MediFlow

Care
in context.

MediFlow brings the patient record, source documents and work still to do into a free, open-source workspace for outpatient care. It helps you work from the clinical context while keeping interpretation and decisions in professional hands.

Use the full workspace without AI. Add intelligent functions only where they earn a place in your work.

Explore the workspace
Patient list in the MediFlow 0.8.6 Web interface, showing synthetic data
The patient list in the 0.8.6 Web interface. All data is synthetic; select the image to enlarge it.

0.8.6 · Available as source code

Start with the work.
Choose the tools around it.

Guided setup in 0.8.6 lets you decide which functions belong in your workspace. Clinical views and settings remain distinct, so configuring the system and working with a patient’s record have their own places.

Using this version means working from source on a Mac. MediFlow runs on that computer, with the interface in its local browser.

View the screens
0.8.6

Set up for your work

The first launch guides your choice of functions. Start with what your practice needs, without having to enable intelligent tools to use the workspace.

0.8.6

Keep the source within reach

Uploading a document, reading the original and reviewing extracted text or a synthesis are different steps. Keeping them distinct lets you check how information was obtained.

0.8.6 · Verification in progress

Choose the ChatGPT integration

The optional ChatGPT integration must be enabled and checked for the selected function. Signing in alone does not establish that it is ready for clinical data.

0.8.6 · Verification in progress

Know your WHO and AIFA references

A reference is useful when its origin and currency are clear. AIFA medicines data retain their source and date; WHO needs a separately configured and checked service.

0.8.6

Separate work from settings

Top navigation serves patients and their records. A separate sidebar groups the settings, giving clinical work and system configuration distinct places in the interface.

0.8.6

Limit access to the task

Compatible clients and agents reach authorized functions through MediFlow, not the database. They may prepare a proposal; confirmation of a clinical change stays with the professional.

Native apps and the 1.0 roadmap

Native app sources are part of the project, not a promise of a ready-to-install app. Their verification and distribution are separate; 0.8.6 includes no signed or notarized installers. Windows, Linux, Mini, iOS and iPadOS remain in the 1.0 roadmap.

Beyond the appointment.
Keep the next step in view.

An appointment rarely stands alone. A previous report may explain a treatment, while today’s findings leave a result to review or a check to arrange. The record needs to support that continuing work, not just document that a visit took place.

MediFlow brings notes, documents, treatments, measurements and outstanding activities into one workspace, making what you record available when the case next needs attention.

Structure for the facts.
Room for their meaning.

A code can name a condition without explaining its significance for a particular person. Structured fields make information easier to organize; clinical text preserves the context needed to understand it. MediFlow gives both a place.

Codes and measurements.
References you can trace.

A catalogue can change after an observation has been recorded. Retaining the source and version of the reference lets you see what was used at the time, rather than read the past through today’s catalogue.

The clinical findingReference · measurement · contextInformation you can return to
What to know about codes and scales

Terminology search helps find a code, not establish its appropriateness for the consultation. WHO Search requires an optional, separately configured local service, the sidecar; curated catalogues in the Apple app sources are not a live WHO ICD-11 catalogue. Scales distinguish missing answers from explicit values and retain their source and version in the history.

The local POMA-28 translation should not be taken as evidence of a clinimetrically validated Italian version of the scale.

Read the treatment
with its context.

Treatments and documents belong to the same clinical history. Pharmaceutical catalogues provide references for that work, while FHIR export prepares data for exchange in a documented format.

Patient recordReference cataloguesSource documentsParts of the same history
Updating references and exchanging data

AIFA catalogue updates can come from the official source or a local file; their date and origin remain available. Exemption records require review of the import preview and a backup before replacement. FHIR export follows a defined contract rather than guaranteeing compatibility with every receiving system. FHIRv2 still requires checks to establish equivalent behaviour.

Explore how data moves through MediFlow

When the work resumes.
Return to the context,
not a blank page.

A phone call may raise a different question about a patient you already know. The useful starting point is the relationship between the report, the treatment and the follow-up still to arrange, rather than any one item on its own.

That is also a reason to consider AI selectively. A summary, suggested structured data or a reading across documents can help bring scattered information together while preserving the route back to its sources.

These aids require a function to be selected and enabled. Models can be wrong, so the result still needs professional review against the source material.

Start with what is already known.

A call is easier to place in context when diagnoses, treatments, measurements and outstanding activities can be read as part of one patient’s history, not as unrelated entries.

Intelligence Fabric.
Choice, built into the system.

MediFlow’s full workspace is usable without AI, which is off until you choose to enable it. Intelligence Fabric provides the supporting structure for adding optional functions without making a model a condition of ordinary work, including where resources are limited.

A treatment review and a reading across documents do not need the same kind of help. Fabric therefore separates four functions, each with its own permitted tools, data and permissions. Their outputs are proposals for professional review, not clinical decisions.

Get oriented before looking deeper.

A summary brings relevant parts of the history together as a starting point for reviewing a case, not a substitute for reading it.

What reviewing the result involves

Check the proposal against the record, its sources and the patient’s current situation. Recalled information can be incomplete or no longer relevant; a summary does not replace the clinical history.

Choose for the task.
Within the permitted options.

Model selection is limited by the MediFlow catalogue for each function. When configured locally, Ollama can serve the first three functions; optional ATHENA/MLX is reserved for Treatment Reasoning on compatible Macs. External services are off by default and need explicit activation. They never take over silently when a local route is unavailable.

Access and conditions for the ChatGPT integration

The ChatGPT integration is optional and off by default. Signing in, enabling a function and checking that it works are separate steps; a ChatGPT account is not equivalent to OpenAI API access. Before any content is sent, the relevant consent is required and MediFlow checks access, permissions and the validity of the selected data. The response stays linked to its sources for review and cannot confirm a clinical change.

Before data can leave the local system

Choosing an external model also means deciding what information may leave the computer. The designed process limits content to what is needed, replaces identifiers and reconciles the result locally. These protections are enabled per function and are not available on every route.

Narrative clinical text remains blocked until the required controls are available and passed, with no implicit alternative route for sending it. Replacing identifiers is pseudonymization, not a guarantee of anonymity: the GDPR still applies.

TREATMENT INTELLIGENCE · TREATMENT REVIEW

Treatment Reasoning

ATHENA MLX · localDefault
Treatments6
Diagnoses2
Parameters4
Diary3
Evidence7

Choose which local model will prepare this proposal. ATHENA has not read sources or changed any content at this stage.

SourcesRead onlyReview draftWaitingRecord and medicationUnchanged
The default remains distinct from a choice applied only to the current proposal.

Invented case and data; the interaction reproduces the MediFlow panel and does not run the model.

How MediFlow works.
What those choices mean.

The record stays on the Mac.
Access goes through MediFlow.

The Mac holds the record and the services that govern access. Browsers, authorized clients and agents use those services: changing the tool does not change the rules for the data.

Specific functions can be reached without opening the full interface. Access still requires authentication, remains limited to the authorized task and leaves a record of the operations.

Roadmap 1.0

Mini.
Access from the terminal.

Mini is the command-line version: it searches references, reads activities and prepares proposals from a terminal through MediFlow services. It is not agentic headless access, which uses a separate contract and clients. Mini remains a 1.0 roadmap direction.

What the demonstration establishes

The synthetic-data demonstration covers a local Mac connection: Web sign-in and authorization, a search for the hemoglobin LOINC code and a plan of two reads. It shows Mini reaching the services, not assessing a clinical case.

There were no open activities for the synthetic patient, so both the list and follow-up proposal were empty. That does not demonstrate the quality of a proposal with substantive clinical content. No clinical changes were saved.

Authorization and session limits

Clinical functions are not exposed before Web authorization. If the Supervisor is missing, Mini reports the connection as unavailable; signing out closes the session processes. The demonstrated scope is a local Mac, not every platform.

CLI → Supervisor → MediFlow services
Access: authorization from the Web
Search: hemoglobin · LOINC 718-7
Activities for synthetic patient: none
Follow-up proposal: empty, nothing saved
Demonstrated plan: two reads
Logout: session processes closed

A development demonstration using synthetic data, not a live terminal on this site or clinical verification of 0.8.6.

Headless access.
An agent works within granted capabilities.

This is separate from Mini: Codex is shown as one possible client of MediFlow’s agent interface. The demonstration crosses a worklist, polypharmacy and several sources, then prepares a review queue without writing to the record.

MediFlow /Polypharmacy worklist review

The request is composed in the Codex prompt field.

Astra · Low selected in the composerNo action before sending

The request combines a worklist, polypharmacy and several sources; it is not a shortcut to one screen.

AstraLow
Local0 changesreview/elena-moretti

Demonstration with entirely invented data. Codex uses only granted read and preparation capabilities; this site is not connected to a record.

Local browser · authorized clientsMediFlow HostServices · permissions · auditLocal SQLite database
Assessing 0.8.6 for use

The project documentation sets out the requirements for the Mac and the browser interface on localhost. Being able to work without AI does not mean MediFlow can run on any hardware.

Public source code is not clinical validation. Before real clinical data is used, the software must be assessed in its intended environment. Synthetic tests demonstrate bounded behaviour, not the system’s clinical suitability.

Read the project documentation on GitHub

Responsibility
belongs in the design.

Deciding where and how to process information also means being accountable for its use. MediFlow starts locally, limits access and retains sources so that assistance from a tool does not obscure the path the data takes.

Minimization, encryption of sensitive clinical fields and traceable operations are technical choices. A real deployment must also establish its purposes, roles and legal basis. Architecture alone cannot settle those responsibilities.

GDPR

Privacy concerns how data is used throughout, not just where it is stored.

Assess the intended use of the data

The assessment must address the legal basis, conditions for processing health data, roles, retention, security and whether an impact assessment is needed. Local operation helps control data but does not by itself establish compliance for its use.

Read the GDPR regulation

AI Act

An aid to reasoning needs to be assessed for what it does and the part it plays in the decision.

Purpose, classification and responsibility

Intended purpose, function and the roles of operators determine the assessment of classification and obligations. Human review is a control, not certification. Any qualification as a medical device requires a separate assessment.

Read the AI Act regulation

Open code allows people to question the choices behind a tool, not just use it. MediFlow is free and aims to remain so, making study, discussion and contribution part of what the project offers.

Explore the project.
MediFlow is free; hardware, models and external services have their own costs and terms.MIT · Open source