One integrated platform for health and care.
The record, the operations, the governance and the population view as one set of facts — with each component’s real status stated rather than implied.
One platform, not a suite
Every component reads the same record and the same jurisdiction profile. There is no integration layer between them, because they are not separate products.
Surfaces, applications, the record, integration and the platform base.
What the platform is made of
| Component | What it does | Status |
|---|---|---|
| Whole person record | One longitudinal record across every setting a person is known to, resolved rather than merged. | Live |
| Clinical applications | Consultation, prescribing, assessments, diagnostics, long-term conditions and specialist pathways. | Live |
| Care coordination | One case with a named key worker and a list of participating organisations, not a case per organisation. | Live |
| Operational flow | Demand and capacity as one managed line — front door, wards, discharge and the constraint that is actually binding. | Live |
| Referral management | Protocol-gated referral with pre-consultation diagnostics ordered against the pathway’s own criteria. | Live |
| Governance & assurance | Incident to risk to board objective as one traceable chain, on a tamper-evident audit. | Live |
| Population health | Segmentation, risk stratification, inequalities and cohort-to-action. | Live |
… continued
| Component | What it does | Status |
|---|---|---|
| Citizen services | A portal, proxy access, declared communication needs and self-management. | Live |
| Research services | Cohort discovery, de-identified extracts and an immutable extract ledger. | Live |
| Genomics | Referral, consent, pedigree and pharmacogenomic surfaces — with a persistence gap stated below. | Partial |
| Analytics & reporting | Statutory returns, board reporting and a report registry with computed deadlines. | Live |
| Workflow automation | Policy turned into a gated process with quorum approvals and escalating service levels. | Live |
| Open APIs & integration | FHIR, HL7 v2, bulk export, adapters and a message engine. | Live |
The patient portal, and an honest account of it
A portal is where a person exercises rights, so a control that appears to work and does not is worse here than anywhere else on the platform. Four of these are not yet what they look like, and the page says which.
Thirteen portal capabilities with their real status. The four amber and red rows are recorded in the platform’s own defect register.
Four controls that do not yet do what they appear to
The per-study research opt-out and the national data opt-out both render, both move when a person toggles them, and neither writes anything. A person can believe they have opted out and have not.
The granted-access list is held in process memory, so it is lost on restart and differs between replicas — and revoking an entry restricts no staff access, because access is governed by role and organisation scope.
The data export returns a fixed demonstration bundle, identical for every patient. It demonstrates the resource shape and must never be offered to a person as their data-portability response.
These are published here rather than quietly fixed later because a buyer evaluating information governance needs the real position, and because saying so is the only thing that makes the rest of this site worth believing.
A jurisdiction is a configuration, not a release
The ten configuration steps. An unconfigured value fails safe to nothing rather than to a neighbouring jurisdiction’s.
Every value cites something
A configuration entry carries its source, the date it took effect and the person accountable for it. An uncited value is a draft.
History stays true
Superseding a value does not overwrite it. Last year’s performance still reconciles against the body that actually held the contract.
Never a borrowed default
An unconfigured jurisdiction gets nothing, not England’s. Coding a discharge in the wrong country’s classification is worse than refusing to code it.