ProvidEHR
Prevention operating system · longitudinal EHR foundation · governed co-work

Prevention and early detection for an entire population.

Engineered for national-scale validation. Designed to grow into the general EHR.

InVivo is where people live day to day. ProvidEHR is where the health system turns those daily signals into governed care, team workflow, cohort learning, and measurable outcomes. The same versioned, openEHR-compatible foundation supports an expanding longitudinal EHR workflow surface. AI agents like ChatGPT and Claude can draft and coordinate through bounded MCP and A2A capabilities while clinicians retain authority; InVivo makes patient CarePlan follow-through, consented measurements, and timely early-signal escalation part of the clinical loop.

Panel-first prevention registryBetween-visit evidence, clinician-attested10M synthetic / 20-cell validation target
ProvidEHR · Patient chart
v0.9
EM
Eleanor Marsh
62 y · Female · Patient #P-0421
Active
HR
72 bpm
BP
118/76 mmHg
SpO₂
98 %
Active CarePlan
Rounds · review

Breast reconstruction pathway. Post-op day 5: 9 of 12 activities complete. Incision care marked complete by patient; photos and drain-output note require clinician verification.

FHIR CarePlanTask eventsPatient-reported
Timeline
Last 30 days
  • CarePlan activity reportedToday
    Incision care completed
  • Rounds review requestedToday
    Photos and drain-output note
  • Baseline checklist signedPre-op
    Procedure instructions acknowledged
Encounter note · draft ready for review
openEHR-compatible architecture
HL7 IPS · FHIR R4/R5
SNOMED CT / OMOP terminology
Swedish national integration path
Structured clinical records
Human-in-the-loop AI
Audit-ready workflows
Protocol-locked trial evidence
Red-team assurance suite
10M / 20-cell validation target
Clinician-friendly UX
Built so far

What is built, and what each thing does not yet establish

A few capabilities that show how the platform treats clinical authority, patient control and verifiable history. Each one states its limits plainly and links to the implementation.

Ambient documentation

Notes are drafted from the visit, and cite where each line came from

Consultations can be captured and turned into a structured note draft. Every part of that draft points back to the exact moment in the conversation it came from, so a clinician can check a claim instead of trusting it.

How it holds up

The draft is a proposal, never a record. Nothing reaches the chart until a clinician has reviewed it and signed, and editing the transcript afterwards invalidates the signature rather than quietly changing the note.

Boundary: Live capture, telephony and cross-device calling are still being rolled out. This is documentation support; it is not a diagnostic product and carries no medical-device clearance.

Inspect merged evidence
Clinician authority

A clinician's signature is the only thing that enters the record

AI can draft, suggest and prepare. It cannot commit. Crossing into the patient's authoritative record requires a signature from a licensed clinician, bound to the exact content they reviewed.

How it holds up

A signature covers specific bytes, so altered content stops matching it. Prescriptions and orders need a separate single-use approval taken at the moment of the click, and the highest-risk actions need two qualified people rather than one.

Boundary: Provider onboarding, live credential checking and production trust operations are still external. Signing proves who took responsibility; it does not by itself make a system certified.

Inspect merged evidence
Governed AI

How much oversight an AI action needs is decided by the rules of your market

Each AI capability declares what it is for. From that declaration the platform works out the supervision the relevant regulations demand — and the answer can differ between the EU and the US for the same feature.

How it holds up

Required oversight can only ever be raised, never quietly lowered, and a capability whose declared purpose demands more supervision than a model has earned is refused rather than downgraded. Retraining is checked against a pre-agreed change plan, so a model cannot drift outside what was approved.

Boundary: This enforces a declaration; it does not classify any product on your behalf. CE marking, FDA clearance, a quality management system and notified-body assessment remain separate regulatory work.

Inspect merged evidence
Verifiable history

The record can prove it has not been rewritten — without trusting us

Every entry in the audit history is bound into a structure that lets anyone confirm two things for themselves: that a specific event is in the record, and that nothing already recorded was later altered or removed.

How it holds up

Those checks are arithmetic a third party runs on published values, not an assurance we issue. The history is also published to outside witnesses, so presenting one version of events to one party and a different version to another requires their cooperation, not just our silence.

Boundary: Long-term archival custody, key custody and independent audit acceptance remain operational commitments. Independent witnessing is in place as a mechanism; a genuinely third-party witness network is still being established.

Inspect merged evidence
Patient control

Patients choose what each app is allowed to see

When a patient connects a third-party app, they select which parts of their record it may access. That choice becomes the app's actual permission, not a preference recorded next to a broader one.

How it holds up

Removing a permission removes the corresponding authority, including the app's ability to keep returning without the patient present. Portal sign-in also locks after repeated failed attempts, and that lock survives a restart.

Boundary: Identity proofing, help-desk recovery and support operations are deployment responsibilities. App-ecosystem certification is separate.

Inspect merged evidence
Emergency access

Emergency access works immediately, and is still answerable afterwards

In an emergency a clinician can reach what they need without waiting for an approval cycle. The access is narrow, time-bound, and recorded for review before it is used rather than after.

How it holds up

Emergency access is read-only and tied to one patient; it cannot widen into changing records or administration. Each use creates a review item with the reason given, and ordinary access never silently inherits emergency permission.

Boundary: Who reviews these, how quickly, and what follows are organisational policies your deployment sets. The platform produces the record and the queue.

Inspect merged evidence
Trust by design

Designed for trust, auditability, and clinical governance.

Designed with healthcare privacy and governance requirements in mind, so clinical teams stay in control of every read, write, and disclosure.

Post-quantum safe storage

Post-quantum safe for newly written, long-lived PII and PHI.

Health and identity records can remain sensitive for decades. A copy captured today must not become readable simply because a future quantum computer can break the public-key protection widely used today.

With ProvidEHR's hybrid clinical envelope enabled, every newly written clinical envelope is sealed locally with a NIST-standardized post-quantum layer before managed encryption. Reading it requires both encryption layers and the exact clinical record context. Breaking a classical key-establishment path alone is not enough to reveal the patient data.

Scope, stated plainly: this protection applies to newly written hybrid clinical envelopes when the complete configuration is active. It does not retroactively protect older ciphertext or mean that every external integration and transport has completed its post-quantum migration. Hardware-backed key custody, independent review, certification, and production deployment evidence remain separate claims.
Public evidence comparison · reviewed 9 August 2026

How public post-quantum readiness evidence compares

We searched official product, security, documentation, and corporate pages for “post-quantum,” “quantum-safe,” “quantum-resistant,” ML-KEM, and PQ migration evidence. NIST says organizations should begin moving to its finalized standards now. A missing public statement is not proof that a vendor has no private program or customer-specific capability—it means we found no product-specific evidence that customers can evaluate. See theNIST post-quantum guidanceused as the common baseline.

ProvidEHR

Implemented, narrowly scoped

Newly written clinical envelopes use the configured hybrid post-quantum layer. Historical ciphertext and every transport or integration are not covered by that claim.

Epic

No public EHR-specific PQ evidence found

Epic's public FHIR guidance calls for industry-standard encryption and maintained cryptographic packages. The official material reviewed did not identify a post-quantum algorithm, migration plan, or deployed PQ protection for Epic EHR data.

MEDITECH Expanse

No public EHR-specific PQ evidence found

MEDITECH publicly describes strong security protocols and keeping encryption protocols current. The official material reviewed did not identify a post-quantum algorithm, migration plan, or deployed PQ protection for Expanse data.

Role-based and context-aware access

Audit trail for clinical reads and writes

Human approval for high-risk AI actions

No silent chart changes by agents

Version-aware clinical records

Consent-aware external disclosure workflows

Separation of clinical source of truth from AI-generated drafts

Designed to keep PHI out of unnecessary client storage

The product

A clean clinical workspace on top of a structured health record platform.

ProvidEHR is designed to feel calm and focused for clinicians, while giving organizations a durable foundation built around openEHR principles.

IMPLEMENTED

Patient chart

Create and open patient charts with the basics clinicians expect: name, date of birth, sex, timeline, vitals, and clinical context.

View feature details →
IMPLEMENTED

Structured documentation

Capture clinical information in structured, template-driven records designed for reuse, validation, search, and interoperability.

View feature details →
SYNTHETIC-VALIDATED

CarePlan execution

Represent longitudinal plans, assigned activities, patient-reported completion, clinician verification, and escalation state as first-class record data.

View feature details →
IMPLEMENTED

Timeline-first care

View a patient's story through a clear clinical timeline instead of digging through disconnected screens.

View feature details →
IMPLEMENTED

Safer corrections

Support version-aware clinical updates with reviewable history and audit trails.

View feature details →
IMPLEMENTED

Clinical lists and results

Keep demographics, problems, allergies, medications, diagnostic results, service requests, encounters, and notes as structured projections with provenance.

View feature details →
SYNTHETIC-VALIDATED

Medication reconciliation and prescribing

Make source conflicts visible, preview canonical medication state, and keep prescribing, eRx transmission, interaction signals, and clinician review version-bound.

View feature details →
IMPLEMENTED

Identity, consent, and audit

Bind access to tenant, cell, role, purpose, consent, break-glass, proxy, revocation, disclosure, and PHI-safe audit evidence.

View feature details →
SYNTHETIC-VALIDATED

FHIR, SMART, Bulk, openEHR, and AQL

Project the record through FHIR R4/R5 summaries, SMART launch, NDJSON export, openEHR-compatible templates and supported AQL queries.

View feature details →
SYNTHETIC-VALIDATED

Terminology and interoperability

Use governed value sets, validate-code, deterministic ICD/LOINC/SNOMED/OMOP crosswalks, and connector contracts for regional and national exchange.

View feature details →
SYNTHETIC-VALIDATED

Patient, proxy, and agent surfaces

Provide bounded patient/proxy views, companion and voice workflows, delegated MCP/A2A tasks, and source-cited AI drafts without autonomous authoritative writes.

View feature details →
IMPLEMENTED SLICE

Planned full EHR operations

Scheduling, ADT, inpatient, emergency, surgery, nursing, pharmacy, radiology, pathology, blood bank, monitoring, supply chain, and billing worklists are now available as governed product slices; durable integrations remain queued.

View feature details →
EXTERNAL / PLANNED

Planned national-scale trust

SITHS/BankID, NPÖ, 1177, LabPortalen, quality and vaccination registries, ONC/Inferno evidence, live regional credentials, independent clinical validation, and national-scale production proof remain external gates.

View feature details →
IMPLEMENTED SLICE

PHI-safe observability and assurance

Emit bounded request and trace correlation plus route-template completion evidence without exporting raw paths, identities, credentials, or clinical payloads.

View feature details →
IMPLEMENTED SLICE

Hospital operations command center

Coordinate scheduling, referrals, ADT, ED, procedures, nursing, diagnostics, pharmacy, and revenue worklists with explicit ownership and human decision gates.

View feature details →
IMPLEMENTED CONTRACT

Public, private, and hybrid deployment

Model Swedish public care, US private delivery, and hybrid networks with tenant, identity, payer, policy-pack, and regional integration boundaries.

View feature details →
IMPLEMENTED SLICE

Downtime and recovery

Keep offline-safe drafts and queued actions replay-safe, then reconcile conflicts explicitly before they become authoritative clinical data.

View feature details →
IMPLEMENTED POLICY

AI safety and human review

Typed capabilities, source citations, uncertainty, bounded delegation, and clinician gates keep AI assistance useful without autonomous clinical writes.

View feature details →
IMPLEMENTED EVIDENCE PATH

Migration and readiness

Track source mappings, connector contracts, readiness bundles, rehearsal evidence, owners, and activation gates for each deployment.

View feature details →
IMPLEMENTED SLICE

Clinical collaboration rooms

Coordinate source-bound clinician and agent work around a shared question, preserving participants, proposals, and the final human decision.

View feature details →
The problem

Most EHRs were not designed for the next decade of healthcare.

Care teams need an EHR that respects their time, structures clinical data for reuse, and is genuinely ready for safe AI assistance.

Fragmented clinical data

Records scatter across disconnected systems, making longitudinal care and reuse difficult.

Documentation overload

Clinicians lose hours every day to repetitive, unstructured documentation.

AI struggles to help

Unstructured records limit what AI can safely retrieve, summarize, or draft.

Brittle integrations

Vendor lock-in and ad-hoc interfaces make every new connection painful.

Auditability as an afterthought

Provenance, consent, and version history are bolted on rather than designed in.

Technical UX, not clinical UX

Clinicians shouldn't have to navigate database-shaped tools to deliver care.

Population prevention + longitudinal EHR + governed co-work

Build the prevention operating system—and the EHR foundation beneath it.

ProvidEHR combines governed prevention, early detection, CarePlan coordination, population learning, and an extensible longitudinal general-EHR foundation. Alongside Cambio COSMIC, COSMIC can remain the authoritative operational EHR while ProvidEHR adds the prevention layer; InVivo keeps each person connected to the plan between visits. The ambition is an evidence standard grounded in reproducible, independently reviewable validation and engineered for national-scale evaluation—not an unsupported claim of superiority or rollout readiness.

01
Operational EHR

Cambio COSMIC

COS Sandbox validation pending

Cambio's published OAuth, API-key, FHIR search and governed NEWS2 contracts are pinned in a deterministic synthetic harness. Credentialed COS Sandbox read/write validation and certification remain pending; COSMIC keeps its business rules, versions and authority.

02
Prevention + longitudinal record plane

ProvidEHR

Fail-closed enforcement staged

Rust services implement identity, tenant and scope controls, clinician attestation, provenance, audit, versioned records, population worklists, early-signal evidence, CarePlan coordination and aggregate cohort learning. Signed programme actions carry enforced intended-use labels; patient nudges reject diagnostic or treatment directives, and regulated releases require validation, safety-case, locked-version, monitoring and rollback evidence. Prevention plans, packets and risk outputs now use bounded indexed paths partitioned by trusted deployment region, including Bulk FHIR projections. The backend is exercised locally; production deployment and identity cutover remain gated.

03
Patient CarePlan loop

InVivo

Between-visit follow-through

Approved actions, reminders and education reach the person; completion, symptoms, questionnaires and measurements return as consent-scoped evidence for clinician verification and timely escalation.

04
Human-AI co-work

Codex + Claude

Repository plugin ready

The governed repository plugin is installable in Codex and Claude Code/Cowork with short-lived, EHR-bound delegation. A2A tasks now support delegation-bound finite SSE status streaming from submitted to terminal state; durable long-running workers and external push delivery remain open. Hosted Codex Work PHI access still needs an OAuth/app connector. Consequential clinical changes remain staged, reviewable and human-attested.

Parallel integration pilots

Two markets, two evidence paths

COSMIC and Malaffi are separate pilot paths built on the same governed integration boundary. Each must earn its own vendor or HIE evidence before activation.

Sweden · pilot

Cambio COSMIC

Synthetic contracts · sandbox pending

The Open Services OAuth, subscription-key, FHIR search and governed NEWS2 contracts are exercised in a deterministic synthetic harness. A recorded credentialed COS Sandbox round trip and Cambio certification are the next external gates.

Abu Dhabi · pilot

Malaffi

Disabled connector foundation · onboarding pending

ProvidEHR would connect as the facility EHR. The source-bound HL7 v2/MLLP kernel and disabled profile-driven connector cover safe projection, ACK binding, Emirates ID validation and Abu Dhabi jurisdiction defaults. The Malaffi onboarding pack, a sponsoring facility, exact profiles, live delivery, conformance testing, UAE deployment and certification remain external gates.

Evidence before readiness claims

COS Sandbox credential validation and Cambio certification remain pending. Malaffi onboarding, facility sponsorship, partner profiles, live delivery, conformance testing, UAE deployment and certification also remain pending. ProvidEHR does not claim a Cambio, Malaffi or DoH partnership, certification, production connection or live national-service connection.

Target topology · regional federation

Patient-level care stays regional. Prevention knowledge travels.

Repeatable ProvidEHR regional nodes are the target deployment pattern: each node keeps identity, consent, clinical records, audit and CarePlan execution close to the care system, while a central knowledge plane distributes signed, versioned prevention programmes.

01

Signed programme packs

A central knowledge plane publishes signed, versioned programmes, terminology, measures, model cards and validation suites for explicit regional acceptance. Regulated activation fails closed without validation, safety-case, locked-version, monitoring and rollback evidence.

02

Regional ProvidEHR nodes

Repeatable regional cells apply locally approved releases and connect to the incumbent EHR, InVivo patient loop and governed clinical co-work surfaces. Prevention reads enter through deterministic, bounded regional index pages so another region's rows are excluded before projection.

03

Patient data stays local

Patient-level identity, consent, records, CarePlan execution and audit remain in the regional clinical data plane unless a specific lawful, purpose-bound flow is approved.

04

Aggregate-only learning

Only approved aggregate cohort evidence returns to the learning plane, with provenance, minimisation and small-cell controls; patient rows are rejected and candidate knowledge artifacts do not auto-activate.

The signed-release and aggregate-only learning contracts are exercised locally. This remains the scale-out architecture, not a production-deployment claim: regional cells and cross-region operations still require deployment, security, privacy and recovery evidence.

Executable CarePlans

Show how care is carried out, not just recommended

Each plan turns evidence into reviewable tasks, patient follow-through, verification, and escalation. AI organizes context and uncertainty; clinicians retain consequential decisions.

Trigger AI evidence + uncertainty Clinician gate Tasks → evidence → escalation

Investor demo visual: examples are executable workflow concepts; unavailable integrations are labeled mockups.

Interactive workflow mockup

Pre-diabetes prevention

Step 1 of 4
Clinician turn
Roam clinician workspace
Care team worklist

AI highlights HbA1c trend, missing context, and evidence citations.

Evidence linkedConsent boundOffline-safe draft
AI support at this step

Evidence-linked context, uncertainty, missing-data prompts, and a bounded next-best-action suggestion. AI cannot sign, prescribe, diagnose, or complete clinician-only work.

Reinforce progress or route an AI-supported escalation suggestion to a clinician.
XPRIZE Healthspan · Finals Rules v1.0

Trial evidence that fails closed.

ProvidEHR now includes a protocol-locked evidence and enrollment foundation aligned to the public Finals Rules dated April 13, 2026. It protects the chain from consent and external randomization through repeated endpoint evidence and non-authoritative planning analysis.

Personalized threshold equations are pending; ProvidEHR does not invent them.
The third central-lab immune category remains pending XPRIZE definition.
Authority stays outside the app

XPRIZE-Utah DCC REDCap data and DCC analyses remain authoritative for judging. ProvidEHR is trial-execution and evidence infrastructure—not the therapeutic, an XPRIZE endorsement, or a guarantee of an award.

Read the current Finals RulesGET /v1/research/healthspan/protocol
Protocol evidence

Six visits. One auditable chain.

BV1, BV2, Mid1, Mid2, FUV1 and FUV2 stay tied to masked assessors, source records, SOPs, units, calibration and one prespecified lower-body power method and device.

Consent and randomization

Permission before assignment.

Enrollment requires a real EHR, study-specific protocol and ICF consent, plus an immutable assignment reference from an external IRT. Consent, identity reservation and audit commit atomically.

Planning analysis

Complete-roster ITT, honestly labelled.

Local scenarios preserve every randomized participant and reproduce the published one-sided 90% Newcombe lower confidence bound without presenting local calculations as judging results.