commvita
Connected care platform
Architecture

Use it locally, keep what you have, grow to national

How one platform serves a single organisation, then a region, then a country, without copying data to the middle and without switching off the systems you already run. What it means in practice, and what runs today.

Live vs demonstrated: Live — real, API-backed platform logic (wired end-to-end today) Demonstrated — representative control surface with seeded data / illustrative UI mock-up
© 2026 Commvita Digital Health Solutions Ltd. All rights reserved.

1 The question, answered plainly

Can I use this in my own organisation, keep the systems I already run, and later use the same thing across a region and then nationally? Yes, and the way it’s built is what makes the yes honest. You start on your own estate with your own systems feeding it. When you join a region, your record stays yours and only answers move. When a national body needs the picture, your instance feeds it in the national shape. Nothing is copied to the middle, and nothing you run today is switched off to begin.

The rest of this page walks through those three steps, then says which parts run today and which are demonstrated on seeded data. It is the second question every buyer should ask, and it’s answered at the end without hedging.

2 Start where you are, and keep what you have

A practice, a community provider, a trust or a council runs its own copy of commvita on its own kit, and is the data controller for it. The systems already in place carry on. They feed the record instead of being replaced by it.

What you keep

Your existing systems

Your patient administration system sends admissions, transfers and discharges through the connector layer. The GP record is requested from the practice’s own system when it’s needed. Messages and referrals arrive on the wire formats the NHS already uses. The shared record says on its face that the contributing systems remain the systems of record.

What you add

One record, one login, one worklist

A whole-person record that all of those feeds land on, with governance, flow and reporting on the same platform. Staff stop re-keying between screens. Managers see numbers that update as care happens. The Flow Edition starts at £1 an instance and carries the platform base without the clinical record, so you can begin with flow and governance and add the record when you choose.

What you decide

Your data, your estate, your rules

The record is shaped to published, open models, so you can leave with it. Every user’s reach is worked out at sign-in from your own organisation structure. Where your country’s rules haven’t been entered, the platform switches that capability off and says why, instead of borrowing another country’s.

Nothing is thrown away on day one. A go-live on this platform is a connection job, not a migration. The lineage table on the platform’s Architecture screen lists, module by module, which fields staff type, which the system generates and which arrive from an integration, so a migration lead can see what changes for whom before anything is switched on. The page on migrating on, and leaving covers the export path if you ever go the other way.

3 Why we don’t copy your data to the middle

England’s health and care system is thousands of separate legal entities, and that separation is where accountability lives. Any plan to join them up has to survive contact with that fact.

~6,150GP practices~207NHS trusts36Integrated care boards153Upper-tier local authoritiesEach is a separate legal entityits own data controller · its own regulator relationship · its own liabilityThat isn’t an accident of history to be tidied away. It’s the accountability structure of the system.An architecture that requires it to be dissolved isn’t an architecture — it’s a precondition nobody can meet.plus several thousand independent, private and voluntary-sector providers
Indicative counts, August 2026. What matters is the order of magnitude, not the last digit — there’s no plausible reform that turns this into one organisation.

There are two ways to join up organisations’ data. You can copy everything to a central store, or you can leave each organisation in charge of its own record and send the question to where the data already lives. The first creates a new controller holding everyone else’s liability, a new target, and a copy that’s out of date the moment it lands. The second moves only the answer. commvita is built the second way, and the diagram below is the whole argument.

Centralise — copy the data to the middleOne controller inherits everyone else's liabilityCentral copya new controller, a new targetOrg 1Org 2Org 3Org 4Org 5Org 6every arrow is a data-sharing agreement, a DPIA and a transferand the copy is stale the moment it landsFederate — send the question, not the dataEach org stays its own controller; only answers moveQueryaggregate answer, k≥5Org 1controllerOrg 2controllerOrg 3controllerOrg 4controllerOrg 5controllerOrg 6controller0 rows transferred · counts under 5 suppressedthe answer is computed where the data already lives
The difference is who becomes the controller. Copying every organisation's data to the middle creates a new controller holding other people's liability, a new target, and a copy that’s out of date the moment it lands. Federating leaves each organisation the controller of its own record and moves only the answer.

The practical test to put to any supplier, including us: when a query runs, how many rows leave the organisation that holds them? Here the answer is none. A cohort question is executed at each site and returns a count, with anything under five suppressed so a small group can’t be narrowed to a person.

4 Join a region

A region is many organisations and one shared view. Four things have to work for that to be real, and each can be adopted without the others.

1

Identity: resolve the person, don’t merge the records

A master patient index resolves one person across organisations and identifier schemes without creating a merged record that somebody then has to own. A record locator points at where a document lives instead of copying it.

/empi/nrl-connector
2

Record: a shared view, with the source systems still in charge

The regional record is assembled from contributing systems, and care homes and community providers contribute and read through the same contract as an acute trust.

/single-patient-record/care-homes-shared-record
3

Query: the answer moves, the data doesn’t

A feasibility question runs at every site and returns an aggregate. This is what makes multi-site research and population analysis possible without a transfer.

/cohort-discovery/federated-query
4

Governance: who may ask, and what survives the answer

Sharing agreements with signatories and review dates, a Caldicott queue for anything that isn’t direct care, notification when a non-controller reads, and an access log that can’t be edited afterwards.

/dspa-manager/ig-spine/legitimate-access-log

The thing a region most needs to get right is who may open which record. On this platform that decision follows the recorded care relationship and never the organisation chart. Commissioning a service is not a reason to read the records it creates. The region screen below reports the decision the platform has already made, relation by relation.

The federated region screen listing which relations carry access: subordinate does, commissions, delegated to and member of do not, with the organisation tree beneath
Who can see this record, decided by relation: subordinate carries access, commissioning and delegation don’tCaptured from the running system, build B-692 · demonstration data

5 Feed the nation

A national body doesn’t need your record. It needs the picture, in the shape it has published. commvita pins the national canonical data model and produces extracts in it, so a local instance feeds the national platform instead of competing with it.

The things that change between a county and a country are held as data instead of code. The jurisdiction profile carries the country’s identifiers, terminology editions, data-protection rules and reporting duties as signed, dated entries, and refuses to run a capability whose entry is missing. The organisation spine holds the structure from the department down to a physical site as effective-dated configuration, so when the map is redrawn, and it will be, the change is a data entry with a date and not a rebuild.

What lets one platform sit at all three levels is that it holds meaning, movement and behaviour in one place. A person, an organisation or a referral means the same thing in a ward, a regional team and a national extract. What happened is recorded as events that can’t be edited later, so a count at one level is the same fact at the next. And the rule about who may see what runs on the server everywhere, so the answer doesn’t change with who is asking. The architecture explainer says what is built in each of those today; the Flow Edition and the FDP compares the product set with the national data platform’s.

6 What runs today, and what doesn’t yet

Every claim above is listed here against the screen it lives on and whether it’s live or demonstrated on seeded data.

Live — platform logic wired end to end todayDemonstrated — a representative surface over seeded data
What it doesWhere it livesStatus
Resolve one person across organisations/empi● Live
Point at a record without copying it/nrl-connector○ Demonstrated
Shared cross-organisation record/single-patient-record · /nhr● Live
Care homes contribute and read/care-homes-shared-record○ Demonstrated
Who may see this record, by relation/federation● Live
Aggregate-only feasibility, counts under five suppressed/cohort-discovery · /federated-query○ Demonstrated
Sharing agreements, Caldicott queue, access log/dspa-manager · /ig-spine · /legitimate-access-log● Live
Reach resolved at sign-in/rbac-matrix● Live
Organisational map as dated configuration/org-spine · /jurisdiction-profile● Live
Standards on the wire/connector-dashboard · /epr-hub · /ihe-profiles● Live register, simulated liveness
Extract in the national canonical model/fdp-cdm● Live
The honest edges. The federated query layer, its node board and the suppression rule are built and behave as described against seeded nodes; commvita isn’t operating a live multi-organisation query network today, and the national tier is described from the design and that demonstrated layer. The region screen, identity resolution, organisation spine and national extract are live on a single instance. The translation of an inbound feed into the canonical shape is the part of the connector path not yet built. And joining a region doesn’t remove the need for agreements; it changes what they have to say, and an information governance team still signs them.
What it costs, and what you sign. The Flow Edition is £1 per instance, running on your own kit, with optional paid support. The Population Platform adds the clinical record and population health when you want it. Support levels and response times are contract matters and aren’t promised here. Source-code escrow is offered, and the escrow page explains what’s in it.
© 2026 Commvita Digital Health Solutions Ltd. All rights reserved. UK GDPR · Data Protection Act 2018Caldicott principlesNational Data Opt-outFHIR R4 · HL7 v2 · IHEFlow Edition £1 per instanceNon-SaMD