commvita
Connected care platform
POPULATION PLATFORM

Patient Portal

The person's own way into their record — appointments, medications, results, communication needs, proxy access and research transparency — with the two access controls that are demonstrated rather than enforcing named on the face of this document.

Live vs demonstrated: Live — real, API-backed platform logic (wired end-to-end today) Demonstrated — representative control surface with seeded data / illustrative UI mock-up

1What the portal is

The patient portal is the person's own way into their record and into the services around it. It is separately authenticated — a portal session is not a staff session and carries none of a staff account's reach — and it is jurisdiction-branded, so it wears the health system's identity, its colours and its identifier label, with commvita™ named as the platform underneath rather than over the top.

Fifteen tabs, grouped by what a person came to doLook after todayAppointments — book, reschedule, cancelMedications and repeat requestsMessages to and from the practiceTest resultsCare plan and open tasksLook after myselfMy goals — weight, BP, exercise, smokingPreventive nudges — book, defer or declineVaccinations and certificateMaternity and baby — the digital red bookSpecialist services — physiotherapy, eye healthBe treated properlyCommunication needs and reasonable adjustmentsFamily history, self-declared and non-genomicLinked accounts — proxy and carer accessData and privacyFeedbackJurisdiction-branded: the portal wears the health system's own identity and identifier label, with commvita™ as the platform underneath.
Fifteen tabs, but a person does not think in tabs. They arrive to do one of three things: deal with today, look after themselves, or be treated properly — and the last group is the one most portals leave out.

2Dealing with today

Appointments can be booked against real slots, rescheduled and cancelled; a repeat prescription can be requested against a specific medication with a note; messages go to and from the practice; test results, the care plan and its open tasks are readable. An appointment request that has no bookable slot becomes a request rather than a dead end.

Alongside that sit preventive nudges — a vaccination due, a screening invitation, an annual review, a medication review. Each carries three answers, not one: book it, remind me later, or decline with a reason. The reason matters: a decline recorded with its reason is clinical information, and a decline recorded as silence is a person who looks like they were never asked.

3Being treated properly

A declared communication need becomes a constraint on every letterThe person declaresLarge print · easy read · braille · BritishSign Language interpreter · a supporterpresent · extra time.Declared in the portal, or recorded bystaff.It becomes a required formatHeld once, on the person — not per letter,per service or per system.Surfaced to staff as a banner, not buriedin a note.Every outbound letter must honour itThe elective experience standards make thismeasurable: an appointment letter in a format theperson cannot read is a breach, not a near miss.So the portal declaration and the compliance figureread the same record.The point of self-declaration is that the person should not have to ask five services separately, and then again next year.
Held once, on the person. A communication need declared in the portal is the same record the elective experience standards measure compliance against, so the two cannot disagree.

The portal also carries a self-declared family history — “my mother had breast cancer” — which can open earlier screening. It is explicitly non-genomic, and that separation is deliberate: collapsing a family-history statement into genomic data would drag the heaviest consent regime on the platform onto a screening reminder, for no benefit to anyone.

Proxy and carer access, in both directionsAccounts I can reachA parent for a child under an age threshold.An adult child acting for a parent.An appointed carer, or a lasting power ofattorney.Each shown with the relationship it rests on.Who can reach mineThe same list from the other side — because aproxy arrangement the subject cannot see is notconsent, it is an administrative fact about them.Revocable by the person, with a confirmationnaming who loses access.Why both directions matterA one-sided proxy register answers the carer'squestion and not the patient's.Transparency under Article 15 is about what theperson can see, not what the service canproduce on request.
A proxy arrangement the subject cannot see is not consent — it is an administrative fact about them. So the register is readable from both sides and revocable from the subject's.

4Research participation

Secondary use of health data is the thing patients are least often told about and most often surprised by. The portal names each study the person's pseudonymised or anonymised data feeds into, with the organisation, the lead researcher, the approval reference, the data categories used, the anonymisation applied and the lawful basis — and it says, per study, whether opting out is possible at all, because for a fully anonymised dataset it often is not.

Where nothing is recorded for that person, the population transparency list is shown rather than an empty page — an empty page would imply no research is happening, which is a stronger claim than the absence of a row supports.

Research participation — shown honestly, and the opt-out is not yet wiredLive — what the person is shownEach study their pseudonymised or anonymised data feeds into, by name.The organisation, the lead researcher and the approval reference.Which data categories are used, and the anonymisation applied.The lawful basis, and whether opting out is possible for that study.Where nothing is recorded for this person, the population transparency list isshown instead — not an empty page implying no research.NOT WIRED — the opt-out controlThe per-study opt-out toggle changes React state and posts nowhere. Theopted_out column exists on the record and the portal never writes it.The National Data Opt-out switch is the same: local state, no persistence.So the screen shows a choice being made and the choice is not recorded.Refreshing the page restores the previous position.A control that appears to work and does not is worse than an absent one, andthis is stated here because a person would otherwise believe they had optedout.
The transparency half is live and genuinely better than most. The control half is not wired, and saying so is the whole point of a document like this.

The opt-out controls do not persist. Read this before demonstrating them. The per-study research opt-out and the National Data Opt-out switch both change on-screen state and post to nothing. The database column exists; the portal never writes it. A person who used these would believe they had opted out and would not have. Until they are wired, an opt-out must be recorded through the service in the normal way, and the toggles should not be presented to a real patient population.

5Who has seen my record?

This is one question in ordinary language and three different questions in a health record system, and conflating them is how a portal comes to claim transparency it does not deliver.

Three different questions about access — and commvita answers them in three different places“What have I done in the portal?”LIVEThe Portal Activity Log — the person's ownactions, from the audit trail.Honestly labelled. It is not, and does not claimto be, a record of who read the file.“Who have I let in?”DEMONSTRATEDA list of granted access, with an organisation, anaccess type and an expiry, and a revoke action.Held in memory: a grant is lost on restart and isnot visible on another replica, and an empty listfalls back to a shared example.Revoking removes the row. It does NOT restrict aclinician — staff access is governed by role andorganisation scope, not by this list.“Who has actually read my record?”ELSEWHEREThis exists — every access carries alegitimate-relationship justification andanomalous patterns are flagged.It is a staff and information-governance surface,and the person-facing version is produced as asubject-access response.It is NOT a tab in the portal today.
The product labels its activity log honestly as a Portal Activity Log. This document does not re-label it as an access log, because the two are not the same thing and a patient reading a marketing page would not know the difference.

Where the real access record lives. Every staff access to a record carries a legitimate relationship justification, anomalous patterns — out-of-area, bulk, cross-organisation — are flagged for investigation, and the log is append-only and hash-chained so it is tamper-evident. A person can challenge a justification, and a per-person Article 15 view can be produced. All of that is real. None of it is currently a tab in the portal, and closing that gap is a wiring job, not a build.

6Where it lives, and its honest edges

FunctionEndpointStatus
Sign in, profile, care plan, medications, test results /portal/auth, /me, /care-plan, /medications, /test-results Live
Appointments — book against real slots, reschedule, cancel, request /portal/appointments, /available-slots, /appointment-requestLive
Messages and repeat prescription requests /portal/messages, /repeat-request Live
Preventive nudges — book, defer, decline with reason /portal/nudges + three actions Live
Communication needs and reasonable adjustments /portal/comm-needsLive
Self-declared family history (non-genomic) /portal/family-historyLive
Vaccinations, read from the immunisation spine /portal/vaccinationsLive
Research participation — transparency view/portal/research Live
Research and national opt-out — controls not wired Not wired
Portal activity log (the person's own actions) /portal/access-logLive
Granted access list — held in memory, does not gate staff access /portal/record-accessDemonstrated
Who has read my record — staff and IG surface, not in the portal /legitimate-access-logLive elsewhere
Care feed for family and carers/portal/care-feed Live
Rapid review — patient- or family-initiated escalation /portal/rapid-reviewLive
Patient transport request · firearms medical request /portal/patient-transport/request, /firearms-request Live
Data portability export — returns a fixed example bundle /portal/fhir-exportDemonstrated
Maternity and baby · specialist services · goals · linked accounts Demonstrated

The portability export is a shape, not a record. /portal/fhir-export returns a fixed FHIR bundle — the same date of birth, the same condition, the same medication and the same vaccination — whatever patient asks for it. It demonstrates the resource structure a real export would take. It must not be offered to a patient as their data portability response under Article 20, because it is not their data.

The granted-access list does not gate anything. It is held in a process-local store, so a grant is lost when the service restarts and is invisible to the other replica, and an empty list falls back to a shared example containing a fictional practice, nurse and pharmacy. Revoking a row removes the row. Staff access is governed by role and organisation scope, and revoking here does not change it.

What the portal is not. It is not a clinical decision-support tool and carries no medical-device claim. It does not diagnose, triage or advise. A nudge is an invitation, not an instruction, and every clinical action it can start — a booking, a repeat request, a rapid review — lands on a human being.

Routes: /portal (patient) · /patient-portal (staff) · API: /portal (42 endpoints), separately authenticatedStandards: UK GDPR Art.15 · Art.20 · Accessible Information Standard DCB1605 · NHS Reasonable Adjustment Flag · Non-SaMD
© 2026 Commvita Digital Health Solutions Ltd. All rights reserved.