OpenHIE-inspired behavioral miniature · wholly synthetic
A patient moves. Their data does not.
Watch one entirely synthetic encounter become portable—without pretending that an exchange is one giant database.
Nothing starts until you choose.
Rivermark Demonstration Network Logical architecture · systems at rest
Payload route Every highlighted line is an invoked sender-to-receiver contract.
- Registration message enters the exchange: community-app to iol, not invoked in this transaction.
- Clinic request or artifact enters the exchange: clinic-ehr to iol, not invoked in this transaction.
- Hospital requests a permitted shared summary: hospital-ehr to iol, not invoked in this transaction.
- Laboratory receives an order or returns a result: laboratory to iol, not invoked in this transaction.
- Pharmacy submits a minimum supply event: pharmacy to iol, not invoked in this transaction.
- The sending system credential is checked: iol to authentication, not invoked in this transaction.
- Worker, organization, location and service are related: iol to interlinking, not invoked in this transaction.
- Identity evidence is evaluated: iol to entity-matching, not invoked in this transaction.
- Purpose and disclosure policy are evaluated: iol to policy, not invoked in this transaction.
- Local and enterprise identity links are queried: iol to client-registry, not invoked in this transaction.
- Canonical facility status and endpoint are queried: iol to facility-registry, not invoked in this transaction.
- Canonical worker role and status are queried: iol to health-worker-registry, not invoked in this transaction.
- A versioned semantic mapping is requested: iol to terminology-service, not invoked in this transaction.
- A fictional product identity is resolved: iol to product-catalogue, not invoked in this transaction.
- A redacted operation event and derivation evidence are recorded: iol to audit-evidence, not invoked in this transaction.
- A permitted normalized clinical subset is read or written: iol to shared-health-record, not invoked in this transaction.
- A periodic minimized aggregate is exported: iol to hmis, not invoked in this transaction.
- A minimum supply event changes represented stock: iol to lmis, not invoked in this transaction.
- A separate fictional eligibility or claim state is exchanged: iol to finance-insurance, not invoked in this transaction.
Active station spine
Inside the exhibit
The mechanism stays open.
- 01IdentityWho is this—without guessing?
- 02RoutingWhich capability is actually invoked?
- 03MeaningWhat changed in shape or semantics?
- 04ProvenanceHow did this artifact come to be?
- 05FailureWhere did processing stop?
- 06RecoveryWhat one condition made replay safe?
The governing idea
An HIE is not one enormous database.
It is a governed journey among systems that know different things and are authoritative for different things. The interoperability layer coordinates that journey without becoming the truth for identity, care, product, stock, payment, or population reporting.
for whom Client Registry by whom Health Worker Registry where Facility Registry what care Terminology + SHR what product Catalogue + LMIS who pays Finance service
Complete architecture, in document order
Text equivalent of the logical atlas. Each capability owns different facts.
| Capability | Role | Authoritative for | Explicitly not authoritative for |
|---|---|---|---|
| Community apppoint of service | Captures a small synthetic registration artifact in a field workflow. |
|
|
| Clinic EHRpoint of service | Owns Lumenbank Clinic local identity, encounter, order, and result workflow context. |
|
|
| Hospital EHRpoint of service | Performs a later permitted cross-town identity query and limited summary retrieval. |
|
|
| Laboratorypoint of service | Receives a normalized order and asserts an immutable synthetic result. |
|
|
| Pharmacypoint of service | Creates a minimum dispense or supply event after resolving product identity. |
|
|
| Interoperability Layerinteroperability | Authenticates systems, invokes policy, validates, routes, mediates, orchestrates, logs, queues, and replays. |
|
|
| Authenticationtrust | Returns a clearly simulated sending-system credential outcome. |
|
|
| Interlinkinginteroperability | Verifies authored practitioner-role, organization, location, and service relationships. |
|
|
| Entity matchinginteroperability | Represents exact, possible, ambiguous, and no-match identity outcomes. |
|
|
| Client Registryreference | Links retained local identifiers to one synthetic enterprise client identity. |
|
|
| Facility Registryreference | Returns canonical facility identity, hierarchy, operational status, services, and endpoint. |
|
|
| Worker Registryreference | Returns canonical synthetic worker identity, role, status, and facility relationship. |
|
|
| Terminologyreference | Validates a tiny code set and governs versioned semantic mappings. |
|
|
| Product Cataloguereference | Resolves a fictional local pack to a canonical fictional product identity. |
|
|
| Shared Health Recordclinical | Stores a normalized, operational, person-centric subset of shared clinical artifacts and versions. |
|
|
| HMISpopulation | Owns a later periodic aggregate reporting fact without patient drill-through. |
|
|
| LMISsupply | Applies an idempotent stock decrement and may issue a replenishment signal. |
|
|
| Finance & insurancefinance | Owns entirely fictional eligibility, claim, and finance states. |
|
|
| Policytrust | Evaluates an authored requester, role, organization, purpose, category, time, and directive input. |
|
|
| Audit & provenanceevidence | Keeps separate evidence of security/operational events and artifact derivation. |
|
|