commvita
Connected care platform
POPULATION PLATFORM

Patient Portal

The person’s own way into their record — appointments, medications, results, communication needs, proxy access and research transparency — with the two access controls that are demonstrated rather than enforcing named on the face of this document.

First to market
The person can download their own record as a structured file, and the download is logged. A standards-based personal health record bundle under the data portability right, with every download written to the processing-activity audit. No patient portal we assessed provides it. Preventive nudges come off the live disease register, and a declined nudge records the reason for clinical audit.From commvita’s own assessment of this module against the systems it competes with. Our assessment, not an independent one.
Live vs demonstrated: Live — real, API-backed platform logic (wired end-to-end today) Demonstrated — representative control surface with seeded data / illustrative UI mock-up

1What the portal is

The patient portal is the person’s own way into their record and into the services around it. It’s separately authenticated — a portal session isn’t a staff session and carries none of a staff account’s reach — and it is jurisdiction-branded, so it wears the health system’s identity, its colours and its identifier label, with commvita™ named as the platform underneath instead of over the top.

Fifteen tabs, grouped by what a person came to doLook after todayAppointments — book, reschedule, cancelMedications and repeat requestsMessages to and from the practiceTest resultsCare plan and open tasksLook after myselfMy goals — weight, BP, exercise, smokingPreventive nudges — book, defer or declineVaccinations and certificateMaternity and baby — the digital red bookSpecialist services — physiotherapy, eye healthBe treated properlyCommunication needs and reasonable adjustmentsFamily history, self-declared and non-genomicLinked accounts — proxy and carer accessData and privacyFeedbackJurisdiction-branded: the portal wears the health system’s own identity and identifier label, with commvita™ as the platform underneath.
Fifteen tabs, but a person doesn’t think in tabs. They arrive to do one of three things: deal with today, look after themselves, or be treated properly — and the last group is the one most portals leave out.

2Dealing with today

Appointments can be booked against real slots, rescheduled and cancelled; a repeat prescription can be requested against a specific medication with a note; messages go to and from the practice; test results, the care plan and its open tasks are readable. An appointment request that has no bookable slot becomes a request instead of a dead end.

Alongside that sit preventive nudges — a vaccination due, a screening invitation, an annual review, a medication review. Each carries three answers, not one: book it, remind me later, or decline with a reason. The reason matters: a decline recorded with its reason is clinical information, and a decline recorded as silence is a person who looks like they were never asked.

3Being treated properly

A declared communication need becomes a constraint on every letterThe person declaresLarge print · easy read · braille · BritishSign Language interpreter · a supporterpresent · extra time.Declared in the portal, or recorded bystaff.It becomes a required formatHeld once, on the person — not per letter,per service or per system.Surfaced to staff as a banner, not buriedin a note.Every outbound letter must honour itThe elective experience standards make thismeasurable: an appointment letter in a format theperson can’t read is a breach, not a near miss.So the portal declaration and the compliance figureread the same record.The point of self-declaration is that the person shouldn’t have to ask five services separately, and then again next year.
Held once, on the person. A communication need declared in the portal is the same record the elective experience standards measure compliance against, so the two can’t disagree.

The portal also carries a self-declared family history — “my mother had breast cancer” — which can open earlier screening. It is explicitly non-genomic, and that separation is deliberate: collapsing a family-history statement into genomic data would drag the heaviest consent regime on the platform onto a screening reminder, for no benefit to anyone.

Proxy and carer access, in both directionsAccounts I can reachA parent for a child under an age threshold.An adult child acting for a parent.An appointed carer, or a lasting power ofattorney.Each shown with the relationship it rests on.Who can reach mineThe same list from the other side — because aproxy arrangement the subject can’t see isn’tconsent, it’s an administrative fact about them.Revocable by the person, with a confirmationnaming who loses access.Why both directions matterA one-sided proxy register answers the carer’squestion and not the patient’s.Transparency under Article 15 is about what theperson can see, not what the service canproduce on request.
A proxy arrangement the subject can’t see isn’t consent — it’s an administrative fact about them. So the register is readable from both sides and revocable from the subject’s.

4Research participation

Secondary use of health data is the thing patients are least often told about and most often surprised by. The portal names each study the person’s pseudonymised or anonymised data feeds into, with the organisation, the lead researcher, the approval reference, the data categories used, the anonymisation applied and the lawful basis — and it says, per study, whether opting out is possible at all, because for a fully anonymised dataset it often isn’t.

Where nothing is recorded for that person, the population transparency list is shown instead of an empty page — an empty page would imply no research is happening, which is a stronger claim than the absence of a row supports.

Research participation — shown honestly, and the opt-out is recorded and honouredLive — what the person is shownEach study their pseudonymised or anonymised data feeds into, by name.The organisation, the lead researcher and the approval reference.Which data categories are used, and the anonymisation applied.The lawful basis, and whether opting out is possible for that study.Where nothing is recorded for this person, the population transparency list isshown instead — not an empty page implying no research.Live — the opt-out, recorded and honouredThe per-study opt-out writes that person’s own participation. A study usingirreversibly anonymised data is REFUSED with the reason, because the datacan’t be linked back — not shown as left.The secondary-use objection writes the same consent record the clinicianreads, and is CHECKED before any person enters a statutorily-authorisedresearch extract. The number excluded is reported with the extract ratherthan dropped silently.Scope follows the HRA rule: it governs s251-authorised use, not a study theperson consented to join, nor anonymised information.The scheme NAME is resolved per jurisdiction and fails safe to nothing —'National Data Opt-out' is England’s and is never shown to a patient anothercountry’s law governs. Where none is configured the choice is still offered,described as recorded and honoured here.
The transparency half is live and genuinely better than most. The control half is now recorded AND honoured, which is the harder half and the one that matters.

Saving the choice isn’t the same as acting on it, so we do both. When somebody objects, they’re taken out of research extracts before those extracts are produced — and the number of people left out is reported with the extract, so nobody mistakes a smaller cohort for a smaller population. What it does not do is on the screen too: it doesn’t affect your day-to-day care, it doesn’t withdraw you from a study you separately agreed to join, and it can’t recall data already shared.

5Who has seen my record?

This is one question in ordinary language and three different questions in a health record system, and conflating them is how a portal comes to claim transparency it doesn’t deliver.

Three different questions about access — and commvita answers them in three different places“What have I done in the portal?”LIVEThe Portal Activity Log — the person’s ownactions, from the audit trail.Honestly labelled. It isn’t, and doesn’t claimto be, a record of who read the file.“Who have I let in?”DEMONSTRATEDA list of granted access, with an organisation, anaccess type and an expiry, and a revoke action.Not yet kept permanently, so treat it as a previewinstead of a record.Revoking removes the row. It does NOT restrict aclinician — staff access is governed by role andorganisation scope, not by this list.“Who has actually read my record?”IN THE PORTALThis exists — every access carries alegitimate-relationship justification andanomalous patterns are flagged.It’s a staff and information-governance surface,and the person-facing version is produced as asubject-access response.It’s now shown in the Data & Privacy tab.
The product labels its activity log honestly as a Portal Activity Log. This document doesn’t re-label it as an access log, because the two aren’t the same thing and a patient reading a marketing page wouldn’t know the difference.

Where the real access record lives. Every staff access to a record carries a legitimate relationship justification, anomalous patterns — out-of-area, bulk, cross-organisation — are flagged for investigation, and the log is append-only and hash-chained so it’s tamper-evident. A person can challenge a justification, and a per-person Article 15 view can be produced. All of that’s real. None of it’s currently a tab in the portal, and closing that gap is a wiring job, not a build.

6How this sits with the NHS App

The NHS App stays the national front door; commvita makes the room behind it deeper — same login, richer content, and the ability to act.

Same identity, no new login

commvita authenticates with NHS Login (OIDC) — the same identity the NHS App uses — and integrates through the NHS App API (appointments, prescriptions, records, messages, notifications), so the person isn’t asked to learn a second account.

NHS Login OIDC/nhs-app

From read-and-notify to act-and-book

Where the national baseline mostly shows and notifies, commvita lets the person book from a nudge, request PIFU, submit PROMs and raise an urgent review — write-back and action, not just a view.

Book · PIFU · PROMs/portal/rapid-review

One record across settings

commvita carries a cross-setting record — GP, hospital, community, mental health, social care and pharmacy — so what the person sees isn’t only their GP record but their whole journey, with the source of each entry shown.

Whole-person recordFHIR R4 · shared care

7Where it lives, and its honest edges

FunctionEndpointStatus
Sign in, profile, care plan, medications, test results /portal/auth, /me, /care-plan, /medications, /test-results Live
Appointments — book against real slots, reschedule, cancel, request /portal/appointments, /available-slots, /appointment-requestLive
Messages and repeat prescription requests /portal/messages, /repeat-request Live
Preventive nudges — book, defer, decline with reason /portal/nudges + three actions Live
Communication needs and reasonable adjustments /portal/comm-needsLive
Self-declared family history (non-genomic) /portal/family-historyLive
Vaccinations, read from the immunisation spine /portal/vaccinationsLive
Research participation — transparency view/portal/research Live
Per-study opt-out — persisted, anonymised studies refused with the reason /portal/research/{id}/opt-out Live
Secondary-use objection — persisted and honoured in research extracts /portal/data-choices Live
Portal activity log (the person’s own actions) /portal/access-logLive
Granted access list — held in memory, doesn’t gate staff access /portal/record-accessDemonstrated
Who has read my record — shown to the person in the Data & Privacy tab, drawn from their own record /portal/who-accessed-my-recordLive
Care feed for family and carers/portal/care-feed Live
Rapid review — patient- or family-initiated escalation /portal/rapid-reviewLive
Patient transport request · firearms medical request /portal/patient-transport/request, /firearms-request Live
Data portability export — the person’s own record; empty categories named /portal/fhir-exportLive
Maternity and baby · specialist services · goals · linked accounts Demonstrated

Download a copy of your record. You get your own conditions, medications, vaccinations and test results, in a standard format other systems can read. If we hold nothing under a heading, the download says so and leaves it out — we never put an example in its place, because a made-up line in a medical record is worse than a gap.

The “who can see my record” list is a view, not a switch. It shows you who has access. Removing an entry takes it off your list; it doesn’t change what a member of staff can open, which is set by their role and their organisation. We say that plainly instead of offer a button that looks like it does more than it does. Making it a real control is planned and is not built yet.

What the portal isn’t. It isn’t a clinical decision-support tool and carries no medical-device claim. It doesn’t diagnose, triage or advise. A nudge is an invitation, not an instruction, and every clinical action it can start — a booking, a repeat request, a rapid review — lands on a human being.

Routes: /portal (patient) · /patient-portal (staff) · API: /portal, separately authenticatedStandards: UK GDPR Art.15 · Art.20 · Accessible Information Standard DCB1605 · NHS Reasonable Adjustment Flag · Non-SaMD
© 2026 Commvita Digital Health Solutions Ltd. All rights reserved.