. The grounded-span
to_fhir()facade dispatches supported entities to Condition, Observation, MedicationStatement, and Procedure resources, assembles deterministic Bundles, and reports unmapped labels. A conservative DiagnosticReport exporter adds explicit status handling and reference normalization. - More export validation. Dependency-free base FHIR R4 structural checks and US Core 9.0.0 checks cover supported resources. Additional validators check reference targets, profile declarations, and Observation extensions. FHIR R5 Bundle comparison reports structural round-trip differences.
- Expanded OMOP CDM 5.4 coverage. Exporters add
measurement,procedure_occurrence,visit_occurrence,observation_period, andnote_nlprows, preserving supported numeric values, units, dates, and source offsets. Cohort validation checks keys, relationships, vocabulary references, and note provenance. - Explicit terminology sources. ValueSet expansion works with caller-loaded vocabulary snapshots or an explicitly configured terminology endpoint. A local terminology cache records versioned provenance and rejects stale-release reuse. Restricted terminology requires caller-supplied access and permissions.
Synthetic FHIR/OMOP conformance coverage includes the official HL7 R4 validator, a malformed-resource negative control, and OMOP column, key, and reference checks. The Java validator and restricted vocabulary content are not bundled.
Document and multimodal intake
preflight_asset brings manifest, media-type, profile, resource-limit, and digest checks into one ordered accept-or-abstain report. An unevaluable check is reported as an abstention rather than a successful validation.
- Bounded BMP, GIF, and WebP header inspection extends image preflight coverage. WAV handling gains additional envelope and RF64 refusal checks.
MOBILE_V1andDESKTOP_V1profiles bound bytes, dimensions, pages, frames, and duration before decoding. Batch summaries detect duplicate identifiers and digests and validate aggregate limits.- Memory-streamed Tesseract OCR and PDF/PNG export improvements add source-line, reading-order, and redaction-fidelity checks. OCR still requires a caller-installed Tesseract runtime.
- ONNX inference validates label metadata before optional runtime imports and adds tensor batching and execution limits.
Privacy policies, structured data, and audit
New local tools make privacy decisions and their supporting evidence easier to inspect:
- Policy controls: versioned policy schemas, composition and migration checks, minimum-necessary field selection, and field-level FHIR/OMOP de-identification with patient-consistent date shifting.
- Structured-data checks: tabular re-identification risk and schema-drift reports, surrogate-map integrity checks, and nested-redaction idempotence checks.
- Audit evidence: structured access reviews, evidence-bundle integrity and replay verification, key-custody and rotation metadata, and bounded exception and retention reports.
- Artifact protection: authenticated encryption for reversible surrogate mappings with caller-owned keys, local deletion planning and verification, dataset-upload guards, privacy scanning for Git/CI workflows, and completed session-trace scrubbing.
These reporting APIs use bounded metadata, counts, offsets, hashes, and provenance instead of retaining protected source values. Deletion, upload, trace cleanup, and other external effects remain explicit operations.
The optional Snowpark adapter adds caller-managed warehouse de-identification. The separate privacy-proxy application requires an injected transport, keeps mappings scoped to each request, and supports placeholder restoration across streaming responses.
Agent and training workflows
Agent integrations gain strict provider-result and run-summary schemas, opaque correlation identifiers, typed governance identifiers, and artifact references with digest and size metadata.
Federated-training helpers add scheduling windows, round-status summaries, validated update metadata, and aggregate metrics with clipping declarations and minimum-group suppression. Retraining tools rank aggregate evidence, score trigger signals, and prepare recipe proposals. Compute, cost, energy, and carbon accounting adds explicit budget reports.
These additions provide orchestration and evidence contracts. They do not automatically train, deploy, or qualify a model.
Compatibility and fixes
Existing v2.3 registry callers keep their family-based API. RegistryService, family CLI selectors, unambiguous model aliases, and caller-owned schema-v1 files remain supported. An SDK upgrade does not require migrating those files.
Applications that need separate channels for model tiers or formats can opt into SlotRegistryService and schema-v2 slots keyed by family::tier::format. Stored slot versions are independent of version-like tokens in model repository names. The compatibility adapter retains existing schema-v2 files and refuses ambiguous multi-slot family operations without writing.
The static Python API comparison against v2.3.0 reports zero removed symbols, zero narrowed signatures, and zero new deprecations. The REST API retains its existing paths and component schemas, with Persian added to the language enum.
Other fixes include compatible Swift dependency resolution, stricter ONNX metadata validation, request-scoped privacy-proxy restoration, Windows artifact-deletion identity checks, and refreshed documentation and container dependencies.
The clinical, governance, and orchestration additions described above are Python capabilities. Matching npm, Swift, and Android version numbers do not imply that every new Python API is implemented on those platforms.
Upgrade
Use these coordinates once the v2.5.0 packages and tag are published:
:::bash
# Python SDK
pip install --upgrade "openmed==2.5.0"
# Optional Hugging Face and FHIR integrations
pip install --upgrade "openmed[hf,fhir]==2.5.0"
# JavaScript package
npm install openmed@2.5.0
Swift Package Manager:
:::swift
.package(url: "https://github.com/maziyarpanahi/openmed.git", from: "2.5.0")
Android through JitPack:
:::kotlin
implementation("com.github.maziyarpanahi:openmed:v2.5.0")
Container:
:::bash
docker pull ghcr.io/maziyarpanahi/openmed:v2.5.0
For Helm deployments, select the release image with image.tag=v2.5.0. Review the migration guide before adopting slot registries, new serialized schemas, or the clinical-preserving preview.
Use and qualification
OpenMed is assistive software. Clinical outputs require qualified review and must not automatically determine diagnosis, treatment, or billing. Structural validation and synthetic regression tests do not establish clinical efficacy, deployment-specific privacy performance, or regulatory compliance.
Before deployment, evaluate identifier recall, critical leakage, source-span integrity, clinical-text preservation, date handling, and surrogate consistency on the intended languages and runtimes. Model artifacts and their existing release targets are unchanged by this SDK release.
Release links
Versioned links become available with the v2.5.0 tag:
- Migration guide
- Release documentation
- [Full changelog][full-changelog]
What's Changed
- chore: prepare OpenMed v2.3.0 by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3018
- feat(multimodal): add bounded WAV metadata reader by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3021
- feat(multimodal): add bounded WAV metadata reader by @alberthammerich in https://github.com/maziyarpanahi/openmed/pull/3020
- feat: integrate remaining reviewed OpenMed changes by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3030
- feat(clinical): add conservative FHIR DiagnosticReport exporter by @mohamedhossammohamed in https://github.com/maziyarpanahi/openmed/pull/2989
- feat(training): validate federated round scheduling windows by @alberthammerich in https://github.com/maziyarpanahi/openmed/pull/2992
- feat(clinical): add deterministic citation ordering by @alberthammerich in https://github.com/maziyarpanahi/openmed/pull/2993
- feat(multimodal): add privacy-safe asset batches by @krudo-taco in https://github.com/maziyarpanahi/openmed/pull/3016
- feat(multimodal): add content-free cache keys by @alberthammerich in https://github.com/maziyarpanahi/openmed/pull/3017
- feat(multimodal): implemented PHI-safe processing summaries by @AaronProbha18 in https://github.com/maziyarpanahi/openmed/pull/3019
- feat(multimodal): implement PHI-safe processing summaries by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3022
- feat(multimodal): add privacy-safe asset batches by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3024
- feat: add Persian PII language pack by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3025
- feat(clinical): add deterministic citation ordering by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3026
- feat(agent): add opaque correlation identifiers by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3027
- feat(clinical): add conservative FHIR DiagnosticReport exporter by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3028
- feat(training): add federated round status and scheduling by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3029
- feat(agent): add opaque correlation identifiers by @libaojiang in https://github.com/maziyarpanahi/openmed/pull/2990
- feat(training): render privacy-safe federated round status by @alberthammerich in https://github.com/maziyarpanahi/openmed/pull/2991
- feat: add Persian PII language pack by @janithcd in https://github.com/maziyarpanahi/openmed/pull/3014
- feat(multimodal): add content-free cache keys by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3023
- feat: validate federated update metadata by @janithcd in https://github.com/maziyarpanahi/openmed/pull/3034
- feat: add FHIR R4 structural validation by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3033
- feat: add US Core conformance checks by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3058
- feat: add OMOP measurement and procedure exporters by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3059
- feat: add OMOP supporting table exporters by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3060
- feat: add privacy-safe federated metrics by @be-student in https://github.com/maziyarpanahi/openmed/pull/3035
- feat(agent): add content-free artifact references by @KevinAndrewDong in https://github.com/maziyarpanahi/openmed/pull/3032
- feat: add offline catalog coherence regeneration by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3061
- feat(eval): rank PHI-free retraining slices by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3065
- feat(eval): add aggregate retraining trigger scorer by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3066
- feat(release): dispatch retraining recipe proposals by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3068
- feat(risk): mitigate longitudinal linkage by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3069
- refactor: rekey model-registry state to slot-keyed schema v2 with assigned SemVer by @DrVelvetFog in https://github.com/maziyarpanahi/openmed/pull/2556
- Add a model-registry rollback compatibility report by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2553
- Complete local privacy-proxy service boundary by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3070
- Add a no-PHI exception taxonomy validator by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2546
- Add field-level de-identification policies for OMOP and FHIR by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2187
- Add a reusable CI privacy-scan action by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2322
- Add a structured redaction contract for nested resources by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2460
- Track release compute cost and carbon budgets by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2200
- Block unsafe dataset uploads with a local privacy guard by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2316
- Generate a counts-only trace privacy audit artifact by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2326
- Add offline dependency inventory, SBOM, and advisory evidence by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3124
- Add an audit-artifact retention scrubber by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2448
- Encrypt reversible surrogate mappings at rest by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2308
- Add a minimum-necessary structured field selector by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2458
- Add audit-report signing key rotation support by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2438
- Add a privacy budget ledger for aggregate releases by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2457
- Add a session-end trace scrubbing hook by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2321
- Add a pre-push privacy scanner for repository fixtures by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2324
- Add a tabular re-identification risk report by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2456
- Add a no-PHI telemetry exporter by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2459
- Add local deletion planning and verification by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3125
- Validate OMOP cohort exports and FHIR round-trip fidelity by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3127
- Add structured access reviews and privacy policy governance by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3128
- Add conservative FHIR structural validators by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3126
- Add bounded privacy release validation and integrity checks by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3129
- Add versioned privacy policies and migration review gates by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3130
- Add a provenance-aware terminology cache by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2474
- Add warehouse Python de-identification UDF by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2496
- Add surrogate key-provider and custody validation by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3131
- Add audit-access scope and review-expiry checks by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3132
- Add bounded audit-report validation by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3133
- Add audit evidence replay, lineage, and freshness checks by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3134
- Add policy simulation and coverage verification by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3135
- Add a differential-privacy budget migration verifier by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2547
- Add reproducible release provenance verification by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2552
- Add a privacy release-gate aggregator by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2579
- Add a privacy exception budget gate by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2614
- Add an audit-envelope parser with redacted payload metadata by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2622
- Add a structured privacy waiver lifecycle ledger by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/2656
- feat: add canonical FHIR export facade by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3031
- feat: add ValueSet and ECL expansion by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3036
- feat: complete grounding export round-trip validation by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3037
- feat(multimodal): add privacy-safe multimodal preflight report by @DrVelvetFog in https://github.com/maziyarpanahi/openmed/pull/3073
- feat: add strict run summary schema parsing by @LobsterQBA in https://github.com/maziyarpanahi/openmed/pull/3074
- feat: validate multimodal provider result envelopes by @janithcd in https://github.com/maziyarpanahi/openmed/pull/3076
- feat(agent): add canonical governance identifiers by @takagibit18 in https://github.com/maziyarpanahi/openmed/pull/3079
- Add bounded BMP header dimension preflight by @Bembaby in https://github.com/maziyarpanahi/openmed/pull/3136
- Add bounded GIF header dimension preflight by @Bembaby in https://github.com/maziyarpanahi/openmed/pull/3137
- Add bounded WebP header dimension preflight by @Bembaby in https://github.com/maziyarpanahi/openmed/pull/3139
- Add RF64 rejection fixtures for WAV metadata by @Bembaby in https://github.com/maziyarpanahi/openmed/pull/3138
- Add structural locale tag normalization by @Bembaby in https://github.com/maziyarpanahi/openmed/pull/3140
- feat(multimodal): add pre-decode limit profiles for multimodal assets by @DrVelvetFog in https://github.com/maziyarpanahi/openmed/pull/3072
- fix: refresh release and security baselines by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3142
- Add clinical-preserving privacy processing and ONNX batching by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3075
- fix: validate ONNX labels before runtime imports by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3147
- v2.5.0 by @maziyarpanahi in https://github.com/maziyarpanahi/openmed/pull/3221
New Contributors
- @AaronProbha18 made their first contribution in https://github.com/maziyarpanahi/openmed/pull/3019
- @libaojiang made their first contribution in https://github.com/maziyarpanahi/openmed/pull/2990
- @be-student made their first contribution in https://github.com/maziyarpanahi/openmed/pull/3035
- @KevinAndrewDong made their first contribution in https://github.com/maziyarpanahi/openmed/pull/3032
- @LobsterQBA made their first contribution in https://github.com/maziyarpanahi/openmed/pull/3074
- @takagibit18 made their first contribution in https://github.com/maziyarpanahi/openmed/pull/3079
- @Bembaby made their first contribution in https://github.com/maziyarpanahi/openmed/pull/3136
Full Changelog: https://github.com/maziyarpanahi/openmed/compare/v2.3.0...v2.5.0