CCareOS
Ground truth · open for criticism

What should healthcare feel like if we designed it now?

Our target is not “more AI.” It is a healthcare environment where the right information is already there, uncertainty is visible, routine work almost disappears, patients understand what is happening, and humans stay in control.

Boundary: CareOS remains synthetic / pre-hospital research. This page describes the target system and the proof needed to earn each step.

One foundation. Different superpowers.

A doctor, nurse, patient and integration engineer should never see the same generic dashboard. They consume the same source-linked truth through interfaces shaped around their responsibility.

Physician

What changed? What matters?

Changed since last review, current context, pending results, contradictions, work that needs a decision and one-click sources. The agent prepares; the physician decides.

Nursing

What changed this shift?

Care-relevant deltas, unresolved tasks, isolation changes and handover context—not another full-chart reread.

Patient

What is happening to me?

Plain-language current state, pending items, next steps, medicines, sources and a way to flag something that looks wrong.

Social / discharge

Stop chasing information.

Structured aftercare need, reusable patient context, digital status and prepared referral packages instead of repeated calls, fax and copy-paste.

Hospital IT

Operate a product, not glue.

Adapter/version compatibility, source health, identity, conformance, upgrades, rollback and machine-readable blockers.

CISO / DPO / leadership

Evidence, not promises.

Data flows, permissions, versions, audit, incidents, Time Returned to Care and safety stops—without reverse-engineering a sales deck.

It should live where the work already lives.

New hardware must not be required for core value. The product adapts to clinical environments instead of asking the hospital to adapt to the product.

PC / managed Windows / Citrix
  → PRIMARY clinical surface
  → KIS patient context launches CareOS

Tablet
  → rounds / bedside / source review / voice capture

Phone
  → lightweight secure tasks / capture / carefully bounded alerts
  → not a miniature KIS

Offline
  → NOT offline-first clinical care
  → approved last-known cache may be READ-ONLY + visibly stale
  → no absence claims · no generic write · no agent tools
  → existing KIS/local workflow remains fallback

We measure minutes returned to care.

German hospital evidence makes the opportunity concrete: documentation and evidence obligations consume close to three hours daily for physicians and nurses in a 2025 DKI survey. Our targets below are ambitions to prove—not current CareOS outcomes.

Physician · targeted workflowspilot ≥20 min / shift → mature 45–60
Nurse · handover/documentationpilot ≥15 min / shift → mature 30–45
Discharge / social servicepilot ≥20 min / eligible case
Hospital IT · supported integrationshours, not repeated weeks
Synthetic inspiration

Physician review

75 minutes of complex pre-round information work in a shift → 48 minutes. 27 minutes returned. Must still pass verification and safety gates.

Synthetic inspiration

Nursing handover

55 minutes across targeted handover work → 35 minutes. 20 minutes returned. No increase in missed items or alerts.

Synthetic inspiration

Aftercare case

60 minutes of search / re-entry / coordination → 30 minutes. 30 minutes returned. Real workflow evidence required.

Evidence context: DKI 2025 bureaucracy survey · German EHR time-motion study · Recare’s public Discharge time-savings example.

The agent is inside the workflow—not the workflow.

The default product is not a chatbot. Agents are narrow helpers with visible identity, explicit tools and revocable authority.

Good agent jobs

Prepare, find, draft, route.

Pre-round synthesis, change detection, source-linked timelines, note/discharge drafts, missing-field checks, aftercare packages, patient explanations, result-finalisation routing and product guidance.

Much higher bar

Diagnose, prescribe, write, send.

Diagnosis/treatment recommendations, medication changes, order entry and consequential external communication require separate evidence, governance and often regulatory assessment. There is no generic autonomous shortcut.

untrusted model proposal
        ↓
deterministic patient · task · tool · data · budget policy
        ↓
trusted tool proxy / source-linked context
        ↓
reviewable draft
        ↓
human authority

The patient is not an afterthought.

Germany’s ePA already provides patient access/control and access logging. CareOS should make authorised information easier to understand without creating a parallel shadow record.

Patient home

Know what is happening.

What we know · what changed · what is pending · what happens next · medicines · documents/sources · access transparency · flag a possible error.

Patient agent

Understand, don’t impersonate.

Explain jargon, translate presentation, prepare questions and locate information. The interface always distinguishes source record, clinician plan and AI explanation.

Official context: gematik ePA FAQ · ePA transparency updates, July 2026.

A hospital’s first week should be boring.

No “big go-live weekend.” The new path earns dependency while the legacy workflow remains available.

Day 0IT only.

Manifest, preflight, source discovery, conformance, identity, network, rollback. No clinician dependency.

Day 1Synthetic team test.

10–15 minute orientation. Learn changed, pending, review and source—nothing else.

Days 2–5Shadow.

Approved deidentified/source sandbox. Measure time, searches, source checks, corrections and failures.

Week 2+Earn live read-only.

One workflow, one ward, accountable owners, legacy fallback. Expand only when evidence says yes.

Design the worst day before the best day.

Critical infrastructure cannot hide behind “AI can make mistakes.” The platform must define what happens when identity, sources, models, networks or people fail.

Wrong patient

Never guess identity.

Authoritative patient/encounter binding outside the model. Explicit cross-source ID strategy. Ambiguity blocks.

Source outage

Unavailable ≠ absent.

Other facts may remain visible, but completeness is false and absence/negative inference is disabled.

Stale cache

Age cannot hide.

Offline cache is optional, approved, time-bounded and read-only. When too old, it disappears.

Compromised model

No self-escalation.

The model cannot choose a new patient, grant tools, widen egress, invoke break-glass or silently write.

KIS upgrade

Test before clinicians discover it.

Capability diff → conformance → canary/shadow → promote or rollback.

CareOS outage

The hospital still works.

CareOS is not the system of record. Existing hospital workflows remain fallback; model outage does not remove core context.

A clinical graph underneath—not another pile of PDFs.

Healthcare is a relationship over time. The graph is a logical contract; hospitals do not need to buy a specific graph database.

Patient
 ├─ Encounter
 │   ├─ Fact ── asserted by ── Source
 │   ├─ Result ── derived from ── Specimen
 │   ├─ Fact ── supersedes / contradicts ── Fact
 │   ├─ Task ── assigned to ── Team
 │   ├─ Decision ── supported by ── Evidence
 │   └─ Agent draft ── reviewed by ── Human
 └─ Access event ── actor / treatment context / time

If people depend on it, we operate it like critical software.

24/7 support is not a marketing badge. It needs named owners, explicit severity response, release rings, recovery exercises and a real fallback story.

Future service target

24/7 Sev-0 / Sev-1 path.

Proposed acknowledgement targets: ≤5 minutes for patient-safety/broad outage, ≤15 minutes for major degradation. Monthly ops review, quarterly clinical-value review, annual resilience exercises.

Release discipline

No silent clinical changes.

Models, prompts, mappings, policy, adapters and write authority are versioned, tested, canaried and rollbackable. A published container is not automatically a clinical release.

Communication: use the rails, improve the context.

Germany already has ePA/TI/KIM; Europe is moving toward EHDS/MyHealth@EU. CareOS should make information trustworthy and usable across those rails, not invent another universal inbox.

within hospital
  → provider-local canonical context

hospital ↔ practice
  → national ePA / TI / KIM / structured interfaces where applicable

hospital ↔ post-acute / rehab / nursing
  → structured networks such as Recare + national rails

EU
  → EHDS / MyHealth@EU priority datasets

global
  → FHIR / IPS-shaped minimum context + issuer trust + receiving policy

Official context: gematik KIM · ePA for hospitals · European Health Data Space.

We are early. The foundation is the work.

The synthetic architecture is far ahead of the real-world evidence. That is exactly why the next move is contact with real clinicians, hospital systems and production integration teams—not another speculative AI feature.

Vision / architecture~70%
Synthetic engineering foundation~55%
Self-install / integration product~35%
Clinician-facing evidence~25%
Patient-facing product~15%
Real hospital integration evidence~5%
Multi-hospital repeatability~2%

Weighted against the full endgame, roughly 10–15%. Against what can responsibly be done before real hospital access, roughly 70–80%.

The difficult questions are part of the product.

This page is meant to be challenged. If one of these answers is weak, that is a roadmap item—not something to smooth over.

Are we actually saving the time we claim to care about?
We do not claim current savings. Every pilot needs a before/after baseline: task time, searches, calls, source opens, corrections, missed pending work and abandonment. In CareOS evaluation logic, speed cannot override a safety-stop or verification-decay event.
What if the UI becomes so good that clinicians stop checking sources?
Then the rollout fails. Verification behavior is a first-class metric. We want fewer unnecessary searches—not automation bias.
What happens when the Wi-Fi dies?
The existing local source workflow remains fallback. A hospital-approved recent cache may be shown read-only with unavoidable age; no general writes, sends, agent tools or absence claims are permitted offline.
Can the agent make a treatment decision?
Not by default. The current architecture treats models as untrusted proposers. Diagnostic/treatment recommendation or consequential action is a separate evidence/regulatory product with a much higher bar.
What can patients see?
CareOS should align with official access/legal policy and the ePA, then add a usable projection: current state, changes, pending items, next steps, sources and correction/question flows. It should not create a secret parallel patient record.
Are we replacing the KIS?
No. CareOS sits beside systems of record. The endgame is stable context/interoperability seams so applications can improve without a dangerous big-bang replacement.
Why a graph?
Because clinical meaning depends on relationships, time, provenance and supersession. The graph is logical: fact → source, fact → supersedes → fact, decision → evidence, draft → agent → human review. It does not require one database vendor.
How do we know Hospital #100 is easier than Hospital #1?
We measure integration engineer hours, adapter reuse, configuration-only rate, custom code/site, conformance failures and upgrade regressions. If marginal integration cost does not fall, we have consultancy—not infrastructure.
What is the biggest current gap?
Reality. Real clinician behavior, real KIS/LIS interfaces, real hospital identity/network/security constraints and a second independent site. We have pushed synthetic architecture far enough that external reality should now become the project manager.
Open invitation

Tell us where this breaks in the real world.

We are deliberately building this as a ground truth for discussion—not a polished claim that healthcare has been solved. If you run hospital integrations, clinical workflows, security, nursing, medicine or patient advocacy, the most useful contribution is the assumption we got wrong.