Essay

The Window That Only Opens One Way

A consolidated published seven-part series on patient access in healthcare, the portals that own the record, the apps that only read it, and the access point nobody has built.

Jason Newell

A woman sits at her kitchen table with her phone and three apps open. One is from the hospital where she had surgery. One is from the clinic that manages her thyroid. One is from the urgent care she walked into on a Sunday in a different state. Each app shows her a piece of herself. None of them shows her the same piece, and none of them will speak to the others. The number she needs is in the second app. The surgeon who should see it works inside the first. Between them sits the woman, holding the phone, which is to say holding the cables.

This is the ordinary condition of being a patient. Not a missing feature, not a bug in any one product, but the shape of the whole arrangement. The record of her care is real and mostly complete, somewhere, in pieces, behind glass. She can look at it. She cannot reach into it.

Start with the thing everyone calls the patient's window into their care, and notice that it is the most headful object in the building. MyChart is not a headless system. It is Epic's record with Epic's face bolted to it, the two shipped together as one. The patient sees results, messages, bills, scheduling, all of it rendered exactly one way by the vendor that owns the store underneath. There is one head, and the head does not come off.

The convenience is genuine, and the people using it are doing the sensible thing. When everything you need is behind one login and it mostly works, you stop asking why it could not have been otherwise. That is the quiet cost. The portal is good enough that the patient forgets they are looking at one vendor's interpretation of one slice of themselves.

Every other vendor portal has the same shape. Oracle Health's HealtheLife, the MEDITECH portal, athenahealth's patient app: each is a presentation layer fused to one record system. The proof is in what the patient carries. A person treated at three health systems running three different records holds three portals, three logins, three half-charts that do not know about each other. Epic has softened its own version of this. One MyChart login now reaches across many Epic sites and some outside ones, so inside the Epic world the fragmentation is real but shrinking. Across vendors it is as bad as it ever was.

So the patient becomes the integration engine. They are the one carrying the result from the second app to the surgeon in the first, by screenshot, by memory, by reading a number aloud in a waiting room. The most sophisticated interoperability in the building runs on a person retyping their own blood pressure. The window shows them everything and lets them move nothing.

The systems that actually behave like a head you can swap are the ones the patient bolts on from outside. Apple Health Records is the clean example. It reads through the same patient-access standard endpoints every certified record system now has to expose, and it gathers hundreds of institutions into one timeline the patient owns. Many stores, one head, the real architecture working as advertised.

And it shows you exactly how far the real thing gets, which is the federal floor and no further. Apple sees what the regulation guarantees: a defined set of data classes, read only, the mandated resources and nothing past them. No note the doctor actually reasoned in. No image. No correction. No way to put anything back. What the patient gets is a clean, shallow, owned read of a deep record they still cannot reach the bottom of. It is the best patient-facing aggregation that exists, and it stops precisely where the interesting half of the chart begins.

It is worth standing in the graveyard for a moment, because this idea has died before. Microsoft HealthVault, gone. Google's personal health record, dead more than once. They did not fail on engineering. They failed because the data they could gather was thin, the patient was not the customer anyone was building for, and a window with nothing deep to show gets closed and forgotten. Apple's version survives partly because it rides hardware people already keep in their pocket, not because the record underneath finally got rich.

Behind these heads sits a quieter tier doing the plumbing. Aggregators and brokers, open-source efforts that let a patient self-host the whole thing. They matter, and they inherit every limit above them. They can only serve what the endpoints expose. They have to decide, at every door, whether the person knocking is the same person the record describes. They live or die on identity, which is the wall nobody on the patient side has made boring and universal yet. A patient standing at that door has a clean view of the room and no key to it.

Here is the part that should reframe the question. The headless content system is already in healthcare, running heavily, and it never touches the chart.

Contentful, Sanity, Adobe Experience Manager: these run the health system's front door. Find-a-doctor, the service-line pages, the patient-education library, the pre-visit instructions, all of it structured content under swappable web and mobile and kiosk heads. That side of the house is a textbook headless content system, and it works, because content about care is authored, owned, versioned on your own calendar, and free of the identity problem. It is the picture working exactly as it promises, on the half of the problem that fits the picture.

Content about care, not content that is care. The wall between those two is the wall the whole metaphor keeps trying to paint over. The brochure that tells you how to prepare for a colonoscopy is easy to syndicate to any screen. The result of the colonoscopy is not, and the difference is not technical sophistication. It is that the result is bound to a person, accreted from machines, owned by no single author, and governed by law.

There is a joke buried in the acronym, and you should not miss it. The other CMS, the federal one, the Centers for Medicare and Medicaid Services, is the reason a patient-access head can exist at all. Its interoperability and patient-access rules, with the information-blocking provisions of the 21st Century Cures Act beside them, are what force every record store to open the endpoints Apple Health reads from. One CMS is the architecture pattern. The other CMS is the regulator that pried the door open by law.

The cleanest content model in the world is inert until somebody makes the store answer the door, and in healthcare the thing that makes it answer is not good design. It is a rule with a compliance deadline.

Strip away the vendors and three problems are left standing, and they are the same three from the integration layer underneath, seen now from the patient's end of the building.

The first is asymmetry. A patient can read their record through fifty heads and write to none. There is no patient-facing path worth the name for putting something back: a correction, a home blood-pressure log, a symptom they wrote down at two in the morning, an outside record the system has never seen. The closest thing is a message in a portal, dropped into a queue a clinician may or may not work, attached to nothing the chart will trust. Read is a commodity now. Write does not exist.

The second is identity. The patient is the only party present at every encounter in every system, the only one who could in principle carry a proven identity from door to door. Instead, every aggregator re-solves identity badly at each endpoint, and every health system runs its own master patient index deciding, internally, whether two records are the same human. The patient could be the answer to the matching problem and is currently treated as one more thing to match. That is the load-bearing wall, and from the patient's side it is the one nobody is even pretending to build.

The third is the cliff under the data. The moment a patient directs their own record into an app they chose, the protections built for covered entities can fall away. The privacy rule may simply not follow the data out the door. So the patient is offered control of their record on the condition that exercising it strips the governance off. A read that costs you your protections is not the open door it looks like. It is a turnstile that keeps the safety on the wrong side.

None of these is a screen problem. You cannot design your way out of any of them with a nicer interface, which is exactly why the interface is where everyone has stayed.

So the opening is not another read app. That shelf is full. The opening is everything the read apps were built to avoid.

A patient write path is the first of them, and the hard word in that phrase is not write. It is trusted. Anyone can let a patient type a number into a box. The unbuilt thing is a path where what the patient contributes lands in the record as something a clinician will act on: attributed, provenance intact, reconciled against the master index, flagged as patient-reported without being quietly discarded for it. The home reading that a doctor trusts enough to change a dose. The outside summary that lands once, in the right chart, deduplicated on the way in.

A patient-held, portable, proven identity is the second, and it is the one with the most leverage, because it attacks the wall directly. Make the patient able to prove they are themselves once, in a way every door accepts, and the matching problem stops being re-solved at every endpoint. Nobody has made this boring and universal. The pieces exist, in fragments, in standards documents and pilot programs. The thing that turns them into something a person carries the way they carry a driver's license does not.

Governance that travels with the data is the third. The protection should be a property of the record, not of the building it happens to be sitting in. When a patient moves their data, the rules that guard it should move too, instead of falling off at the threshold.

Notice that all three are the same shape. They are the work of making the patient a first-class writer and a verifiable identity and a carrier of their own protections, rather than a viewer standing at glass.

I build a local-first AI resident on a single workstation. MAX names the machine, the modular executor that runs in my own building and answers to my own rules. MARA names the clinical mission, the same architecture pointed at a chart. The honest question is not whether such a thing is impressive. It is where it helps, for whom, and where it changes nothing.

Internally, on the provider side, the fit is real and specific. The danger with any assistant set loose on a chart is that it reasons fluently over a record that is quietly wrong. Give a smooth model an orphaned scan, an outside summary that arrived three times, a lab result that came in under a code nobody mapped, and it will produce a confident reading of a chart that does not add up, and the confidence is the danger. The value of an assistant built with epistemic discipline is the opposite reflex: it inherits the reconciliation gap and is built to notice it, to mark what it cannot trust instead of smoothing past it, to say a scan is referenced but unreachable rather than narrating around the hole. That is a provider-facing tool, and it helps the clinician precisely by refusing to be as fluent as the record pretends to be.

Externally, on the patient side, the fit is narrower and more interesting. Because the architecture is local-first, the data does not have to leave the patient's device or the building to be reasoned over, which speaks straight to the cliff from Part 4. A patient-side resident could be the head that carries its governance with it, that holds provenance, that prepares a patient contribution in a form already shaped to land in the record as trusted rather than discarded. That is a real role, and it is one of the few patient-facing roles that is not just another read app.

And here is where the knife points inward. None of this solves identity. A reasoning layer cannot decide whether the record over here and the record over there are the same human; that wall is underneath it, and an assistant that assumes the wall is solid is making the same error as a portal that does. It does not own the schema, so it ages on a clock the standards bodies set, not one I control. And it cannot conjure a write path the record vendor will not expose. Where write is a sales meeting and a security review measured in months, a clever resident on the patient's side does not change the answer at the other end of the wire.

MARA can make the half that is reasoning honest. It cannot make the half that is plumbing exist. Anyone who tells a health system otherwise is selling the painted wall.

The market sorts itself neatly once you hold the asymmetry in mind. It is saturated exactly where the work is easy and nearly empty exactly where the work is hard.

The read side is crowded and getting more so. Apple owns distribution and a clean experience and rides hardware the patient already carries, which is most of why it is alive when its predecessors are not. Google and Amazon are circling the same consumer surface. Underneath them, an aggregation tier moves a federally mandated read across organizations and increasingly does it well. The endpoints themselves are close to a commodity now, because a rule forced them to exist. All of that is genuine, and all of it is the same product wearing different paint: a window onto a store the patient does not own, opening one way.

Then July 2025 happened, and it is the most important move on the board. At a White House event branded Make Health Tech Great Again, the Centers for Medicare and Medicaid Services announced a voluntary Health Tech Ecosystem and secured pledges from more than sixty companies, among them Apple, Google, Amazon, OpenAI, Anthropic, Microsoft, Oracle, Epic, and a long list of payers and health systems. Twenty-one networks pledged to meet a new interoperability framework and become CMS Aligned Networks, with the first designations and the first Blue Button claims flowing through them targeted for early 2026. The framing was explicit: opt-in, no central government database, the patient in control.

Read past the branding and the interesting thing is what the pledge treats as the unlock. It is not another viewer. It is identity. CMS described patients reaching their data without setting up an account and password at every healthcare website, using modern digital identity instead, and roughly thirty companies pledged to help build those credentials. That is the federal floor finally trying to grow the one wall this series keeps naming. Whether it grows straight is another question, but for the first time the identity layer is the headline rather than an afterthought.

And the cliff is sitting right inside the same pledge. Among the pledging companies are consumer apps like Noom and Oura that are not covered entities. They committed to connect, with patient consent, and pull relevant health data to personalize what they do. Privacy scholars noted the obvious: once the data lands in an app that HIPAA does not reach, the patient is left to police secondary use and resale on their own. The governance-at-the-door problem is no longer a hypothetical. It is the open question written into national policy.

The write and secondary-use fight already has a face, and it is in court. In September 2024 the data platform Particle Health filed an antitrust suit against Epic, alleging Epic used its dominance over the record to choke off Particle's access in an emerging payer-data market. The companies had already fought through the Carequality dispute process, which handed Particle a corrective action plan over how some of its customers were using treatment-purpose access. A federal judge let the antitrust case survive dismissal in 2025, narrowing it to the hard question of how the market is even defined. Whatever the verdict, the case is the industry arguing on the record over who may pull a chart and for what purpose, which is the identity-and-governance problem wearing a docket number.

The plumbing tier is real, funded, and moving. Health Gorilla, a federally designated network under the national exchange framework since late 2023, reported query volume climbing from a couple hundred thousand a month to tens of millions through early 2025, runs identity proofing at a high assurance level, joined the new CMS-aligned effort, and sits on a Series C raise of fifty million dollars. Around it has grown what one analyst calls the individual access layer: companies like Flexpa, Fasten, Zus, Metriport, 1up, and Redox that act as on-ramps, connecting a consumer app to the national networks with identity proofing built in. Flexpa was named an early adopter for the CMS-aligned patient-access work and paired its aggregation with a reusable digital identity provider, explicitly to kill the clipboard and to make a patient prove themselves once rather than at every door.

So give the field its due. What the players do well is exactly the read side and the on-ramp: making the read a commodity, normalizing messy records into something an app can use, and, newly and most importantly, treating patient identity as reusable rather than re-proved at each endpoint. That last move is the first serious push against the load-bearing wall, and it is happening now.

What nearly all of them are still missing is the same pair of things, and they are missing them because they are hard, not because no one noticed. No one has shipped a patient write path a clinician trusts: everyone reads, and a patient still cannot put a home reading or a correction into the chart as something a doctor acts on. And no one has built governance that survives the data leaving the covered building, which the pledge's own non-HIPAA apps prove is unsolved. The interoperability market is measured in low single-digit billions and growing at a healthy clip, but the dollars cluster at the read surface. Saturation where it is easy, vacancy where it matters.

One wrinkle deserves naming, because it ties back to the last part. The same July pledge invites patients to pour their record into a conversational assistant. Which means the thing reasoning over the chart is arriving before the wall under it is built. That is exactly the failure an honest assistant has to be designed to refuse, and exactly why the question in the final part is the one I would actually ask.

So you sit across from the CTO of a large provider system, and you do not ask about the portal roadmap, because the portal roadmap is the read side and everyone has one. You ask something smaller and let it open on its own.

You ask: when one of your patients takes a reading at home, a blood pressure, a glucose, a number they wrote down at two in the morning, where does it land. They will reach for the patient-generated-data feature, the integration with the wearable, the box in the app. Then you ask the quieter version. When it lands, does a clinician trust it enough to act on it, or does it sit in a queue nobody works. The gap between those two answers is the whole opening, and you have led them to it without ever saying the word write.

And if there is time, you ask the other one. How many times does one of your patients prove they are themselves, across all the doors they walk through inside your system and the ones they walk through outside it. Watch them count, and watch them realize they are describing the master patient index from the patient's side, the same wall, seen from the one place nobody is building from.

You do not have to pitch anything. The architecture they have spent a decade and a fortune on reads their patients fluently and lets them write nothing, proves their identity over and over and trusts it nowhere, and the CTO already knows this in the way you know a sound in your house at night.

The only thing left to say is the thing the woman at the kitchen table has been saying all along, with three apps open and a number she cannot move. She can see all of it. She can reach none of it. And the window was built to look like a door.

SOURCES

CMS Newsroom, White House and Tech Leaders Commit to Create Patient-Centric Healthcare Ecosystem (Jul 30, 2025). https://www.cms.gov/newsroom/press-releases/white-house-tech-leaders-commit-create-patient-centric-healthcare-ecosystem

Fierce Healthcare, White House and CMS launch Health Tech Ecosystem Initiative. https://www.fiercehealthcare.com/regulatory/white-house-and-cms-launch-health-tech-ecosystem-initiative-expand-use-digital-health

HIMSS, HHS Convenes Private Sector Companies to Advance Interoperability and Patient Access. https://www.himss.org/news-center/hhs-convenes-private-sector-health-and-tech-companies-to-advance-interoperability-and-patient-access-to-data/

TechTarget, White House health tech initiative sparks data privacy concerns. https://www.techtarget.com/healthtechsecurity/feature/White-House-health-tech-initiative-sparks-data-privacy-concerns

Fierce Healthcare, Particle Health antitrust lawsuit moves forward after judge denies full dismissal. https://www.fiercehealthcare.com/health-tech/particle-healths-antitrust-lawsuit-against-epic-moves-forward-after-judge-dismisses

MedCity News, Unpacking the Epic-Particle Health Dispute. https://medcitynews.com/2024/09/epic-ehr-healthcare-lawsuit-data/

Healthcare IT News, How Health Gorilla is advancing interoperability as a TEFCA QHIN. https://www.healthcareitnews.com/news/how-health-gorilla-advancing-interoperability-tefca-qhin

Health Gorilla / PR Newswire, Health Gorilla Joins CMS-Aligned Network. https://www.prnewswire.com/news-releases/health-gorilla-joins-cms-aligned-network-as-a-trusted-data-network-enabling-ai-ready-clinical-data-exchange-302517829.html

Union Healthcare Insight, Interoperability's next frontier: the Individual Access Layer. https://www.unionhealthcareinsight.com/post/interoperability-s-next-frontier-the-individual-access-layer

Continues in Part 7: The question I would ask.

#HealthcareLeadership #DigitalHealth #PatientExperience #Interoperability #HealthTech #HealthIT

NarrativeESY-NAR-005

Keep reading

More field notes

This piece is part of the MAX Research Collective library. Browse the rest, or connect on LinkedIn.