Skip to content
THOS

Built and operated by Laetoli (T) Limited in Dar es Salaam. A private system, built to national standards.

Language

One health record, wherever a Tanzanian is treated.

THOS keeps one patient record and one identity across every facility that treats a person. It sits alongside the systems a hospital already runs, over published standards.

Built by Laetoli (T) Limited, Dar es Salaam.

Facility onboarding starts Q4 2026. The ledger below marks how far each piece has got.

What THOS does

Every row carries its state, its standard, and where to check it

THOS capabilities, their current state, the standard each conforms to, and where to verify it
CapabilityStateStandardWhere to verify
One patient identity across facilitiesBuilt, not in serviceHL7 FHIR R4 · Patient/$matchCapabilityStatement at /metadata
One record, versioned, that travels with the patientBuilt, not in serviceHL7 FHIR R4 (4.0.1)CapabilityStatement at /metadata
Consent gates every read and every writeBuilt, not in serviceHL7 FHIR R4 · Consentsupabase/functions/il/index.ts
Emergency access, recorded against the clinician who used itBuilt, not in serviceNo applicable standardsupabase/functions/il/index.ts
Tamper-evident audit trail, written even when access is deniedBuilt, not in serviceHL7 FHIR R4 · AuditEventWalk the chain: GET /audit/$verify
Results and observationsBuilt, not in serviceHL7 FHIR R4 · Observation, DiagnosticReportCapabilityStatement at /metadata
Orders for laboratory and imagingBuilt, not in serviceHL7 FHIR R4 · ServiceRequestCapabilityStatement at /metadata
Electronic prescribingBuilt, not in serviceHL7 FHIR R4 · MedicationRequestCapabilityStatement at /metadata
Referrals between facilitiesBuilt, not in serviceHL7 FHIR R4 · ServiceRequest, CommunicationCapabilityStatement at /metadata
Appointments and schedulingBuilt, not in serviceHL7 FHIR R4 · AppointmentCapabilityStatement at /metadata
Continues working when the connection drops, and replays afterwardsBuilt, not in serviceNo applicable standardapps/thos/src/lib/offlineQueue.ts
Clinical notes and documentsDocumentReference is not among the resource types the interoperability layer accepts, so a note is written to the device and does not reach the national record. Until it is added, a clinical note does not travel with the patient.PartialHL7 FHIR R4 · DocumentReferenceCapabilityStatement at /metadata
Coded clinical terminologyThe mediator recognises all four systems, but the curated national subset is roughly forty concepts and an unrecognised code is logged rather than rejected: deliberately, so a missing row cannot block care. Coded data is therefore not yet reliable enough to report on.PartialLOINC · SNOMED CT · ICD-10 · ICD-11supabase/migrations/0038_terminology_seed.sql
Clinical records signed by the clinician who wrote themThe application signs each resource and stores the signature on it, but the interoperability layer has no signature handling, so nothing verifies it on the way in or on the way out. A signature nobody checks is a record of intent, not a guarantee of authorship.PartialJWS (RFC 7515) · FHIR provenance patternapps/thos/src/lib/api.ts
Admissions and transfers from a facility’s existing systemPlannedHL7 v2 ADTNot yet verifiable
Imaging exchangePlannedDICOMwebNot yet verifiable
Payer settlement and claimsPlannedISO 20022Not yet verifiable
Patient registration, and review of what citizens submitNone of the three checks a reviewer needs is connected. There is no NIDA identity service, no SMS gateway and no NHIF or CHF eligibility endpoint, so a submission is approved on what the citizen typed and the screen says so on every row.PartialOpenHIE Client Registrysupabase/migrations/0067_preadmin_registration.sql
Citizen access without a smartphonePlannedSMS/USSDapps/thos/src/lib/ussd.ts

The architecture

Every link names the protocol that runs over it

THOS national architectureAn OpenHIE mediator is the only route to the national record. Solid links carry traffic today; dashed links are planned and do not exist yet. THOS clinical application → Interoperability layer (FHIR R4 · OAuth 2.0). Partner facility EMR (planned) → Interoperability layer (HL7 v2 ADT, planned). Imaging (PACS) (planned) → Interoperability layer (DICOMweb, planned). Citizen access (planned) → Interoperability layer (SMS/USSD, planned). Interoperability layer → Client registry (Patient/$match); Terminology service (Code validation); Consent (Consent decision); Shared health record (Versioned read/write); Audit log (Append-only); Payer settlement (ISO 20022, planned). Client registry. Terminology service. Consent. Shared health record. Audit log. Payer settlement (planned).THOS clinical applicationAuthenticated SPA · offline queue and replayPartner facility EMRNot yet integratedImaging (PACS)Not yet integratedCitizen accessNot yet builtInteroperability layerOpenHIE mediator · the only door to the recordClient registryEMPI · Patient/$matchTerminology serviceCurated subset: see registerConsentGate on every read and writeShared health recordFHIR R4 4.0.1 · versionedAudit logHash-chained · verifiablePayer settlementNot yet builtFHIR R4 · OAuth 2.0HL7 v2 ADTDICOMwebSMS/USSDPatient/$matchCode validationConsent decisionVersioned read/writeAppend-onlyISO 20022

Solid: carrying traffic today. Dashed: planned, not yet built. The mediator’s CapabilityStatement is public at /metadata: a conformance claim nobody can retrieve is not a conformance claim.

Reach, by region

Real administrative boundaries · Select a region for detail

THOS reach by region30 regions of Tanzania: 2 pilot cohort, 28 not yet scheduled. Scheduled: Dar es Salaam, Mwanza.

Boundaries: geoBoundaries (gbOpen), ADM1, CC BY 4.0. 30 regions. Tanzania has 31: Songwe is absent from the open release, so Mbeya here covers both.

Onboarding begins in Q4 2026 with 12 pilot facilities across Dar es Salaam and Mwanza. No facility is connected today; this map prints the count when one is.

Dar es Salaam
Pilot cohortPilot cohort, Q4 2026. Facilities named in the registry once onboarding agreements are signed.
Mwanza
Pilot cohortPilot cohort, Q4 2026. Facilities named in the registry once onboarding agreements are signed.
  • Pilot cohort2
  • Not yet scheduled28

Source: onboarding plan · As of

The family

16 products, and the ones that open today are linked

16 products carry the THOS name: renal, maternity, laboratory, blood, medicines. All share the one record drawn above.

THOS
The health operating system
On the THOS core
TABHOS
Behavioural health
Awaiting migration
THOSMama
Maternal and child health
Awaiting migration
THOSRenal
Nephrology and dialysis
Awaiting migration
THOSMD
Clinical education
Awaiting migration
THOSDerma
Dermatology
Awaiting migration
THOSOptics
Eye care
On the THOS core
THOSSurgeon
Surgery
On the THOS core
THOSNCD
Chronic disease
On the THOS core
THOSLabs
Laboratory systems
On the THOS core
THOSUgavi
Supply and ownership
On the THOS core
THOSDamu
Blood service
On the THOS core
ReferralHub
Referrals between facilities
On the THOS core
THOSInsured
Health insurance
On the THOS core
THOSClaims
Claims and settlement
On the THOS core
THOSSentinel
Disease surveillance
Shelved

Each one in detail: its host, what flows, and what was verified

Standards and conformance

Standard, version, level, and the date it was last tested

Nothing here has been independently tested yet. THOS implements FHIR R4 and publishes its CapabilityStatement openly, and that much is checkable today: but implementing a specification and passing its test suite are two different claims, and only the first is true. The “last tested” column will carry a date when it has one to carry.

Certification register: standard, publisher, version, conformance level, date last tested, and test report
StandardPublisherVersionConformanceLast testedReport
HL7 FHIREighteen resource types, versioned, with read, vread, search, create, update and transaction. The server publishes its own CapabilityStatement unauthenticated, so the claim is checkable without an account. Touchstone conformance testing has not been run.HL7 InternationalR4 (4.0.1)Implemented, untestedNot testedNone
OpenHIE architectureInteroperability layer, client registry, terminology service and shared health record are present and separated, and the record is reachable only through the mediator. No OpenHIE conformance workflow has been run against it.OpenHIEMediator patternImplemented, untestedNot testedNone
LOINCThirty-one codes are curated in the national subset. Codes outside it are recorded and logged rather than rejected, so laboratory data is coded but not yet reliably coded.Regenstrief Institute2.78PartialNot testedNone
SNOMED CTSix concepts are curated. Distributing SNOMED CT nationally requires a member licence held by the country, and confirming Tanzania’s standing is a procurement question that has to be settled before this row can move.SNOMED InternationalInternational editionPartialNot testedNone
ICD-11The system recognises ICD-11 MMS and ICD-10 URIs and validates against a curated subset. National reporting still runs on ICD-10, so both are accepted deliberately.World Health OrganizationMMSPartialNot testedNone
OAuth 2.0Bearer tokens are verified against a remote JWKS with an issuer check. The CapabilityStatement declares OAuth as the security service. SMART on FHIR app launch is not implemented.IETFRFC 6749Implemented, untestedNot testedNone
JSON Web SignatureResources are signed by the writing application and the signature is stored on the resource. The interoperability layer does not verify it, so authorship is asserted rather than proven. See the capability ledger.IETFRFC 7515PartialNot testedNone
HL7 v2Required to take admissions and transfers from the systems Tanzanian hospitals already run. Not implemented.HL7 International2.5.1 (ADT)PlannedNot testedNone
DICOMwebRequired for imaging exchange. Not implemented.NEMA / DICOM Standards CommitteePS3.18PlannedNot testedNone
ISO 20022Required for payer settlement. Not implemented.ISONot chosenPlannedNot testedNone

Where the programme stands

Every figure carries its source and the time it was true

Connected facilities

Onboarding begins Q4 2026 with 12 pilot facilities in Dar es Salaam and Mwanza. The count appears here when the first one connects.

Facility registry

Standards conformance

The mediator implements FHIR R4 and publishes its CapabilityStatement openly. No independent conformance suite has been run against it.

Certification register