Independent research and innovation platform. Not an NHS organisation or NHS-endorsed service.
Technical implementation

Integrate narrowly. Preserve provenance. Prove closure.

The first deployment should sit around existing NHS medication and workflow systems, consume only the data needed for the pilot, and create an auditable action layer rather than another unrestricted medication database.

Architecture principle

Read from source systems. Create owned events. Write back only through governed workflows.

01

Source

Medication, prescribing, dispensing, discharge and selected operational systems.

02

Normalise

Map patient, medicine, event, organisation, provenance and timestamp into a common event model.

03

Detect

Apply deterministic rules and approved analytics to identify conflicts, oversupply signals or resource opportunities.

04

Route

Create an accountable task for the responsible service or professional.

05

Close

Record acknowledgement, reconciliation, outcome and verification without erasing source history.

Minimum data model

Enough structure to make the loop auditable.

Medication state

What is believed to be active?

Medicine identifier, strength, formulation, route, dose, frequency, status, source organisation, source system and last verified time.

Change event

What changed?

Start, stop, dose, route or formulation change; author; clinical role; organisation; reason; effective time; intended duration; follow-up and provenance.

Supply state

What has been prescribed or dispensed?

Repeat status, prescription date, dispense status, quantity, partial supply, owing, cancellation and next expected cycle where available.

Workflow state

Who owns the next action?

Recipient organisation, accountable role, task, status, acknowledgement, reconciliation result, conflict reason and closure timestamp.

Integration sources

Likely pilot interfaces.

  • Primary care: current medication and repeat state
  • Acute/EPR: admission, inpatient change and discharge medication events
  • Community pharmacy: dispensing and supply state
  • Shared care record: cross-setting visibility and provenance where available
  • Care home/eMAR: administration and local medication state for included residents
  • Pharmacy/aseptic systems: preparation timestamps and selected resource measures
Interoperability

Standards first where interfaces permit.

The pilot should map to NHS-supported interoperability standards and preserve source identifiers and provenance. The exact interface pattern depends on the participating systems and approved access routes; the first technical discovery should confirm what is available rather than assume universal API access.

Deployment sequence

Move from synthetic to shadow to controlled intervention.

Stage 1Synthetic

Workflow alpha

Validate event model, permissions, task states and user journeys without patient data.
Stage 2Shadow

Live data, no action

Measure signal frequency, data quality and false positives without changing clinical workflow.
Stage 3Controlled

Human-reviewed action

Enable only approved interventions for a defined cohort and monitored use cases.
Stage 4Evaluate

Verify outcomes

Compare baseline, workload, safety and resource effects before any scale decision.
Clinical safety and IG

Safety is part of the product architecture.

  • No autonomous prescribing or medicine stopping
  • No silent overwrite of conflicting source states
  • Role-based permissions and minimum necessary access
  • Full event provenance and immutable audit history
  • Defined hazard log, escalation and downtime process
  • DPIA, lawful basis, retention and access controls agreed before live data
Design rule

The newest timestamp does not automatically win.

If hospital, GP, pharmacy or care-home states disagree, Sitora shows the conflict, the source and the responsible reconciler. The resolved state is the result of accountable reconciliation, not automatic replacement.

Technical acceptance criteria

The pilot should not proceed to live intervention unless these are true.

Data

Traceable

Every signal can be traced to source data, timestamp and organisation, with known latency and completeness.

Workflow

Owned

Every actionable event has a named recipient role, status, escalation route and closure definition.

Safety

Controlled

False positives, missed signals and intervention hazards have agreed mitigations and monitoring.

Technical discovery output

A deployable pilot specification, not a theoretical architecture.

The first four weeks should end with confirmed source systems, field-level data specification, interface method, role model, hazard controls, shadow-mode plan and acceptance tests.