commvitaConnected care platform
Research, innovation & data rights

Accelerating research while protecting citizen rights.

Finding groups of patients, real extracts with a data-quality report, a log that can’t be altered — and a plain account of which controls for citizens actually work today.

The cycle

Accelerating research while protecting citizen rights

Care generates evidence and evidence changes care. The loop only works if the person at the start of it can see where their data went and stop it.

The research and discovery cycleA five-stage loop — clinical care, population health, research, discovery, improved care — with genomics running through every stage.Clinical carePopulation healthResearchDiscoveryImproved careGenomicsruns throughevery stageA citizen can see where their data went, and withdraw at any point.

From clinical care to population health, to research, to discovery, and back to better care — with genomics running through every stage.

What it supports

Research the platform is built to serve

  • Clinical research
  • Translational research
  • Learning health systems
  • Population and public health research
  • Genomic research
  • Precision medicine
  • Clinical trials feasibility
  • Real-world evidence

Federated cohort discovery

Counts across separate sites, returning totals only, with small numbers hidden. No individual rows ever leave the source.

OMOP common data model

A real extract, not just a list of what is in it: the person, the period observed, visits, conditions, medicines and measurements. It comes with a data-quality report and a list of codes that couldn’t be mapped, instead of dropping them silently.

Immutable extract ledger

Every extract recorded with its file hashes, so what was released can be reconstructed years later.

Data rights

What a citizen should be able to do — and what they can today

This is the section where a platform is most tempted to describe its intentions. The right-hand column is the measured position.

A citizen should be able toToday
Understand how their data is usedLive A transparency register and a per-route data-source indicator
Declare communication needs and adjustmentsLive
Grant and time-limit proxy access for a carerLive
See their own portal activityLive
See who read their recordLive Shown to the person in the portal, drawn only from their own record
Control participation in a specific studyLive Per-study opt-out, recorded and audited. A study using irreversibly anonymised data can’t be left, and the portal says so
Object to secondary use of their recordLive Recorded against the record and reversible. The scheme is named per jurisdiction, so England’s national data opt-out isn’t shown to a patient elsewhere
Export their recordLive A FHIR bundle built from the record itself; nothing is filled in with demonstration content
Live Live — built, persisted and reachable todayPartial Partial — built with a stated limitPending licence Pending licence — built, awaiting a publisher licenceDesigned Designed — specified, not builtNot built Not built

Why publish this

Because the alternative is a claim that fails at the first information-governance review. Until build B-569 this table listed four of these rows as partial or not built. They sat on the platform’s own defect register with the work named, and they have since been built. A capability gap that’s written down gets fixed; one that’s marketed doesn’t.

Captured from the running system

What this looks like today

These are screenshots of the platform as it runs, not mock-ups. Three surfaces carry the research story from the person to the researcher.

Patient portal, Data & Privacy tab. Three research programmes are listed. Long COVID Outcomes is pseudonymised with a button reading 'I don't want my data used for this'. BREATHE Respiratory Study is anonymised and has no opt-out. CALIBER Cardiovascular Study shows 'You have opted out of this programme' with an 'Undo opt-out' button.
Patient portal · Data & PrivacyResearch programmes

The person decides, study by study

The portal lists every research programme the person’s record feeds, who runs it, and whether the data is pseudonymised or fully anonymised. Each pseudonymised study has its own opt-out. Press it and the platform records the objection against the record, audits it, and stops the feed. Change your mind and you undo it just as easily.

An anonymised study has no opt-out button. That’s the honest position. Once data has been irreversibly anonymised there’s nothing to withdraw, and showing a switch that moves would tell the person they had left when they hadn’t.

Below the studies sits the secondary-use objection. The name of that scheme comes from the jurisdiction, so a patient in Jersey isn’t shown England’s national data opt-out.

Privacy Enhancing Technology module, Policy Manager tab. Tabs for Policy Manager, Token Vault, Watermark Console and Audit Trail. Counters show 6 total policies, 6 active, 0 overdue review, 1 requires consent. A table of privacy policies lists NHS England Aggregate Reporting, GP Connect cross-organisation access, Research Data Warehouse de-identified export and CMS Quality Reporting, each with third party, legal basis, data categories, retention period and status.
Privacy Enhancing Technology · Policy ManagerToken vault · Watermark console · Audit trail

Every route data can leave by is a written policy: who receives it, on what legal basis, which categories, for how long. Identifiers are swapped for tokens held in a vault, and each export carries a statistical watermark unique to its recipient, so a leaked extract can be traced to the organisation that let it go. The audit trail records every access. This is the module that makes the transparency register above true instead of aspirational.

Research Data Portal, Data Catalogue tab. A notice reads 'Before you apply: all data requests are subject to IG review under UK GDPR Art.9(2)(j)'. Tabs for Data Catalogue, Submit Request and My Requests. A search box and category filters. Three dataset cards: Primary Care GP EHR Records with about 48,000 records, Mental Health IAPT and CMHT Records with about 6,200 records, and Social Care Needs Assessments and Care Plans with about 3,400 records. Each shows variables, anonymisation options such as pseudonymised, k-anonymous and synthetic, and whether ethics approval and a data sharing agreement are required.
Research Data Portal · Data CatalogueSubmit request · My requests

The researcher’s side. They browse the catalogue, see what each dataset holds and what protection it comes with, and apply. Every request goes through information-governance review, needs an ethics reference where the dataset requires one, and releases nothing until a data sharing agreement is signed. Synthetic datasets with differential privacy are there for feasibility work without any of that. The request is tracked through approval in the same place it was made.