CAREFABRIC · Overview & impact / Architecture / Explore & connect
Ideas for taking the blueprint further
CareFabric grew out of my study of architecture as code with AI. These notes explore how the design might be tested in practice: start with one handoff, examine the assumptions and learn from the results. I’m sharing them as a starting point for discussion.
A useful first experiment starts with a focused question: which handoff should improve, what must be true before it can operate, and what evidence would justify expanding it? A national-scale ambition can begin with a modest, testable workflow.
For example, one clinic and one laboratory could evaluate the retrieval of recent lab results for an agreed treatment workflow. Select one exchange profile, a small set of systems, named operational owners and an approved test-data approach. This is a scope example, not a promised delivery duration.
| Stage | Working scope | Evidence needed to continue |
|---|---|---|
| 1 · Establish the foundation | Document or summary exchange, identity handling, local policy, audit and support ownership. | Approved workflow and data contract; successful and denied paths demonstrated; recovery and escalation exercised. |
| 2 · Add structured depth | Selected FHIR resources, terminology mapping and receiving-workflow integration. Optional reviewed AI assistance. | Conformance results for the selected guide; usable clinical context; measured review burden and data quality. |
| 3 · Expand deliberately | More participants, profiles and event-driven exchange where justified. | Repeatable onboarding, capacity and failure testing, version compatibility and funded operational ownership. |
Set a baseline before implementation. Agree the denominator, observation period and acceptance threshold for each measure; report failures and exclusions alongside successes.
Reduced duplicate investigations or improved patient outcomes may be valuable longer-term objectives. They require appropriate clinical evaluation and cannot be inferred from exchange volume alone.
Federated custody changes where responsibilities sit; it does not remove them. Local data quality, review staffing, mapping work and service reliability still determine whether the exchange is useful.
Fund registry operations, policy publication, discovery, trust services and audit intake. Give those services an accountable owner, an availability target and an incident process.
Each site needs ownership of its adapters, identity remediation, sharing rules, certificates and review queues. Include these costs in the business case.
If compensation for response work is considered, agree it separately from clinical authorization. Evaluate incentives and equity explicitly; this blueprint does not prescribe fees or revenue splits.
Clinical exchange is the scope of the CareFabric spine. Claims adjudication, payment settlement and replacing the local chart system belong to separate decisions. Keeping these responsibilities distinct makes the initial operating agreement easier to reason about.
| Risk | Design response and evidence |
|---|---|
| Wrong-patient retrieval | Validated identity rules, reviewable ambiguity, denied-path tests and incident investigation. |
| Sensitive metadata accumulates centrally | Minimized fields, restricted access, retention limits and privacy review of the locator and audit data. |
| Authorization service is unavailable | Redundant services and tested recovery. Fail closed for new authorizations; document the handling of already-issued grants and emergency workflows. |
| Token theft or replay | Short-lived grants plus enforced sender constraints where selected; key rotation, revocation and replay testing. |
| Relay learns or retains content | End-to-end encryption across the relay, separated keys, retention controls and verification of what the operator can observe. Network metadata can remain visible. |
| Participant or policy versions diverge | Versioned contracts, compatibility tests, controlled policy rollout and rollback. |
| Audit backlog or loss | Durable local buffering, monitored delivery, capacity testing and a defined rule for when exchange must stop. |
| AI or emergency-access exceptions expand quietly | Explicit review, restricted roles, event-level evidence and accountable follow-up. |
| Vendor lock-in or unaffordable operations | Portable contracts and data, documented exit paths, multiple implementation options and measured support costs. |
The intended approach is to integrate through the participant boundary. Feasibility depends on the APIs, exports, vendor agreements and workflow constraints of the systems involved.
Yes. A group can establish the trust function for its own branches. Connecting later to external organizations still requires new governance and compatibility work.
This project presents an architecture proposal and illustrative design work. Taking it into production would require further implementation, conformance testing and operational preparation.
Standards help define and test interoperability. Regulatory obligations and participation requirements depend on the deployment and must be assessed by the responsible clinical, privacy, security and legal owners.
It may be part of the answer. The assessment should identify which CareFabric responsibilities it already satisfies and where identity, governance, discovery or operational gaps remain. The goal is a better handoff, not another box in the estate.
I developed CareFabric while studying architecture as code with AI, and I’m releasing the blueprint to share what I explored and learned.
If you like the idea, have feedback or see a connection to something you’re working on, I’d be happy to hear from you. We can compare notes and see where the conversation goes.
A question, a different perspective or a simple hello is welcome.
Review the technical sources and standards or return to the project overview and healthcare impact.