Skip to content

Concept explainer

The record model

Explains how Atlas structures the patient record, how entries are timed and attributed, and how the clinical history stays readable over time.

The patient record in Pensieve is one durable account of a person, held by Atlas and read by every other tool. This page sets out how the record is structured, how each entry carries its author and its time, and how the clinical history stays readable as it grows.

One record for one person

A patient record is the single account of one person across every encounter and every site. Exactly one record exists per person across the whole platform, held once and read everywhere it is needed. Atlas is the tool that holds a patient's clinical data, and every other tool asks Atlas for it rather than keeping a copy of its own.

An encounter is a single contact between a patient and the hospital. Diagnoses, orders and charges attach to the encounter, and the encounter attaches to the record, so the history reads as a sequence of contacts rather than a flat list.

Figure 1.Diagram showing the patient record holding encounters, with diagnoses, orders and charges hanging from each encounter, and consent and access history held at the record.

What the record holds

The record gathers the clinical facts about a patient in one place. Each part is a first class entry with its own history, so a reader sees both the current picture and how it was reached.

Diagnosescoded

Conditions coded to ICD-11 and carried across encounters.

Clinical formssealed

Completed forms and their responses, locked once finished.

Documentsattached

Scanned and uploaded files described so they can be found again.

Imagingstudy

Studies read in the image study viewer against the right order.

Triageversioned

Emergency triage records, kept as versions as they change.

Consentdirective

The patient's own directives about their record.

Dischargetracked

The progress of a discharge from readiness to completion.

Historylog

The attributed account of who did what and when.

Every entry is timed and attributed

Each entry in the record names the person who made it and the moment they made it. The author and the time travel with the entry, so a reader reconstructs the sequence of care from the record alone.

Attribution holds under pressure

On a shared ward workstation, each member of staff signs in as themselves, so the record stays truthful about who acted even when several people use one screen through a shift. Read more on shared workstations.

Diagnoses on the record

A visit carries the diagnoses recorded during it. Where a visit holds more than one, exactly one is marked as the primary, and promoting another to primary demotes the prior one in the same step, so a visit always reads with a single primary. ICD-11 is the authoritative diagnosis code.

Every change to a diagnosis writes an append-only trail against that diagnosis, so a reviewer sees each attribute as it stood and when it moved. The section on diagnoses and problems sets out how conditions are coded and carried forward.

Corrections keep the history

A correction adds a new version of an entry and keeps the prior one, marked superseded. The earlier version stays visible and stays attributed, so the record reads honestly about what was known at each moment and what replaced it.

Figure 2.Diagram showing an entry recorded, then corrected by a new version while the prior version is kept and marked superseded.

The same discipline holds for an order and for a result. A placed order freezes a snapshot of what was ordered, and a corrected result lands as a new version with the prior one retained. Read more on corrections and amendments.

Readable across sites

The record belongs to the patient, who holds the decision rights over it. It exists once, has no owning hospital, and sits outside the tenancy structure, following the patient to every hospital that treats them. The organisation is the custodian and Data Fiduciary for the care it delivers, not the owner. A clinician who sees the patient at a second site reads the diagnoses, results and documents recorded at the first, within the access their role and the patient's admission allow.

PropertyHow it holds
OwnershipThe record belongs to the patient, who holds the decision rights over it. It has no owning hospital and sits outside the tenancy structure, above any single organisation.
ReachThe record follows the patient to every hospital that treats them and runs Pensieve, subject to the patient's own controls, not only to the sites of one organisation.
AttributionEach entry names its author and the moment it was made.
CorrectionA change adds a new version and keeps the prior one, marked superseded.
CodingDiagnoses are coded to ICD-11 as the authoritative diagnosis code.

Common questions

Is there a separate record at each site?

One record holds the patient across every hospital that treats them. The work happens at a site, and the record belongs to the patient rather than the organisation, so a later contact reads the same history within the access the patient allows.

What happens to a mistaken entry?

A correction adds a new version and keeps the original, marked superseded. Both stay attributed, so a reviewer sees what was recorded, what replaced it, and who made each.

Does every tool keep its own copy of the record?

Atlas holds the clinical data. Every other tool reads it from Atlas through a request rather than storing a copy, so there is one account to correct and one account to audit.

Read how the patient lens narrows a record to the people with a current reason to see it in the patient lens.