Accelerating research while protecting citizen rights.
Finding groups of patients, real extracts with a data-quality report, a log that can’t be altered — and a plain account of which controls for citizens actually work today.
Accelerating research while protecting citizen rights
Care generates evidence and evidence changes care. The loop only works if the person at the start of it can see where their data went and stop it.
From clinical care to population health, to research, to discovery, and back to better care — with genomics running through every stage.
Research the platform is built to serve
- Clinical research
- Translational research
- Learning health systems
- Population and public health research
- Genomic research
- Precision medicine
- Clinical trials feasibility
- Real-world evidence
Federated cohort discovery
Counts across separate sites, returning totals only, with small numbers hidden. No individual rows ever leave the source.
OMOP common data model
A real extract, not just a list of what is in it: the person, the period observed, visits, conditions, medicines and measurements. It comes with a data-quality report and a list of codes that couldn’t be mapped, instead of dropping them silently.
Immutable extract ledger
Every extract recorded with its file hashes, so what was released can be reconstructed years later.
What a citizen should be able to do — and what they can today
This is the section where a platform is most tempted to describe its intentions. The right-hand column is the measured position.
| A citizen should be able to | Today |
|---|---|
| Understand how their data is used | Live A transparency register and a per-route data-source indicator |
| Declare communication needs and adjustments | Live |
| Grant and time-limit proxy access for a carer | Live |
| See their own portal activity | Live |
| See who read their record | Live Shown to the person in the portal, drawn only from their own record |
| Control participation in a specific study | Live Per-study opt-out, recorded and audited. A study using irreversibly anonymised data can’t be left, and the portal says so |
| Object to secondary use of their record | Live Recorded against the record and reversible. The scheme is named per jurisdiction, so England’s national data opt-out isn’t shown to a patient elsewhere |
| Export their record | Live A FHIR bundle built from the record itself; nothing is filled in with demonstration content |
Why publish this
Because the alternative is a claim that fails at the first information-governance review. Until build B-569 this table listed four of these rows as partial or not built. They sat on the platform’s own defect register with the work named, and they have since been built. A capability gap that’s written down gets fixed; one that’s marketed doesn’t.
What this looks like today
These are screenshots of the platform as it runs, not mock-ups. Three surfaces carry the research story from the person to the researcher.
The person decides, study by study
The portal lists every research programme the person’s record feeds, who runs it, and whether the data is pseudonymised or fully anonymised. Each pseudonymised study has its own opt-out. Press it and the platform records the objection against the record, audits it, and stops the feed. Change your mind and you undo it just as easily.
An anonymised study has no opt-out button. That’s the honest position. Once data has been irreversibly anonymised there’s nothing to withdraw, and showing a switch that moves would tell the person they had left when they hadn’t.
Below the studies sits the secondary-use objection. The name of that scheme comes from the jurisdiction, so a patient in Jersey isn’t shown England’s national data opt-out.
Every route data can leave by is a written policy: who receives it, on what legal basis, which categories, for how long. Identifiers are swapped for tokens held in a vault, and each export carries a statistical watermark unique to its recipient, so a leaked extract can be traced to the organisation that let it go. The audit trail records every access. This is the module that makes the transparency register above true instead of aspirational.
The researcher’s side. They browse the catalogue, see what each dataset holds and what protection it comes with, and apply. Every request goes through information-governance review, needs an ethics reference where the dataset requires one, and releases nothing until a data sharing agreement is signed. Synthetic datasets with differential privacy are there for feasibility work without any of that. The request is tracked through approval in the same place it was made.