One health record, wherever a Tanzanian is treated.
THOS keeps one patient record and one identity across every facility that treats a person. It sits alongside the systems a hospital already runs, over published standards.
Built by Laetoli (T) Limited, Dar es Salaam.
Facility onboarding starts Q4 2026. The ledger below marks how far each piece has got.
What THOS does
| Capability | State | Standard | Where to verify |
|---|---|---|---|
| One patient identity across facilities | Built, not in service | HL7 FHIR R4 · Patient/$match | CapabilityStatement at /metadata |
| One record, versioned, that travels with the patient | Built, not in service | HL7 FHIR R4 (4.0.1) | CapabilityStatement at /metadata |
| Consent gates every read and every write | Built, not in service | HL7 FHIR R4 · Consent | supabase/functions/il/index.ts |
| Emergency access, recorded against the clinician who used it | Built, not in service | No applicable standard | supabase/functions/il/index.ts |
| Tamper-evident audit trail, written even when access is denied | Built, not in service | HL7 FHIR R4 · AuditEvent | Walk the chain: GET /audit/$verify |
| Results and observations | Built, not in service | HL7 FHIR R4 · Observation, DiagnosticReport | CapabilityStatement at /metadata |
| Orders for laboratory and imaging | Built, not in service | HL7 FHIR R4 · ServiceRequest | CapabilityStatement at /metadata |
| Electronic prescribing | Built, not in service | HL7 FHIR R4 · MedicationRequest | CapabilityStatement at /metadata |
| Referrals between facilities | Built, not in service | HL7 FHIR R4 · ServiceRequest, Communication | CapabilityStatement at /metadata |
| Appointments and scheduling | Built, not in service | HL7 FHIR R4 · Appointment | CapabilityStatement at /metadata |
| Continues working when the connection drops, and replays afterwards | Built, not in service | No applicable standard | apps/thos/src/lib/offlineQueue.ts |
| Clinical notes and documentsDocumentReference is not among the resource types the interoperability layer accepts, so a note is written to the device and does not reach the national record. Until it is added, a clinical note does not travel with the patient. | Partial | HL7 FHIR R4 · DocumentReference | CapabilityStatement at /metadata |
| Coded clinical terminologyThe mediator recognises all four systems, but the curated national subset is roughly forty concepts and an unrecognised code is logged rather than rejected: deliberately, so a missing row cannot block care. Coded data is therefore not yet reliable enough to report on. | Partial | LOINC · SNOMED CT · ICD-10 · ICD-11 | supabase/migrations/0038_terminology_seed.sql |
| Clinical records signed by the clinician who wrote themThe application signs each resource and stores the signature on it, but the interoperability layer has no signature handling, so nothing verifies it on the way in or on the way out. A signature nobody checks is a record of intent, not a guarantee of authorship. | Partial | JWS (RFC 7515) · FHIR provenance pattern | apps/thos/src/lib/api.ts |
| Admissions and transfers from a facility’s existing system | Planned | HL7 v2 ADT | Not yet verifiable |
| Imaging exchange | Planned | DICOMweb | Not yet verifiable |
| Payer settlement and claims | Planned | ISO 20022 | Not yet verifiable |
| Patient registration, and review of what citizens submitNone of the three checks a reviewer needs is connected. There is no NIDA identity service, no SMS gateway and no NHIF or CHF eligibility endpoint, so a submission is approved on what the citizen typed and the screen says so on every row. | Partial | OpenHIE Client Registry | supabase/migrations/0067_preadmin_registration.sql |
| Citizen access without a smartphone | Planned | SMS/USSD | apps/thos/src/lib/ussd.ts |
The architecture
Solid: carrying traffic today. Dashed: planned, not yet built. The mediator’s CapabilityStatement is public at /metadata: a conformance claim nobody can retrieve is not a conformance claim.
Reach, by region
Boundaries: geoBoundaries (gbOpen), ADM1, CC BY 4.0. 30 regions. Tanzania has 31: Songwe is absent from the open release, so Mbeya here covers both.
Onboarding begins in Q4 2026 with 12 pilot facilities across Dar es Salaam and Mwanza. No facility is connected today; this map prints the count when one is.
- Dar es Salaam
- Pilot cohort
- Mwanza
- Pilot cohort
- Pilot cohort2
- Not yet scheduled28
Source: onboarding plan · As of
The family
16 products carry the THOS name: renal, maternity, laboratory, blood, medicines. All share the one record drawn above.
- THOSMama
- Maternal and child health
- Awaiting migration
- THOSRenal
- Nephrology and dialysis
- Awaiting migration
- THOSDerma
- Dermatology
- Awaiting migration
- THOSSentinel
- Disease surveillance
- Shelved
Each one in detail: its host, what flows, and what was verified
Standards and conformance
Nothing here has been independently tested yet. THOS implements FHIR R4 and publishes its CapabilityStatement openly, and that much is checkable today: but implementing a specification and passing its test suite are two different claims, and only the first is true. The “last tested” column will carry a date when it has one to carry.
| Standard | Publisher | Version | Conformance | Last tested | Report |
|---|---|---|---|---|---|
| HL7 FHIREighteen resource types, versioned, with read, vread, search, create, update and transaction. The server publishes its own CapabilityStatement unauthenticated, so the claim is checkable without an account. Touchstone conformance testing has not been run. | HL7 International | R4 (4.0.1) | Implemented, untested | Not tested | None |
| OpenHIE architectureInteroperability layer, client registry, terminology service and shared health record are present and separated, and the record is reachable only through the mediator. No OpenHIE conformance workflow has been run against it. | OpenHIE | Mediator pattern | Implemented, untested | Not tested | None |
| LOINCThirty-one codes are curated in the national subset. Codes outside it are recorded and logged rather than rejected, so laboratory data is coded but not yet reliably coded. | Regenstrief Institute | 2.78 | Partial | Not tested | None |
| SNOMED CTSix concepts are curated. Distributing SNOMED CT nationally requires a member licence held by the country, and confirming Tanzania’s standing is a procurement question that has to be settled before this row can move. | SNOMED International | International edition | Partial | Not tested | None |
| ICD-11The system recognises ICD-11 MMS and ICD-10 URIs and validates against a curated subset. National reporting still runs on ICD-10, so both are accepted deliberately. | World Health Organization | MMS | Partial | Not tested | None |
| OAuth 2.0Bearer tokens are verified against a remote JWKS with an issuer check. The CapabilityStatement declares OAuth as the security service. SMART on FHIR app launch is not implemented. | IETF | RFC 6749 | Implemented, untested | Not tested | None |
| JSON Web SignatureResources are signed by the writing application and the signature is stored on the resource. The interoperability layer does not verify it, so authorship is asserted rather than proven. See the capability ledger. | IETF | RFC 7515 | Partial | Not tested | None |
| HL7 v2Required to take admissions and transfers from the systems Tanzanian hospitals already run. Not implemented. | HL7 International | 2.5.1 (ADT) | Planned | Not tested | None |
| DICOMwebRequired for imaging exchange. Not implemented. | NEMA / DICOM Standards Committee | PS3.18 | Planned | Not tested | None |
| ISO 20022Required for payer settlement. Not implemented. | ISO | Not chosen | Planned | Not tested | None |
Where the programme stands
Connected facilities
Onboarding begins Q4 2026 with 12 pilot facilities in Dar es Salaam and Mwanza. The count appears here when the first one connects.
Standards conformance
The mediator implements FHIR R4 and publishes its CapabilityStatement openly. No independent conformance suite has been run against it.