ProvidEHR
Integrations

Connect to full EHRs and national systems

ProvidEHR runs beside the systems you already have. It keeps its own openEHR-native record and connects to clinical EHRs and national infrastructure in Sweden and the UAE through one durable, auditable, consent-aware pipeline.

PEOPLE & EDGEInVivo appon-device prevention agent · home BP, PROMsClinicians & AI agentsRounds · Triager · attestation & promotionCitizens · 1177consent & disclosure choicesPROVIDEHR CONTROL PLANEopenEHR-native record · governance · integration registry + durable outboxopenEHR CDRauthoritativeFHIR R4/R5 façadeprojectionGovernance gatedraft→attest→writeDurable outboxidempotent · retrySHARED CONNECTOR CORE (ehr-integration)Cambio COSMICCOS · OAuth + API keyEpicSMART · RS384 JWTOracle / CernerSMART · tenant baseNational adaptersFHIR · openEHRSWEDISH NATIONAL HEALTH INFRASTRUCTURENPÖnational patient summary1177 / Ineracitizen servicesLabPortalenlab orders & resultsInVivoLabs ★our lab networkKvalitetsregisterquality registriesVaccination (NVR) ★+ our registry

★ = ProvidEHR-native capability that can complement or stand in for the national service. Data stays patient-scoped, consent-aware and auditable end to end.

One vendor-neutral core

Every connector shares the ehr-integration kernel — registry, capability discovery, FHIR R4/R5 mapping and openEHR projection. Adding a vendor means adding only its auth and endpoints.

Governed write-back

Nothing is written to a system of record without a staged draft, clinician attestation and a promotion gate. AI drafts can never write directly.

Durable, idempotent outbox

Integration work is recorded through an idempotent outbox with audit and dead-letter state. Persistent worker recovery, retry leases and tenant isolation are being exercised before live sandbox claims.

Cambio COSMIC

Sweden · contract harness · live sandbox pending

Designed for Cambio Open Services OAuth, subscription-key and profile-specific FHIR contracts. Synthetic reads, provenance projection and governed NEWS2 write-back are under deterministic validation; Cambio credentials and certification remain external gates.

Malaffi · Abu Dhabi

UAE · disabled connector foundation · onboarding pending

ProvidEHR would connect as the facility EHR. Native HL7 v2/MLLP, a disabled profile-driven projection connector, Emirates ID validation and AE-AZ safety defaults are implemented; the partner pack, exact profiles, live delivery, facility-sponsored conformance, UAE deployment and certification remain pending.

Epic on FHIR

Global · SMART Backend Services

client_credentials with an RS384-signed JWT client assertion (no shared secret). FHIR R4 read across the core clinical resources.

Oracle Health / Cerner

Global · SMART Backend Services

JWT-assertion auth with the tenant id embedded in the FHIR R4 base URL. Same connector core as Epic — only auth and endpoints differ.

National services

Sweden · roadmap

The architecture has explicit paths for NPÖ and 1177 (Inera), laboratory services, quality registries and vaccination data. Formal agreements, platform adapters and production validation are still required.

How the Cambio COSMIC sandbox path is built

We treat Cambio Open Services as the system boundary and COSMIC as the operational source of truth. The connector path owns OAuth and subscription-key authentication, profile-specific FHIR requests, idempotency and explicit error state. Imported facts are projected into source-cited openEHR compositions. Proposed NEWS2 write-back starts only from a clinician-attested promoted draft. Deterministic synthetic contracts run locally; a credentialed COS Sandbox round trip and Cambio's certification process are still required before production use.

UAE · Abu Dhabi integration path

ProvidEHR as the facility EHR for Malaffi

The UAE path uses the same governed openEHR record and durable integration boundary, with a native HL7 v2/MLLP projection layer built for partner-supplied profiles. The connector is deliberately disabled until independently reviewable onboarding and deployment evidence is attached.

Current status

Code-capable foundation implemented · onboarding, conformance and UAE production activation pending.

Native HL7 v2 + MLLP

Byte-exact parsing, declared delimiters, data-driven profiles, bounded framing and control-ID-bound AA/AE/AR acknowledgements.

Profile-driven clinical projection

A disabled connector maps reviewed openEHR JSON paths into escaped, conformance-validated messages and records source and outbound hashes.

Abu Dhabi identity and policy

Emirates ID checksum validation, delimiter-safe local MRNs, AE / AE-AZ deployment defaults and a conservative UAE oversight floor.

Evidence-backed activation

Traffic stays disabled until facility, profile, transport, network, residency, key-custody and conformance gates carry reviewed evidence.

Governed message path
  1. 1Clinician-attested openEHR source event
  2. 2Reviewed partner profile projection
  3. 3Escaped HL7 v2 message + source/outbound hashes
  4. 4Approved delivery path + correlated application ACK
  5. 5Audit, reconciliation and explicit rollback evidence
External gates before activation
  • A sponsoring Abu Dhabi facility and signed ADHDS onboarding agreements
  • The authoritative Malaffi message profiles, trigger events and terminology bindings
  • Approved transport, endpoint credentials and production network path
  • UAE-resident hosting, in-country key custody and applicable ADHICS evidence
  • Facility-sponsored conformance, reconciliation, rollback rehearsal and production approval

No Malaffi or DoH partnership, certification, conformance, live connection, UAE deployment or production approval is claimed.