The person’s own way into their record — appointments, medications, results, communication needs, proxy access and research transparency — with the two access controls that are demonstrated rather than enforcing named on the face of this document.
The patient portal is the person’s own way into their record and into the services around it. It’s separately authenticated — a portal session isn’t a staff session and carries none of a staff account’s reach — and it is jurisdiction-branded, so it wears the health system’s identity, its colours and its identifier label, with commvita™ named as the platform underneath instead of over the top.
Appointments can be booked against real slots, rescheduled and cancelled; a repeat prescription can be requested against a specific medication with a note; messages go to and from the practice; test results, the care plan and its open tasks are readable. An appointment request that has no bookable slot becomes a request instead of a dead end.
Alongside that sit preventive nudges — a vaccination due, a screening invitation, an annual review, a medication review. Each carries three answers, not one: book it, remind me later, or decline with a reason. The reason matters: a decline recorded with its reason is clinical information, and a decline recorded as silence is a person who looks like they were never asked.
The portal also carries a self-declared family history — “my mother had breast cancer” — which can open earlier screening. It is explicitly non-genomic, and that separation is deliberate: collapsing a family-history statement into genomic data would drag the heaviest consent regime on the platform onto a screening reminder, for no benefit to anyone.
Secondary use of health data is the thing patients are least often told about and most often surprised by. The portal names each study the person’s pseudonymised or anonymised data feeds into, with the organisation, the lead researcher, the approval reference, the data categories used, the anonymisation applied and the lawful basis — and it says, per study, whether opting out is possible at all, because for a fully anonymised dataset it often isn’t.
Where nothing is recorded for that person, the population transparency list is shown instead of an empty page — an empty page would imply no research is happening, which is a stronger claim than the absence of a row supports.
Saving the choice isn’t the same as acting on it, so we do both. When somebody objects, they’re taken out of research extracts before those extracts are produced — and the number of people left out is reported with the extract, so nobody mistakes a smaller cohort for a smaller population. What it does not do is on the screen too: it doesn’t affect your day-to-day care, it doesn’t withdraw you from a study you separately agreed to join, and it can’t recall data already shared.
This is one question in ordinary language and three different questions in a health record system, and conflating them is how a portal comes to claim transparency it doesn’t deliver.
Where the real access record lives. Every staff access to a record carries a legitimate relationship justification, anomalous patterns — out-of-area, bulk, cross-organisation — are flagged for investigation, and the log is append-only and hash-chained so it’s tamper-evident. A person can challenge a justification, and a per-person Article 15 view can be produced. All of that’s real. None of it’s currently a tab in the portal, and closing that gap is a wiring job, not a build.
The NHS App stays the national front door; commvita makes the room behind it deeper — same login, richer content, and the ability to act.
commvita authenticates with NHS Login (OIDC) — the same identity the NHS App uses — and integrates through the NHS App API (appointments, prescriptions, records, messages, notifications), so the person isn’t asked to learn a second account.
Where the national baseline mostly shows and notifies, commvita lets the person book from a nudge, request PIFU, submit PROMs and raise an urgent review — write-back and action, not just a view.
commvita carries a cross-setting record — GP, hospital, community, mental health, social care and pharmacy — so what the person sees isn’t only their GP record but their whole journey, with the source of each entry shown.
| Function | Endpoint | Status |
|---|---|---|
| Sign in, profile, care plan, medications, test results | /portal/auth, /me, /care-plan,
/medications, /test-results |
Live |
| Appointments — book against real slots, reschedule, cancel, request | /portal/appointments, /available-slots,
/appointment-request | Live |
| Messages and repeat prescription requests | /portal/messages, /repeat-request |
Live |
| Preventive nudges — book, defer, decline with reason | /portal/nudges + three actions |
Live |
| Communication needs and reasonable adjustments | /portal/comm-needs | Live |
| Self-declared family history (non-genomic) | /portal/family-history | Live |
| Vaccinations, read from the immunisation spine | /portal/vaccinations | Live |
| Research participation — transparency view | /portal/research |
Live |
| Per-study opt-out — persisted, anonymised studies refused with the reason | /portal/research/{id}/opt-out |
Live |
| Secondary-use objection — persisted and honoured in research extracts | /portal/data-choices |
Live |
| Portal activity log (the person’s own actions) | /portal/access-log | Live |
| Granted access list — held in memory, doesn’t gate staff access | /portal/record-access | Demonstrated |
| Who has read my record — shown to the person in the Data & Privacy tab, drawn from their own record | /portal/who-accessed-my-record | Live |
| Care feed for family and carers | /portal/care-feed |
Live |
| Rapid review — patient- or family-initiated escalation | /portal/rapid-review | Live |
| Patient transport request · firearms medical request | /portal/patient-transport/request, /firearms-request |
Live |
| Data portability export — the person’s own record; empty categories named | /portal/fhir-export | Live |
| Maternity and baby · specialist services · goals · linked accounts | — | Demonstrated |
Download a copy of your record. You get your own conditions, medications, vaccinations and test results, in a standard format other systems can read. If we hold nothing under a heading, the download says so and leaves it out — we never put an example in its place, because a made-up line in a medical record is worse than a gap.
The “who can see my record” list is a view, not a switch. It shows you who has access. Removing an entry takes it off your list; it doesn’t change what a member of staff can open, which is set by their role and their organisation. We say that plainly instead of offer a button that looks like it does more than it does. Making it a real control is planned and is not built yet.
What the portal isn’t. It isn’t a clinical decision-support tool and carries no medical-device claim. It doesn’t diagnose, triage or advise. A nudge is an invitation, not an instruction, and every clinical action it can start — a booking, a repeat request, a rapid review — lands on a human being.