ProvidEHR
Technical platform · prevention + longitudinal EHR foundation

A clinical platform engineered for national-scale validation.

ProvidEHR combines a population-prevention operating system with an extensible longitudinal general-EHR foundation. The React/TanStack frontend is live. Separately, the repository implements and locally exercises Rust services that connect an application to a persistent SurrealDB/RocksDB record plane, versioned openEHR-compatible records, FHIR projections, consent, provenance, audit, InVivo patient follow-through, and governed Codex and Claude co-work. No production backend deployment, HA, DR, or cutover is claimed.

Current readiness

Live frontend · implemented and locally exercised Rust data plane · production backend rollout gated

In the implemented architecture, clinical records, version history, audit events, policy decisions, and integration state pass through the Rust service boundary and persist in pinned SurrealDB 3.2.1. The browser remains a focused care workspace while backend services own validation, authorization, and longitudinal record integrity.

Need the engineering evidence?

Inspect code-versioned C4/UML diagrams, security boundaries, protocol maturity, Lean verification, deployment gaps, and Codex/Claude Co-work installation.

Developer center
Live frontend

Web application and HTTPS edge

React, TypeScript and TanStack Start are hosted through Lovable behind HTTPS. Patient context stays in memory; the signed ProvidEHR session token is tab-scoped rather than a clinical database in the browser.

Implemented · locally exercised

Rust clinical services

A versioned Rust API owns clinical validation, openEHR-compatible records, FHIR projections, AQL, consent, staged writes, attestation, provenance, audit, MCP, and integration policy. Production backend deployment remains gated.

Implemented · locally exercised

Persistent clinical store

SurrealDB 3.2.1 is pinned by image digest for the evidence environment. RocksDB-backed version, contribution, composition, and audit records are exercised across export, clean import, database restart, and reconciliation.

Implemented · fail closed

Runtime authority and schema controller

Record-authenticated, generation-fenced runtime identities are separate from an offline schema-maintenance controller and image. Runtime startup rejects owner-style, legacy, stale, malformed, or incomplete authority configuration.

Implemented · controlled activation

Isolated integration workers

EHR work uses tenant/cell-bound outbox state, compare-and-swap leases with stale-worker fencing, and mounted credential files in a separate worker. COSMIC connectivity is credential-gated and activated through the security and live-sandbox acceptance process.

Runtime authority and schema-control separation

Clinical runtime access and schema authority are separate by construction.

Implemented and locally exercised · deployment evidence gated

  • The API and worker use a SurrealDB record-authenticated runtime principal; owner-style and legacy runtime credentials fail closed.
  • Every runtime identity carries an explicit authority generation, and stale-generation sessions are rejected during verification.
  • Validated TenantId, CellId and DataScope values are immutable for the process lifetime; readiness, SMART configuration, audit, outbox and durable-state keys preserve that server-selected scope.
  • A separate offline schema-maintenance controller and container image owns prepare, provision, verify, and runtime-authority verification; the runtime API and worker images do not carry that authority path.
  • Runtime startup rejects malformed, linked, permissive, direct-value, legacy, or incomplete credential configuration before clinical traffic is accepted.

Current boundary: The runtime-authority split and credential cutover code are implemented and exercised locally. This does not yet establish deployed production cutover, complete application-query isolation across every clinical path, managed KMS/secrets, network and container-platform enforcement, Lean-to-Rust refinement, HA/DR, or regulated-PHI readiness.

National-scale validation harness

Implemented national-scale assurance machinery and the exact target it is designed to test.

  • Exact target profile: 10,000,000 de-identified synthetic patients
  • Target partitioning: 20 isolated deployment cells with 500,000 deterministic identities per cell
  • Constant-memory corpus generation and count/digest/duplicate reconciliation
  • Guarded local or explicit remote workload execution with PHI-free evidence manifests
  • Small local synthetic workflow exercise completed; no production-equivalent 10M result claimed

Evidence required for a 10M claim

Production-equivalent execution and independent review required before regional or population-scale readiness can be claimed.

  • Production-equivalent multi-cell environment and distributed load generators
  • Sustained soak, capacity headroom, N+1 and degraded-dependency execution
  • Restart, restore, vendor-failure and data-corruption reconciliation campaign
  • Load-balanced stateless APIs, durable shared state and clustered/managed storage failover
  • Independent method review, benchmark execution and signed evidence decision

Implemented and locally exercised

  • Live HTTPS React/TanStack frontend plus locked Rust API, worker and SurrealDB 3.2.1 builds
  • Versioned clinical records, provenance, audit and bounded server-side access indexes
  • Generation-fenced runtime database principal plus a separate offline schema-maintenance path
  • Release export, clean isolated import, database restart and record-count recovery rehearsal
  • Explicit tenant/cell scope across readiness, SMART configuration, audit, outbox and in-memory durable state
  • Durable integration claims with bounded leases, monotonic fencing, digest-only capabilities and orphan recovery
  • Versioned red-team and exact 10M/20-cell scale-assurance harnesses, including local verifier and synthetic exercise evidence

Implemented, activation gated

  • Signed session, membership, tenant/scope and forged-header controls pass local tests, but public REST remains in compatibility audit mode until a real Google sign-in is verified
  • Runtime database credential cutover is implemented in code; deployed secret/KMS integration, production verification and rollback evidence remain open
  • COSMIC contract code exists, but security findings and credentialed sandbox read/write evidence remain open
  • Clinical co-work uses short-lived, EHR-bound delegation; hosted Codex Work still needs an OAuth/app connector

Required before regulated PHI production

  • Multi-node API/database failover, load tests, autoscaling and tested regional disaster recovery
  • Production-equivalent 10,000,000-patient / 20-cell run, soak, dependency failure, restart/restore, integrity reconciliation and independent benchmark
  • At-rest encryption evidence, managed least-privilege secrets and automated encrypted offsite backups with agreed RPO/RTO
  • Durable delegation state plus atomic inbound clinical commit and integration-event acknowledgement
  • Authenticated distributed abuse control for Realtime token minting
  • Independent penetration test, DPIA/security review, clinical-safety case and applicable regulatory/customer assurance
The product

A clean clinical workspace on top of a structured health record platform.

ProvidEHR is designed to feel calm and focused for clinicians, while giving organizations a durable foundation built around openEHR principles.

IMPLEMENTED

Patient chart

Create and open patient charts with the basics clinicians expect: name, date of birth, sex, timeline, vitals, and clinical context.

View feature details →
IMPLEMENTED

Structured documentation

Capture clinical information in structured, template-driven records designed for reuse, validation, search, and interoperability.

View feature details →
SYNTHETIC-VALIDATED

CarePlan execution

Represent longitudinal plans, assigned activities, patient-reported completion, clinician verification, and escalation state as first-class record data.

View feature details →
IMPLEMENTED

Timeline-first care

View a patient's story through a clear clinical timeline instead of digging through disconnected screens.

View feature details →
IMPLEMENTED

Safer corrections

Support version-aware clinical updates with reviewable history and audit trails.

View feature details →
IMPLEMENTED

Clinical lists and results

Keep demographics, problems, allergies, medications, diagnostic results, service requests, encounters, and notes as structured projections with provenance.

View feature details →
SYNTHETIC-VALIDATED

Medication reconciliation and prescribing

Make source conflicts visible, preview canonical medication state, and keep prescribing, eRx transmission, interaction signals, and clinician review version-bound.

View feature details →
IMPLEMENTED

Identity, consent, and audit

Bind access to tenant, cell, role, purpose, consent, break-glass, proxy, revocation, disclosure, and PHI-safe audit evidence.

View feature details →
SYNTHETIC-VALIDATED

FHIR, SMART, Bulk, openEHR, and AQL

Project the record through FHIR R4/R5 summaries, SMART launch, NDJSON export, openEHR-compatible templates and supported AQL queries.

View feature details →
SYNTHETIC-VALIDATED

Terminology and interoperability

Use governed value sets, validate-code, deterministic ICD/LOINC/SNOMED/OMOP crosswalks, and connector contracts for regional and national exchange.

View feature details →
SYNTHETIC-VALIDATED

Patient, proxy, and agent surfaces

Provide bounded patient/proxy views, companion and voice workflows, delegated MCP/A2A tasks, and source-cited AI drafts without autonomous authoritative writes.

View feature details →
IMPLEMENTED SLICE

Planned full EHR operations

Scheduling, ADT, inpatient, emergency, surgery, nursing, pharmacy, radiology, pathology, blood bank, monitoring, supply chain, and billing worklists are now available as governed product slices; durable integrations remain queued.

View feature details →
EXTERNAL / PLANNED

Planned national-scale trust

SITHS/BankID, NPÖ, 1177, LabPortalen, quality and vaccination registries, ONC/Inferno evidence, live regional credentials, independent clinical validation, and national-scale production proof remain external gates.

View feature details →
IMPLEMENTED SLICE

PHI-safe observability and assurance

Emit bounded request and trace correlation plus route-template completion evidence without exporting raw paths, identities, credentials, or clinical payloads.

View feature details →
IMPLEMENTED SLICE

Hospital operations command center

Coordinate scheduling, referrals, ADT, ED, procedures, nursing, diagnostics, pharmacy, and revenue worklists with explicit ownership and human decision gates.

View feature details →
IMPLEMENTED CONTRACT

Public, private, and hybrid deployment

Model Swedish public care, US private delivery, and hybrid networks with tenant, identity, payer, policy-pack, and regional integration boundaries.

View feature details →
IMPLEMENTED SLICE

Downtime and recovery

Keep offline-safe drafts and queued actions replay-safe, then reconcile conflicts explicitly before they become authoritative clinical data.

View feature details →
IMPLEMENTED POLICY

AI safety and human review

Typed capabilities, source citations, uncertainty, bounded delegation, and clinician gates keep AI assistance useful without autonomous clinical writes.

View feature details →
IMPLEMENTED EVIDENCE PATH

Migration and readiness

Track source mappings, connector contracts, readiness bundles, rehearsal evidence, owners, and activation gates for each deployment.

View feature details →
IMPLEMENTED SLICE

Clinical collaboration rooms

Coordinate source-bound clinician and agent work around a shared question, preserving participants, proposals, and the final human decision.

View feature details →
CarePlan first

CarePlans are not PDFs. They are living clinical workflows.

ProvidEHR treats the CarePlan as a first-class object: versioned, queryable, auditable, patient-visible where appropriate, and available to Rounds, Triager, MCP tools, and external EHR connectors.

FHIR-shaped workflow model

The plan coordinates patient action, team review, evidence, reminders, and escalation.

The first production-grade template is breast reconstruction, but the model is pathway-based: a clinic can define phases, activities, instructions, questionnaires, rules, required photos, verification points, and record outputs.

Patient-reported completion stays distinguishable from clinician verification.
Low-risk checklist updates can be exposed to approved agents through delegated scopes.
Clinical decisions, orders, prescribing and disclosures remain clinician-governed.
PlanDefinitionGeneric pathway template

Breast reconstruction, spine surgery, dermatology procedures and other reusable protocols.

CarePlanPatient-specific plan

The actual plan assigned to one patient with dates, status, team ownership and visibility rules.

TaskChecklist activity

Pre-op preparation, wound care, diet, medication, measurements, photos and follow-up steps.

Questionnaire / ObservationEvidence and measurements

Patient answers, structured screeners, symptoms, biomarkers, diet logs and recovery signals.

Triage, Rounds, ProvidEHR

One care journey, three clearly separated responsibilities.

Triager supports the patient. Rounds supports the clinician. ProvidEHR records the structured clinical workflow and exposes it safely to authorized apps, agents, and integrations.

Triager

Patient-facing voice intake, symptom review, photo capture and CarePlan checklist confirmation. It gathers structured evidence without making autonomous clinical decisions.

Rounds

Clinician-facing queue, case view and CarePlan compliance surface. It helps the team see what happened, what is late, what needs review and what should escalate.

ProvidEHR

The structured record substrate: CarePlans, Rounds cases, patient-reported activity events, audit trails, delegated agent access and external EHR synchronization.

External EHR

When a clinic already has an EHR, ProvidEHR can run as a governed workflow and data layer while orders and treatment decisions remain in the connected source-of-truth system.

Deployment boundary: ProvidEHR can become the standalone record for a clinic only when deployed and governed that way. In a clinic with Epic, Cerner, COSMIC, Melior or another existing EHR, ProvidEHR should initially be treated as the CarePlan workflow and integration layer, with clinically decisive writes synchronized or routed according to the clinic's governance model.

AI-native

AI that works with the record, not around it.

ProvidEHR is being designed for AI-assisted clinical workflows where agents can retrieve authorized context, draft documentation, prepare summaries, support care coordination, and leave auditable provenance.

AI Chart Summary

Generate concise, source-aware summaries of the patient chart before a visit.

Visit Preparation

Surface relevant vitals, problems, medications, allergies, recent timeline events, and care gaps.

Clinical Note Drafting

Draft encounter notes from structured context for clinician review and approval.

Referral & Discharge Drafts

Prepare referral letters and discharge summaries using patient context and source-linked evidence.

Timeline Intelligence

Turn a patient's clinical timeline into understandable summaries and change highlights.

Patient Communication Drafts

Draft patient-friendly explanations and follow-up messages for review.

Coding & Documentation Support

Suggest documentation gaps and coding candidates for human review.

Medication & Allergy Context

Help clinicians review medication lists, allergy history, and relevant clinical context.

Human review stays at the center: agents can summarize, draft, validate, and coordinate — but clinical writes and disclosures require explicit clinician approval.

Many interfaces, one governed record

Built for the Hyperactive Web.

Every capability is a typed, policy-aware link — discoverable and composable across agents, surfaces, and people. ProvidEHR speaks MCP, A2A, A2P and A2UI, plus a traditional point-and-click workspace, and routes them all through the same kernel.

MCP
A2A
A2P
A2UI
UI
Governance kernel
staging → attestation → promotion · autonomy tiers A0–A3 · fail-closed
openEHR-canonical record · append-only · signed provenance · FHIR projection
MCP

Tools & resources

Model Context Protocol exposes safe, permissioned clinical tools and resources — summaries, timeline, vitals, CarePlans, Rounds — that any assistant can read and act on.

A2A

Agent discovery & delegation

A signed Agent Card lets trusted healthcare agents discover skills and delegate work: referrals, prior-auth support, handovers, document preparation.

A2P

Agent-to-Payment (AP2)

Mandate-based agent payments: a user agent — e.g. from InVivo — can pay for labs, services and referrals on a person's behalf, authorized by signed Intent and Cart mandates with a non-repudiable audit trail. Payment-agnostic, card to stablecoin.

A2UI

Safe agent-generated surfaces

Agents render native, governed UI — confirmations, forms, results — across platforms without shipping arbitrary code. The payload is affordances, not bytes.

UI

Traditional point-and-click

A familiar clinician workspace for charts, CarePlans, Rounds, attestation, and audit — every action governed by the same kernel as the agent paths.

Aligned with the Hyperactive Web protocols — discovery (A2A), tools (MCP), surfaces (A2UI), payments (A2P / Google AP2), and capability links as the connective tissue.

Architecture

Modern infrastructure beneath a simple clinical experience.

A focused stack chosen for performance, structure, and longevity — so clinicians get a calm UX and engineers get a durable platform.

Clinician Workspace
React · TypeScript · Tailwind
AI Assistants & Agents
Drafts, summaries, coordination
Agent Gateway
MCP · A2A · permissioned tools
openEHR-Compatible Clinical Services
Rust services · structured models
SurrealDB Clinical Data Store
Versioned, queryable clinical data