How one platform serves a single organisation, then a region, then a country, without copying data to the middle and without switching off the systems you already run. What it means in practice, and what runs today.
Can I use this in my own organisation, keep the systems I already run, and later use the same thing across a region and then nationally? Yes, and the way it’s built is what makes the yes honest. You start on your own estate with your own systems feeding it. When you join a region, your record stays yours and only answers move. When a national body needs the picture, your instance feeds it in the national shape. Nothing is copied to the middle, and nothing you run today is switched off to begin.
The rest of this page walks through those three steps, then says which parts run today and which are demonstrated on seeded data. It is the second question every buyer should ask, and it’s answered at the end without hedging.
A practice, a community provider, a trust or a council runs its own copy of commvita on its own kit, and is the data controller for it. The systems already in place carry on. They feed the record instead of being replaced by it.
Your patient administration system sends admissions, transfers and discharges through the connector layer. The GP record is requested from the practice’s own system when it’s needed. Messages and referrals arrive on the wire formats the NHS already uses. The shared record says on its face that the contributing systems remain the systems of record.
A whole-person record that all of those feeds land on, with governance, flow and reporting on the same platform. Staff stop re-keying between screens. Managers see numbers that update as care happens. The Flow Edition starts at £1 an instance and carries the platform base without the clinical record, so you can begin with flow and governance and add the record when you choose.
The record is shaped to published, open models, so you can leave with it. Every user’s reach is worked out at sign-in from your own organisation structure. Where your country’s rules haven’t been entered, the platform switches that capability off and says why, instead of borrowing another country’s.
England’s health and care system is thousands of separate legal entities, and that separation is where accountability lives. Any plan to join them up has to survive contact with that fact.
There are two ways to join up organisations’ data. You can copy everything to a central store, or you can leave each organisation in charge of its own record and send the question to where the data already lives. The first creates a new controller holding everyone else’s liability, a new target, and a copy that’s out of date the moment it lands. The second moves only the answer. commvita is built the second way, and the diagram below is the whole argument.
The practical test to put to any supplier, including us: when a query runs, how many rows leave the organisation that holds them? Here the answer is none. A cohort question is executed at each site and returns a count, with anything under five suppressed so a small group can’t be narrowed to a person.
A region is many organisations and one shared view. Four things have to work for that to be real, and each can be adopted without the others.
A master patient index resolves one person across organisations and identifier schemes without creating a merged record that somebody then has to own. A record locator points at where a document lives instead of copying it.
The regional record is assembled from contributing systems, and care homes and community providers contribute and read through the same contract as an acute trust.
A feasibility question runs at every site and returns an aggregate. This is what makes multi-site research and population analysis possible without a transfer.
Sharing agreements with signatories and review dates, a Caldicott queue for anything that isn’t direct care, notification when a non-controller reads, and an access log that can’t be edited afterwards.
The thing a region most needs to get right is who may open which record. On this platform that decision follows the recorded care relationship and never the organisation chart. Commissioning a service is not a reason to read the records it creates. The region screen below reports the decision the platform has already made, relation by relation.
A national body doesn’t need your record. It needs the picture, in the shape it has published. commvita pins the national canonical data model and produces extracts in it, so a local instance feeds the national platform instead of competing with it.
The things that change between a county and a country are held as data instead of code. The jurisdiction profile carries the country’s identifiers, terminology editions, data-protection rules and reporting duties as signed, dated entries, and refuses to run a capability whose entry is missing. The organisation spine holds the structure from the department down to a physical site as effective-dated configuration, so when the map is redrawn, and it will be, the change is a data entry with a date and not a rebuild.
What lets one platform sit at all three levels is that it holds meaning, movement and behaviour in one place. A person, an organisation or a referral means the same thing in a ward, a regional team and a national extract. What happened is recorded as events that can’t be edited later, so a count at one level is the same fact at the next. And the rule about who may see what runs on the server everywhere, so the answer doesn’t change with who is asking. The architecture explainer says what is built in each of those today; the Flow Edition and the FDP compares the product set with the national data platform’s.
Every claim above is listed here against the screen it lives on and whether it’s live or demonstrated on seeded data.
| What it does | Where it lives | Status |
|---|---|---|
| Resolve one person across organisations | /empi | ● Live |
| Point at a record without copying it | /nrl-connector | ○ Demonstrated |
| Shared cross-organisation record | /single-patient-record · /nhr | ● Live |
| Care homes contribute and read | /care-homes-shared-record | ○ Demonstrated |
| Who may see this record, by relation | /federation | ● Live |
| Aggregate-only feasibility, counts under five suppressed | /cohort-discovery · /federated-query | ○ Demonstrated |
| Sharing agreements, Caldicott queue, access log | /dspa-manager · /ig-spine · /legitimate-access-log | ● Live |
| Reach resolved at sign-in | /rbac-matrix | ● Live |
| Organisational map as dated configuration | /org-spine · /jurisdiction-profile | ● Live |
| Standards on the wire | /connector-dashboard · /epr-hub · /ihe-profiles | ● Live register, simulated liveness |
| Extract in the national canonical model | /fdp-cdm | ● Live |