Web application and HTTPS edge
React, TypeScript and TanStack Start are hosted through Lovable behind HTTPS. Patient context stays in memory; the signed ProvidEHR session token is tab-scoped rather than a clinical database in the browser.
ProvidEHR combines a population-prevention operating system with an extensible longitudinal general-EHR foundation. The React/TanStack frontend is live. Separately, the repository implements and locally exercises Rust services that connect an application to a persistent SurrealDB/RocksDB record plane, versioned openEHR-compatible records, FHIR projections, consent, provenance, audit, InVivo patient follow-through, and governed Codex and Claude co-work. No production backend deployment, HA, DR, or cutover is claimed.
Live frontend · implemented and locally exercised Rust data plane · production backend rollout gated
In the implemented architecture, clinical records, version history, audit events, policy decisions, and integration state pass through the Rust service boundary and persist in pinned SurrealDB 3.2.1. The browser remains a focused care workspace while backend services own validation, authorization, and longitudinal record integrity.
Inspect code-versioned C4/UML diagrams, security boundaries, protocol maturity, Lean verification, deployment gaps, and Codex/Claude Co-work installation.
React, TypeScript and TanStack Start are hosted through Lovable behind HTTPS. Patient context stays in memory; the signed ProvidEHR session token is tab-scoped rather than a clinical database in the browser.
A versioned Rust API owns clinical validation, openEHR-compatible records, FHIR projections, AQL, consent, staged writes, attestation, provenance, audit, MCP, and integration policy. Production backend deployment remains gated.
SurrealDB 3.2.1 is pinned by image digest for the evidence environment. RocksDB-backed version, contribution, composition, and audit records are exercised across export, clean import, database restart, and reconciliation.
Record-authenticated, generation-fenced runtime identities are separate from an offline schema-maintenance controller and image. Runtime startup rejects owner-style, legacy, stale, malformed, or incomplete authority configuration.
EHR work uses tenant/cell-bound outbox state, compare-and-swap leases with stale-worker fencing, and mounted credential files in a separate worker. COSMIC connectivity is credential-gated and activated through the security and live-sandbox acceptance process.
Implemented and locally exercised · deployment evidence gated
Current boundary: The runtime-authority split and credential cutover code are implemented and exercised locally. This does not yet establish deployed production cutover, complete application-query isolation across every clinical path, managed KMS/secrets, network and container-platform enforcement, Lean-to-Rust refinement, HA/DR, or regulated-PHI readiness.
Implemented national-scale assurance machinery and the exact target it is designed to test.
Production-equivalent execution and independent review required before regional or population-scale readiness can be claimed.
ProvidEHR is designed to feel calm and focused for clinicians, while giving organizations a durable foundation built around openEHR principles.
Create and open patient charts with the basics clinicians expect: name, date of birth, sex, timeline, vitals, and clinical context.
Capture clinical information in structured, template-driven records designed for reuse, validation, search, and interoperability.
Represent longitudinal plans, assigned activities, patient-reported completion, clinician verification, and escalation state as first-class record data.
View a patient's story through a clear clinical timeline instead of digging through disconnected screens.
Support version-aware clinical updates with reviewable history and audit trails.
Keep demographics, problems, allergies, medications, diagnostic results, service requests, encounters, and notes as structured projections with provenance.
Make source conflicts visible, preview canonical medication state, and keep prescribing, eRx transmission, interaction signals, and clinician review version-bound.
Bind access to tenant, cell, role, purpose, consent, break-glass, proxy, revocation, disclosure, and PHI-safe audit evidence.
Project the record through FHIR R4/R5 summaries, SMART launch, NDJSON export, openEHR-compatible templates and supported AQL queries.
Use governed value sets, validate-code, deterministic ICD/LOINC/SNOMED/OMOP crosswalks, and connector contracts for regional and national exchange.
Provide bounded patient/proxy views, companion and voice workflows, delegated MCP/A2A tasks, and source-cited AI drafts without autonomous authoritative writes.
Scheduling, ADT, inpatient, emergency, surgery, nursing, pharmacy, radiology, pathology, blood bank, monitoring, supply chain, and billing worklists are now available as governed product slices; durable integrations remain queued.
SITHS/BankID, NPÖ, 1177, LabPortalen, quality and vaccination registries, ONC/Inferno evidence, live regional credentials, independent clinical validation, and national-scale production proof remain external gates.
Emit bounded request and trace correlation plus route-template completion evidence without exporting raw paths, identities, credentials, or clinical payloads.
Coordinate scheduling, referrals, ADT, ED, procedures, nursing, diagnostics, pharmacy, and revenue worklists with explicit ownership and human decision gates.
Model Swedish public care, US private delivery, and hybrid networks with tenant, identity, payer, policy-pack, and regional integration boundaries.
Keep offline-safe drafts and queued actions replay-safe, then reconcile conflicts explicitly before they become authoritative clinical data.
Typed capabilities, source citations, uncertainty, bounded delegation, and clinician gates keep AI assistance useful without autonomous clinical writes.
Track source mappings, connector contracts, readiness bundles, rehearsal evidence, owners, and activation gates for each deployment.
Coordinate source-bound clinician and agent work around a shared question, preserving participants, proposals, and the final human decision.
ProvidEHR treats the CarePlan as a first-class object: versioned, queryable, auditable, patient-visible where appropriate, and available to Rounds, Triager, MCP tools, and external EHR connectors.
The first production-grade template is breast reconstruction, but the model is pathway-based: a clinic can define phases, activities, instructions, questionnaires, rules, required photos, verification points, and record outputs.
Breast reconstruction, spine surgery, dermatology procedures and other reusable protocols.
The actual plan assigned to one patient with dates, status, team ownership and visibility rules.
Pre-op preparation, wound care, diet, medication, measurements, photos and follow-up steps.
Patient answers, structured screeners, symptoms, biomarkers, diet logs and recovery signals.
Triager supports the patient. Rounds supports the clinician. ProvidEHR records the structured clinical workflow and exposes it safely to authorized apps, agents, and integrations.
Patient-facing voice intake, symptom review, photo capture and CarePlan checklist confirmation. It gathers structured evidence without making autonomous clinical decisions.
Clinician-facing queue, case view and CarePlan compliance surface. It helps the team see what happened, what is late, what needs review and what should escalate.
The structured record substrate: CarePlans, Rounds cases, patient-reported activity events, audit trails, delegated agent access and external EHR synchronization.
When a clinic already has an EHR, ProvidEHR can run as a governed workflow and data layer while orders and treatment decisions remain in the connected source-of-truth system.
Deployment boundary: ProvidEHR can become the standalone record for a clinic only when deployed and governed that way. In a clinic with Epic, Cerner, COSMIC, Melior or another existing EHR, ProvidEHR should initially be treated as the CarePlan workflow and integration layer, with clinically decisive writes synchronized or routed according to the clinic's governance model.
ProvidEHR is being designed for AI-assisted clinical workflows where agents can retrieve authorized context, draft documentation, prepare summaries, support care coordination, and leave auditable provenance.
Generate concise, source-aware summaries of the patient chart before a visit.
Surface relevant vitals, problems, medications, allergies, recent timeline events, and care gaps.
Draft encounter notes from structured context for clinician review and approval.
Prepare referral letters and discharge summaries using patient context and source-linked evidence.
Turn a patient's clinical timeline into understandable summaries and change highlights.
Draft patient-friendly explanations and follow-up messages for review.
Suggest documentation gaps and coding candidates for human review.
Help clinicians review medication lists, allergy history, and relevant clinical context.
Human review stays at the center: agents can summarize, draft, validate, and coordinate — but clinical writes and disclosures require explicit clinician approval.
Every capability is a typed, policy-aware link — discoverable and composable across agents, surfaces, and people. ProvidEHR speaks MCP, A2A, A2P and A2UI, plus a traditional point-and-click workspace, and routes them all through the same kernel.
Model Context Protocol exposes safe, permissioned clinical tools and resources — summaries, timeline, vitals, CarePlans, Rounds — that any assistant can read and act on.
A signed Agent Card lets trusted healthcare agents discover skills and delegate work: referrals, prior-auth support, handovers, document preparation.
Mandate-based agent payments: a user agent — e.g. from InVivo — can pay for labs, services and referrals on a person's behalf, authorized by signed Intent and Cart mandates with a non-repudiable audit trail. Payment-agnostic, card to stablecoin.
Agents render native, governed UI — confirmations, forms, results — across platforms without shipping arbitrary code. The payload is affordances, not bytes.
A familiar clinician workspace for charts, CarePlans, Rounds, attestation, and audit — every action governed by the same kernel as the agent paths.
Aligned with the Hyperactive Web protocols — discovery (A2A), tools (MCP), surfaces (A2UI), payments (A2P / Google AP2), and capability links as the connective tissue.
A focused stack chosen for performance, structure, and longevity — so clinicians get a calm UX and engineers get a durable platform.