commvitaConnected care platform
Platform

One integrated platform for health and care.

The record, the operations, the governance and the population view as one set of facts — with each component’s real status stated rather than implied.

Architecture

One platform, not a suite

Every component reads the same record and the same jurisdiction profile. There is no integration layer between them, because they are not separate products.

commvita platform architectureFive horizontal layers — surfaces, applications, the whole-person record, integration and the platform base — with a jurisdiction profile rail that every layer reads.SurfacesWhat a person or a professional actually touchesCitizen portalClinician recordcommvita MyDayCare worker appBoard & executivePartner portalsApplicationsClinical, operational, governance and analytic modulesClinical recordReferrals & flowCare coordinationGovernance & assurancePopulation healthResearch servicesThe recordOne whole-person record, openEHR-alignedPerson spineEncountersMedicationsDiagnosticsCare plansGenomicsIntegrationOpen standards in and out — no proprietary data modelFHIR R4HL7 v2SNOMED CTOMOPOpen APIsBulk exportPlatform baseThe parts every jurisdiction sharesIdentity & RBACTamper-evident auditJurisdiction profileData fabricWorkflow engineHosting modelJurisdictionprofileIdentifiers, terminologybindings, regulators,statutory clocks,currency, residency andlegal provisions areread from a sourced,effective-dated record —not compiled in.Every layer reads it.

Surfaces, applications, the record, integration and the platform base.

Components

What the platform is made of

ComponentWhat it doesStatus
Whole person recordOne longitudinal record across every setting a person is known to, resolved rather than merged.Live
Clinical applicationsConsultation, prescribing, assessments, diagnostics, long-term conditions and specialist pathways.Live
Care coordinationOne case with a named key worker and a list of participating organisations, not a case per organisation.Live
Operational flowDemand and capacity as one managed line — front door, wards, discharge and the constraint that is actually binding.Live
Referral managementProtocol-gated referral with pre-consultation diagnostics ordered against the pathway’s own criteria.Live
Governance & assuranceIncident to risk to board objective as one traceable chain, on a tamper-evident audit.Live
Population healthSegmentation, risk stratification, inequalities and cohort-to-action.Live
Components

… continued

ComponentWhat it doesStatus
Citizen servicesA portal, proxy access, declared communication needs and self-management.Live
Research servicesCohort discovery, de-identified extracts and an immutable extract ledger.Live
GenomicsReferral, consent, pedigree and pharmacogenomic surfaces — with a persistence gap stated below.Partial
Analytics & reportingStatutory returns, board reporting and a report registry with computed deadlines.Live
Workflow automationPolicy turned into a gated process with quorum approvals and escalating service levels.Live
Open APIs & integrationFHIR, HL7 v2, bulk export, adapters and a message engine.Live
Live Live — built, persisted and reachable todayPartial Partial — built with a stated limitPending licence Pending licence — built, awaiting a publisher licenceDesigned Designed — specified, not builtNot built Not built
Citizen services

The patient portal, and an honest account of it

A portal is where a person exercises rights, so a control that appears to work and does not is worse here than anywhere else on the platform. Four of these are not yet what they look like, and the page says which.

What the citizen portal does todayThirteen portal capabilities, each marked live, partial, designed or not working, including four controls that do not yet persist.AppointmentsSee, book and change appointmentsLiveMedicationsCurrent medication and repeat requestsLiveMessagesTwo-way messaging with the practice or teamLiveResultsDiagnostics and results as they are releasedLiveCare planThe plan, the goals and who is involvedLiveCommunication needsDeclare a required format or a reasonable adjustmentLiveFamily & proxy accessCarer and parental access, with expiryLiveVaccinationsThe record and a certificateLiveGenomic resultsDesigned. Not built — no patient-facing genomic surface existsDesignedResearch participationThe control renders and persists nothingNot workingNational data opt-outThe control renders and persists nothingNot workingRecord access logShows the person's own portal activity, not who read their recordPartialData exportReturns a fixed demonstration bundle, not the person's dataNot working

Thirteen portal capabilities with their real status. The four amber and red rows are recorded in the platform’s own defect register.

Four controls that do not yet do what they appear to

The per-study research opt-out and the national data opt-out both render, both move when a person toggles them, and neither writes anything. A person can believe they have opted out and have not.

The granted-access list is held in process memory, so it is lost on restart and differs between replicas — and revoking an entry restricts no staff access, because access is governed by role and organisation scope.

The data export returns a fixed demonstration bundle, identical for every patient. It demonstrates the resource shape and must never be offered to a person as their data-portability response.

These are published here rather than quietly fixed later because a buyer evaluating information governance needs the real position, and because saying so is the only thing that makes the rest of this site worth believing.

Configuration

A jurisdiction is a configuration, not a release

The jurisdiction configuration wizardTen configuration steps from identity through to review, with unconfigured values failing safe to nothing rather than to another jurisdiction's value.1Identity2Modules3Identifiers4Landscape5Governance model6Terminology7Frameworks8Compliance9Currencies10ReviewNothing here is a default from somewhere elseAn unconfigured value fails safe to nothing. It never borrows a neighbouring jurisdiction's identifier, regulator or coding system.Ten steps. A jurisdiction is not deployable until the mandatory domains are signed off by a named person.

The ten configuration steps. An unconfigured value fails safe to nothing rather than to a neighbouring jurisdiction’s.

Sourced

Every value cites something

A configuration entry carries its source, the date it took effect and the person accountable for it. An uncited value is a draft.

Effective-dated

History stays true

Superseding a value does not overwrite it. Last year’s performance still reconciles against the body that actually held the contract.

Fail-safe

Never a borrowed default

An unconfigured jurisdiction gets nothing, not England’s. Coding a discharge in the wrong country’s classification is worse than refusing to code it.