commvitaConnected care platform
Platform

One integrated platform for health and care.

The record, the operations, the governance and the population view as one set of facts — with each component’s real status stated not implied.

Architecture

One platform, not a suite

Every component reads the same record and the same jurisdiction profile. There’s no integration layer between them, because they aren’t separate products.

commvita platform architectureFive horizontal layers — surfaces, applications, the whole-person record, integration and the platform base — with a jurisdiction profile rail that every layer reads.SurfacesWhat a person or a professional actually touchesCitizen portalClinician recordcommvita MyDayCare worker appBoard & executivePartner portalsApplicationsClinical, operational, governance and analytic modulesClinical recordReferrals & flowCare coordinationGovernance & assurancePopulation healthResearch servicesThe recordOne whole-person record, openEHR-alignedPerson spineEncountersMedicationsDiagnosticsCare plansGenomicsIntegrationOpen standards in and out — no proprietary data modelFHIR R4HL7 v2SNOMED CTOMOPOpen APIsBulk exportPlatform baseThe parts every jurisdiction sharesIdentity & RBACTamper-evident auditJurisdiction profileData fabricWorkflow engineHosting modelJurisdictionprofileIdentifiers, terminologybindings, regulators,statutory clocks,currency, residency andlegal provisions areread from a sourced,effective-dated record —not compiled in.Every layer reads it.

Surfaces, applications, the record, integration and the platform base.

Components

What the platform is made of

ComponentWhat it doesStatus
Whole person recordOne record over time, across every setting a person is known to, resolved instead of merged.Live
Clinical applicationsConsultation, prescribing, assessments, diagnostics, long-term conditions and specialist pathways.Live
Care coordinationOne case with a named key worker and a list of participating organisations, not a case per organisation.Live
Operational flowDemand and capacity as one managed line — front door, wards, discharge and the constraint that’s actually binding.Live
Referral managementProtocol-gated referral with pre-consultation diagnostics ordered against the pathway’s own criteria.Live
Governance & assuranceIncident to risk to board objective as one traceable chain, on a tamper-evident audit.Live
Population healthSegmentation, risk stratification, inequalities and cohort-to-action.Live
Components

… continued

ComponentWhat it doesStatus
Citizen servicesA portal, proxy access, declared communication needs and self-management.Live
Research servicesCohort discovery, de-identified extracts and an immutable extract ledger.Live
GenomicsReferral, consent, pedigree and pharmacogenomic surfaces — with a persistence gap stated below.Partial
Analytics & reportingStatutory returns, board reporting and a report registry with computed deadlines.Live
Workflow automationPolicy turned into a gated process with quorum approvals and escalating service levels.Live
Open APIs & integrationFHIR, HL7 v2, bulk export, adapters and a message engine.Live
Live Live — built, persisted and reachable todayPartial Partial — built with a stated limitPending licence Pending licence — built, awaiting a publisher licenceDesigned Designed — specified, not builtNot built Not built
Citizen services

The patient portal, and an honest account of it

A portal is where a person exercises rights, so a control that appears to work and doesn’t is worse here than anywhere else on the platform. Four of these aren’t yet what they look like, and the page says which.

What the citizen portal does todayThirteen portal capabilities, each marked live, partial, designed or not working, including four controls that don’t yet persist.AppointmentsSee, book and change appointmentsLiveMedicationsCurrent medication and repeat requestsLiveMessagesTwo-way messaging with the practice or teamLiveResultsDiagnostics and results as they’re releasedLiveCare planThe plan, the goals and who is involvedLiveCommunication needsDeclare a required format or a reasonable adjustmentLiveFamily & proxy accessCarer and parental access, with expiryLiveVaccinationsThe record and a certificateLiveGenomic resultsDesigned. Not built — no patient-facing genomic surface existsDesignedResearch participationThe control renders and persists nothingNot workingNational data opt-outThe control renders and persists nothingNot workingRecord access logShows the person’s own portal activity, not who read their recordPartialData exportReturns a fixed demonstration bundle, not the person’s dataNot working

Thirteen portal capabilities with their real status. The four amber and red rows are recorded in the platform’s own defect register.

Four controls that don’t yet do what they appear to

The per-study research opt-out and the national data opt-out both render, both move when a person toggles them, and neither writes anything. A person can believe they have opted out and haven’t.

The granted-access list is held in memory, so it’s lost when the system restarts and differs between copies. Removing an entry doesn’t restrict any member of staff, because access is controlled by role and organisation instead.

The data export returns the same demonstration file for every patient. It shows the shape of the data and must never be given to someone as their own record.

We publish these and not quietly fixing them later. A buyer assessing information governance needs the real position, and saying so is the only thing that makes the rest of this site worth believing.

Configuration

A jurisdiction is a configuration, not a release

The jurisdiction configuration wizardTen configuration steps from identity through to review, with unconfigured values failing safe to nothing instead of to another jurisdiction’s value.1Identity2Modules3Identifiers4Landscape5Governance model6Terminology7Frameworks8Compliance9Currencies10ReviewNothing here is a default from somewhere elseAn unconfigured value fails safe to nothing. It never borrows a neighbouring jurisdiction’s identifier, regulator or coding system.Ten steps. A jurisdiction isn’t deployable until the mandatory domains are signed off by a named person.

The ten setup steps. A value that hasn’t been set falls back to nothing, never to a neighbouring country’s.

Sourced

Every value cites something

A configuration entry carries its source, the date it took effect and the person accountable for it. An uncited value is a draft.

Effective-dated

History stays true

Superseding a value doesn’t overwrite it. Last year’s performance still reconciles against the body that actually held the contract.

Fail-safe

Never a borrowed default

An unconfigured jurisdiction gets nothing, not England’s. Coding a discharge in the wrong country’s classification is worse than refusing to code it.