commvita
Connected care platform
Digital consent

Digital consent — direct care, research, genomics and proxy access, one lifecycle

One lifecycle for every kind of consent an organisation holds: consent to treatment taken on a tablet, in the portal or spoken and witnessed; capacity assessed the way the Mental Capacity Act sets it out; research opt-out study by study; genomic consent answered element by element and withdrawn in one tap; and the list of people a person has said may see their record. Withdrawal is as easy as giving, because Article 7 says it has to be. Staff side at /consent-hub, patient side at /portal.

Live vs demonstrated: Live — real, API-backed platform logic (wired end-to-end today) Demonstrated — representative control surface with seeded data / illustrative UI mock-up
© 2026 Commvita Digital Health Solutions Ltd. All rights reserved.

1 Consent turns up in four different forms

Most organisations hold consent in four places. A paper form in a folder. A research opt-out in a governance spreadsheet. A genomic form scanned into a shared drive. A note saying a daughter can be told things. Four owners, and no way to answer the question that matters: what has this person agreed to today, and what have they taken back?

Ahead of the field
The person changes their own choices, and the change lands where the clinical team can see it. The portal is where somebody sees what their data is used for and turns a study, a genomic element or a national objection off. The decision, including a refusal, lands in the governance trail rather than in a phone call somebody has to remember. In the patient-facing products we assessed, the record of what somebody chose sits apart from the clinical record and gets reconciled by hand.From commvita’s own competitive assessment of the patient portal against the systems it competes with. Our assessment, not an independent one.

Consent Hub is one lifecycle over all four: ask, record, evidence, withdraw. Staff side at /consent-hub, the person’s own side in the portal at /portal, both writing to the same record. Build them as four modules and you get four different answers to “has this been withdrawn?”, which is how organisations end up using data somebody objected to two years ago and hearing about it in a complaint.

Consent to treatment

Tablet · portal · verbal, witnessed

A versioned template with numbered elements, a capacity flag where the law needs one, and three ways to confirm. The record says which it was.

Research and secondary use

Per study · national objection

The person sees the studies their data feeds and leaves any one of them. Separately they can object to secondary use under statutory authorisation.

Genomic consent, and proxy access

Element by element · who may see my record

Genomic consent isn’t one yes but six questions, each answerable and withdrawable on its own. Beside it, the people a person has said may see their record.

2 Asking: the queue, the tablet, the portal, the spoken word

A consent request is a job of work. It sits in a queue with the patient, the template, the method and how long it has waited, and turns red past a day. From there you hand the device over, send it to the portal, record a verbal consent, or mark it declined.

The In-Person Signing screen in tablet mode for a community nursing treatment consent, version 2.1: a Mental Capacity Act 2005 capacity check ticked, the full consent wording, four elements to tick of which three are marked required, three ways to confirm, and a signature drawn on screen with the I Consent button held disabled until the required elements are ticked
Consent Hub · In-Person SigningCaptured from the running system, build B-591 · seeded data
1

Sign on the screen

Finger or stylus, on a phone in a front room as well as a desk. The strokes are captured as vector paths, so the mark stays crisp at any size.

2

Tap to confirm

For people who can’t draw or would rather not. The record stores a tap confirmation, never a signature.

3

Verbal, witnessed

Spoken consent needs a named witness and their role before it saves. That’s what makes it evidence instead of an assertion.

4

Or send it to the portal

The person completes it themselves, and the request expires after 48 hours instead of sitting open forever.

Two things then happen with no extra work: the decision joins the patient’s communications timeline, and the consent is registered in the central signature registry with a content hash and the patient it belongs to, so every signature the organisation holds is countable in one place.

3 Capacity, done as the Act sets it out

A consent from somebody who lacks capacity for that decision isn’t a consent. The Mental Capacity Act 2005 sets a two-stage test, decision by decision and moment by moment, starting from the presumption of capacity.

The Capacity Assessment surface for a named decision, consent to insertion of a urinary catheter: Stage 1 diagnostic test answered yes, Stage 2 functional test with understand yes, retain no, weigh no, communicate yes, an outcome banner reading lacks capacity for this specific decision with a prompt to consider an IMCA, and a Best Interests Decision panel under MCA 2005 Section 4 asking who decided, who was consulted, what was decided and why
Consent Hub · Capacity AssessmentCaptured from the running system, build B-591 · demonstrated surface

The form follows the statute. Stage one asks whether there’s an impairment of, or disturbance in the functioning of, the mind or brain. If not, capacity is presumed and the assessment stops. If there is, stage two asks the four functional questions and the outcome is computed, not typed in. Where capacity is absent, a best interests panel opens under Section 4: who decides, who was consulted, what was decided, and why.

Where the ceiling is, plainly. This tab is a demonstrated surface. It walks the statutory test and computes the outcome, but pressing save keeps the assessment on the screen and doesn’t write it to the record. The stored capacity assessments live in the Court of Protection module at /court-of-protection, which is API-backed, refuses an assessment not bound to a real person and a named decision, and ignores any outcome somebody types in. Joining the two is small work, and it isn’t done. The capacity check inside signing is enforced: a template that needs one can’t be completed until the clinician confirms capacity for that procedure at that time.

4 Templates, and the conversation before the signature

A template is versioned, categorised and made of elements, each marked required or optional. It carries a minimum age, the jurisdiction it was written for, and whether a capacity check is needed. Deactivating one stops it being used from now on, without touching consents already taken under it.

The Decision Aids tab showing six NICE-aligned patient decision aids in a list, with the atrial fibrillation aid open: three options for reducing stroke risk set out as benefits against risks and harms, a Montgomery material-risk note about weighing individual stroke risk against bleeding risk, and three what-matters-to-you questions
Consent Hub · Decision AidsCaptured from the running system, build B-591 · seeded library

Montgomery changed what informed consent means here: the test is no longer what a body of doctors would disclose, it’s what this person would want to know before deciding. So the module carries decision aids — options side by side with benefits and harms, the material risk in plain words, and the questions that help somebody work out what matters to them. Six are seeded, following NICE guidance on anticoagulation, knee osteoarthritis, statins, prostate cancer, type 2 diabetes and depression.

Rated honestly. The library is a demonstrated surface and the screen says so itself: seeded content instead of a maintained clinical library, and the individualised numbers a real aid needs, a person’s own stroke or cardiovascular risk, aren’t wired here. Attaching an aid to a consent request is described on screen and isn’t built. The template library beside it’s fully API-backed.

5 Withdrawal, and what the record keeps

Article 7(3) of the UK GDPR says withdrawing consent must be as easy as giving it. That’s a design instruction and the module treats it as one. If giving takes one tap and withdrawing takes a phone call, a form and a fortnight, the organisation has failed the test while looking careful.

The Consent Records register with four signed consents: hand-signed on a tablet, verbal plus witnessed, tap confirmed, and portal PIN verified, each with the patient, NHS number, template, date and time signed, validity end date or indefinite, an active status and a Withdraw action on every row
Consent Hub · Consent RecordsCaptured from the running system, build B-591 · seeded data

Every record carries a Withdraw action. It asks for a reason, takes effect immediately, and updates the row instead of deleting it, so the withdrawal sits on the record showing consent was given. That pair is what an audit needs; a deleted row reads as though the person never consented, which is untrue. The withdrawal lands on the communications timeline in the same breath, marked under Article 7.

Analytics answers the operational question beside it: requests by status, method and template, the consent rate, anything pending more than a day. An IG lead sees not that consent exists as a policy, but that a third of requests became a consent this month and two are overdue.

6 The person’s own side: research, study by study

Secondary use is where consent goes vague in most systems: one buried toggle labelled “research” with nothing behind it. The portal names the studies, says who runs each, and lets the person leave one without leaving the rest.

The patient portal research transparency list on a phone: three named studies with the organisation running each one and whether the data is pseudoanonymised or anonymised; the pseudoanonymised study offers I don’t want my data used for this, the anonymised study offers no opt-out button at all, and the third study shows you have opted out of this programme with an Undo opt-out action
Patient Portal · My data and researchCaptured from the running system, build B-591 · seeded data

The middle card offers no way out, and that’s the honest answer instead of a missing button: a study on irreversibly anonymised data can’t link anything back to the person, so there’s nothing to remove, and accepting the request while doing nothing would be a lie told politely. The two either side are pseudonymised, so leaving takes one tap and so does rejoining.

Underneath sits the wider objection to secondary use, and this is where jurisdiction matters. The scheme is resolved from the person’s jurisdiction profile: in England the National Data Opt-out, cited to the Act and guidance that govern it. Where none is configured the platform names none and says the choice is recorded and honoured here but registered with no national service. Naming England’s scheme to somebody it doesn’t govern is a false statement about their rights. The screen states three limits unprompted: it doesn’t affect direct care, it doesn’t withdraw somebody from a study they agreed to join, and it can’t recall data already shared.

7 Genomic consent: six questions, six answers, six withdrawals

Genomic consent is where a single yes does the most damage. Agreeing to a test isn’t agreeing to be told about unexpected findings, nor that relatives may be approached, nor that the sample is kept for research. So they’re separate questions.

The patient portal genomic consent card: a clinical testing consent dated 28 May 2026 marked signed by you, six elements each shown with the person’s own answer — unexpected findings, relatives approached, sharing with the national genomic service, long-term sample storage, research use and biobank — a single Withdraw this consent button, and three statements of what commvita does not do, including that it does not assess capacity
Patient Portal · Your genomic testing consentCaptured from the running system, build B-591 · seeded data

The asymmetry is the design. Giving consent in the portal runs a signature ceremony: a one-time code is sent, the person enters it, and the signature is bound to that consent and nothing else. Withdrawing needs no code, no reason and no signature, just one button. An element nobody answered stays unanswered instead of defaulting to no, because “declined” and “not asked” are different findings. A withdrawn consent stays visible, since hiding it would leave somebody unable to see that they once consented and no longer do.

The same register carries consents obtained in conversation and attested by the clinician’s own signature, and consents held on paper — recorded by form reference and who holds the original, because the platform has no document store and won’t pretend to. It shows which route each consent came by, so nobody mistakes an attestation for the patient’s own signature. The workflow won’t offer to submit a referral while consent is anything other than obtained.

What withdrawal can’t do, said on the screen. It stops further use from that moment. It can’t recall a result already shared, or un-tell a relative already approached. The portal says so in those words instead of implying a clean undo.

8 Proxy and record access — and the honest limit

The portal holds the list of people a person has said may see their record: a GP practice with contribute rights, a community nurse with view rights expiring after a year, a pharmacy. Grants carry an expiry, can be revoked at any time, and each grant or revocation writes an audit entry naming the patient as the actor.

Here is the limit, which I would rather write than have a Caldicott Guardian find in a demonstration: the list doesn’t gate what staff can see. Clinical access is decided by role-based access control and organisation scope. It’s a demonstrated surface: it shows a person what has been granted and lets them revoke it, with the enforcement path still to be joined. Where consent does gate something today it gates it end to end: an objection to secondary use is checked before a row of a research extract is built, and a genomic referral won’t move without a live consent.

Where it lives in commvita

CapabilityRouteModel / APIStatus
Pending consent queue · portal send, verbal, decline/consent-hubAPI /consent/requests · /send-portal (48h expiry)● Live
In-person signing · drawn, tap, verbal witnessed/consent-hubAPI /consent/requests/{id}/sign · vector signature · registered in commvita Sign● Live
Template library · versions, elements, capacity flag/consent-hubAPI /consent/templates · create, update, deactivate● Live
Consent records and withdrawal/consent-hubAPI /consent/records · /withdraw (Art.7(3)) · comms timeline● Live
Consent analytics · rate, method, template, overdue/consent-hubAPI /consent/analytics● Live
Capacity assessment (MCA two-stage)/consent-hubScreen holds the assessment; the stored record lives at /court-of-protection☉ Demonstrated
Decision aids (Montgomery)/consent-hubSeeded NICE-aligned library; no attach-to-request path☉ Demonstrated
Research opt-out, study by study/portalAPI /portal/research · /portal/research/{id}/opt-out · refuses anonymised studies● Live
Secondary-use objection · scheme named by jurisdiction/portalAPI /portal/data-choices · honoured on the research extract path · audited● Live
Genomic consent and withdrawal/portal · /genomicsAPI /portal/genomic-consent · one-time-code ceremony · withdrawal without ceremony● Live
Record-access grants and revocation/portalAPI /portal/record-access · audited — doesn’t gate staff access☉ Demonstrated
Two things it isn’t. It isn’t a document store: commvita records that a paper consent exists and who holds it instead of keeping a scan it can’t protect. It isn’t an identity service: the signature ceremony proves the account holder approved this specific thing, not that they’re who they claimed to be at registration. It isn’t a substitute for the conversation, and the genomic screen tells the patient so. It carries no medical-device claim: all of it’s decision support and record-keeping, and a named clinician decides.
© 2026 Commvita Digital Health Solutions Ltd. All rights reserved. Mental Capacity Act 2005 · Code of PracticeMontgomery v Lanarkshire Health Board UK GDPR Art.6, Art.7(3), Art.9NHS Genomic Medicine Service consent policy National Data Opt-out · HRA guidanceNICE patient decision aids Non-SaMD