Dr. Test Provider
Test Family Practice · Toronto
The mechanism
Most systems ask who you are and then decide what to show you. This one starts from nothing being visible and adds only what you have explicitly allowed.
MedUnity is the trusted infrastructure between Canada’s health custodians and the patients whose records they hold. It is the Canadian-owned layer that lets a patient bring the fragments together and direct who sees what, for how long, and why.
Every access is refused unless the patient permitted it, and every access is recorded in a ledger nobody — including MedUnity — can alter.
Not a competing record. Not another silo. The rails, the consent, and the proof.
You have answered the same questions at every appointment, because nobody can see what anyone else wrote down. You have carried your own history between offices — in a folder, on your phone, in your memory — and been made to feel difficult for arriving with printouts. Your record exists. You are just not the one who can reach it.
Your medications, conditions, allergies, results and visit history, in one place you can open. At a new specialist. In another province. At two in the morning when you cannot remember which dose changed in March.
You choose who sees it. You choose for how long. You can see everyone who looked, and you can take it back at any time.
Who is asking, for which categories, and why. A request without a purpose is not a request the system can evaluate.
An active, unexpired, unrevoked permission from you, covering that category, for that purpose. Anything missing is a refusal.
A refused request and a record that does not exist get the same answer. Somebody guessing cannot learn whether you are a patient here.
The access log entry is written in the same transaction as the access. If the log write fails, the read fails. It is not a log that runs alongside; it is a condition of reading.
Provenance is not a feature here. A clinical record without it cannot exist in the store at all — the database will not accept one.
Sent by the clinic, hospital, pharmacy or lab that recorded it, and attributed to them.
A letter or a result you uploaded yourself, marked as coming from you.
Readings from a wearable or a home monitor, labelled as device data rather than as a clinical measurement.
Your journal. Always distinguishable from a clinician’s note, in both directions.
No alerts, no "this looks abnormal", no risk scores, no ordering findings by how serious we think they are. We show the source’s values, the source’s reference ranges and the source’s own flags, exactly as they arrived.
There is no path from any internal console to a patient’s clinical data. The console manages accounts and system health, and that is the whole of it.
The only way a person here can see anything is a grant you made, that you can see, that expires, and that you can revoke.
Not to insurers, not to researchers, not to anyone. It is not a policy; there is no mechanism.
Clinical information is stored as FHIR R4 — the international standard for exchanging health data — from the first commit, rather than in a private format with an export button added later. CA Core+ and CA Baseline are the Canadian profile targets. Conformance against them has not yet been proven, and until it has, we say target rather than conformant.
Nothing is ever edited or deleted in the clinical store, including by whoever wrote it. A correction is a new entry that supersedes the old one, and both stay visible with their dates and their authors.
You search for a clinician by name, practice, city, institution, or MedUnity Number, and choose them from the results. There is no field for a health card number, because we never ask for one.
Step 1 of 2
You type the clinician’s name. You could search by their practice, their city, or their institution instead.
Step 2 of 2
They appear with their practice and city, so you can tell them apart from someone with a similar name.
Test Family Practice · Toronto
You pick a person, choose which parts of your record they can see, and choose how long for. Then you can see exactly what you agreed to. Three decisions, each one yours.
Step 1 of 4
You start from a person. Sharing is always with someone specific, never with "anyone who asks".
Test Family Practice · Toronto
Step 2 of 4
You choose what they can see, one category at a time. Here, medications and allergies. Nothing else is included unless you tick it.
Step 3 of 4
You choose for how long — here, thirty days. It is part of the decision, not a setting you have to go looking for.
Step 4 of 4
Done. You can see who has access, to what, and until when.
Every arrangement has a Stop sharing button. You press it, read one honest sentence about what stopping does and does not do, and confirm. It ends at once, including on a screen they already have open. There is nothing to choose and nobody to ask.
Step 1 of 3
Every arrangement has its own Stop sharing button. Not in a menu, not behind a setting.
Step 2 of 3
One honest sentence: stopping ends their access from now on, but cannot un-see what they already saw. No reason to give, nothing to type.
This stops them seeing anything from now on. It does not undo what they have already seen — anything they looked at, they have seen, and they may have written it into their own records.
Step 3 of 3
It has ended. Immediately, and on a screen they already had open.
Your access log is a plain list of everyone who opened your record, what they saw, and when — including the moment you gave them access. Nobody, including us, can change it. Most months, the most reassuring thing on it is nothing.
Step 1 of 2
Every time someone opens your record, it is written here in a sentence, at the moment it happens.
Dr. Test Provider viewed your medications and allergies on 5 March at 1:40 PM.
Dr. Test Provider viewed your medications on 3 March at 9:15 AM.
Step 2 of 2
And a month where nobody looked says exactly that.
Nobody has looked at your record.
Everything above is either true in the code or it is not. The Evidence page says which, including the parts that are not proven yet.