Patient-issued consent
Every grant is a W3C Verifiable Credential signed by the patient wallet. Hospitals verify the signature on every read; they cannot mint or replay a grant.
24-hour cross-hospital bridge
A referral used to be a PDF. The bridge is an HMAC-signed channel that the receiver hospital opens against the ledger. The token rotates on first open, so a leaked string is worthless.
Hash-chained audit ledger
Every access is appended to a tamper-evident chain. Each row carries the previous row’s hash, and we pin each row to Solana devnet so the chain is verifiable from any device.
15-second AI risk loop
The risk-score engine runs against the patient’s rolling vitals. Unconscious patients trigger a 1-of-3 multi-approval so a verified clinician at another hospital can open access in under a minute.
Emergency response
SOS. Nobody has to press anything.
The risk engine scores every reading your devices stream. The moment a score crosses the critical threshold, VitalMesh raises an emergency request, books an ambulance, reserves a bed at a hospital that can take you, and pulls the on-call clinician onto the case — in that order, without a button press.
It runs on the server, so it does not stop when you close the app. The dashboard shows each stage as it happens, and if the reading was a false alarm you can stand it down with I’m okay now — one control, no digging.
- 1
Scored
Your devices stream vitals continuously. The AI risk engine scores every reading; a mild anomaly is logged, a critical one escalates.
- 2
Emergency raised
An emergency request is created against your record and the on-call clinician is notified. Duplicate readings collapse onto one request instead of raising several.
- 3
Ambulance dispatched
A responder is booked and given a pickup point. If you shared a location, that is used; otherwise the request falls back to a city-level pickup point and the dashboard prompts you to share a precise one.
- 4
Bed reserved
A hospital that can take you is selected by distance and capability, and a bed is held so you are not queued on arrival.
- 5
Packet sent
Your vitals, ECG, allergies and current medicines go to the receiving team before you arrive, so treatment starts at handover rather than at triage.
A wrong reading does not dispatch a wrong ambulance. Multi-device quorum and a gradient check have to agree before the pipeline is allowed to escalate.
How it works
A read with permission attached.
The patient issues the grant. A verified clinician reads it. The ledger records the access.
Across hospitals
The record follows the patient.
A 24-hour HMAC-signed bridge lets a receiving hospital read authorised records. Revocation propagates within one second.
See the live networkPlans
Start small. Add reach.
Questions
Before you connect.
- 01
Who owns the consent grant — the patient or the hospital?
The patient. Every grant is signed by the patient wallet at issue time and held in a hash-chained ledger. Hospitals verify the signature on every read; they cannot mint a grant without the patient wallet signing it.
- 02
How does the cross-hospital bridge differ from a referral?
A referral is a one-shot document. The bridge is a 24-hour HMAC-signed channel: the patient authorises it once, the receiver hospital opens an SSE stream against the ledger, and the token rotates on first open.
- 03
Why hash-chain the audit log?
A database row is mutable. The chain pins every row to the previous row’s hash, so any tampering with a historical entry breaks the link and surfaces when integrity is checked.
- 04
How long does hospital onboarding take?
Two weeks: SSO setup, EHR/HIS webhook integration, clinician roster import, and a shadow-mode run before cutover.
- 05
Can family members see my data without my consent?
No. Family accounts default to zero access. The patient explicitly grants a viewer with an expiry and can revoke access at any time.
Ready to connect a hospital?
Run the 30-day Hospital pilot with a dedicated onboarding engineer.