Monitoring is not understanding ended on a line I have not been able to drop: the patient is the only thread that runs through their own care, and the patient has no app. The integration job, seeing the whole patient across fragmented providers and noticing that the second stroke is a recurrence and not a fresh event, lands on the person least equipped to do it. So build the app. The moment you try, you hit the same wall as everywhere else: what funds it. I worked the clean version of that question on local trades. This is the hard version, and the difference is the lesson.

The argument in five lines

  • The app is a store of data organised to surface patterns. It never advises. Advice is a separate layer attached to a real clinician.
  • That firewall is the design: it keeps the store clear of medical-device rules and keeps the liability where the clinical judgment is.
  • Ads are not an option. Targeting on diagnoses is the nightmare case and mostly illegal, so "if not ads, what?" is a hard constraint here, not a preference.
  • Fund the core as a mutual: everyone has this problem, so tiny universal contributions make it cheap per head and cheaper as it grows. Family plans, free for those who cannot pay, and sponsored memberships from a city or insurer for the rest.
  • Keep the dangerous money out of the core: medic and insurer money funds the separate advice layer and sponsors access, never the pattern store. The funding model is the governance model.

The app that should exist

The gap is not a missing feature in some EHR. It is the absence of a layer that belongs to the patient. Every provider has a system; the cardiologist sees the heart, the neurologist the brain, the pharmacy the script, and each closes its own case as a success. Nobody owns the integration, and the one person positioned to is sick, untrained, and without tools. The thing that should exist is a patient-controlled layer that pulls records together, keeps the whole-patient picture, and raises a hand when a symptom recurs under the same treatment. Not a new silo. An agency layer the patient owns and the providers feed.

And it has a hard line drawn through it. The app is a store of data, organised to surface patterns. It does not advise. It can show that a symptom has recurred three times under the same drug; it does not tell you what to do about that. Advice is a separate layer, attached to a real clinician, and funded separately. That separation is not a disclaimer, it is the architecture. It keeps the store clear of medical-device regulation, keeps the liability where the clinical judgment actually lives, and keeps the patient holding a tool that informs them rather than one that decides for them.

patient side clinical side cardiology neurology pharmacy labs data store surfaces patterns "recurred 3x on the same drug" never advises firewall patient consents per share consented share advice layer a real clinician reads, interprets, advises carries the liability funded by: mutual members funded by: medics / insurers
The store lives on the patient side, gathers records, and surfaces patterns without ever advising. Advice happens only across the firewall, in a clinician-linked layer that reads what the patient consents to share and carries the clinical liability. The wall is also the funding boundary: the store is a member-owned mutual, the advice layer is where medic and insurer money belongs.

Ads are not just bad here, they are radioactive

In the trades version, advertising was the welfare-negative incumbent. In health it is off the table. Targeting a person on the basis of their diagnosis is the worst thing the surveillance model produces, and it is largely illegal: health data is special-category under GDPR and protected under HIPAA. That changes the funding question from a preference into a constraint.

Everywhere else, "if not ads, then what?" is a values question. In health it is a legal one. The answer cannot route through attention, which removes the cheap option and forces the hard one.

The rent does not disappear, it changes clothes. Instead of consumer ad-targeting it is EHR vendor lock-in, data brokering, and the quiet sale of de-identified records. The thing extracting value is the same shape as always. It just wears a compliance badge.

Why this is the harder case

Set the two examples side by side and the friction is obvious.

Local tradesThe patient's app
Revenue lineProvider member fees, clean and recurringNo clean payer; the sickest can least afford to pay
RegulationLightHeavy (special-category data, possible medical-device rules), with a patient-access tailwind from the EHDS
LiabilitySmall claims if the plumber breaks a pipeContained by the firewall: the store surfaces facts, a clinician owns any advice and its liability
The hard partPosting a listingGetting data out of provider EHRs at all
As a targetA city's job boardThe most valuable, most dangerous data store there is

The member-fee model that made the trades co-op self-funding does not transfer. Charge the patient and you rebuild the access tier the subscription model always creates, except now the people priced out are the chronically ill, who are exactly the ones the recurrence problem is about. So the clean answer fails, and you have to find the payer somewhere else.

The payer hiding in the last article

It was there the whole time. Monitoring is not understanding made the case that the recurrence is the question nobody asks, the second stroke logged as a fresh event. The thing that article did not say out loud is that the missed recurrence is not free. Someone pays for the second stroke, the readmission, the avoidable ICU week.

recurrence not caught second event readmission, stroke cost lands on the payer so the payer has a reason to fund catching it the only actor in health whose interest in prevention is structural
Prevention has a natural payer: the entity that eats the cost of the recurrence. The insurer, or in a single-payer system the public budget, saves real money when integration catches the second event before it happens.

Name who pays for the second stroke and you have found the actor whose interest in prevention is structural rather than charitable. That is who will sponsor access and fund the advice, even while the core stays a member-owned mutual.

Keeping the dangerous money out of the core

This is where the funding thesis usually bites its own example, and the design defuses it before governance even gets involved. Money that makes an app sustainable can quietly make it serve the wrong master: an app whose core is paid for by an insurer drifts toward optimising the insurer's cost, with flag-to-deny, rationing, and surveillance. The defence is structural. The core, the pattern-surfacing store, is funded by its members as a mutual, so no insurer pays for it and none can own it.

Insurer and medic money is confined to two places where it does the least harm: the separate advice layer, where a clinical relationship is appropriate anyway, and the sponsorship of access for people who cannot pay, which funds a seat rather than steering the product. What is left is the residual risk that a sponsor leans on the thing it helps pay for, and that is what the governance guards are for.

GuardWhat it enforces
Patient supermajorityAnything clinical or data-sharing needs patient-member control, not payer or provider
Sustainability seat, not a steering oneThe payer funds and gets aggregate outcome metrics, never identifiable data and never a product veto
Surface, do not policeThe app flags and informs the patient; it does not deny care, ration, or report upstream
Capture is visibleOpen governance docs, and a federation that can defederate a compromised instance

What actually funds it: a mutual

The shape is the same layered, insulated stack as the trades model, but the core revenue is a mutual rather than a provider fee, and that changes everything. The insight is that everyone has this problem. Universal problems are what mutuals are for: a very small contribution from many people funds the commons, and because the cost is mostly fixed, the price per head falls as the membership grows.

A mutual earns back the one thing ads got right. Ads gave rich and poor the same product because a third party paid. A mutual gives rich and poor the same product because the many cover the few. Same universal access, no surveillance, no rent.

On the member side that is a few tiers, all kept deliberately cheap:

  • A small individual contribution, low by design and trending lower as usage grows.
  • A family plan: pay once, cover the household, since the integration problem runs in families anyway.
  • Free for those who cannot afford it, cross-subsidised by paying members.
  • Sponsored memberships, the "welfare family" idea, where a city or an insurer pays the contribution for people who cannot, the way a library card is funded for everyone.
LayerFunded byNote
Interop & consent protocolNLnet, Sovereign Tech Fund, Digital Europe / EHDS budgetsPatient-mediated exchange (FHIR), identity and consent. The EHDS access right is a tailwind.
Pattern-surfacing store (the core)Mutual member contributions; family plans; cross-subsidyMember-owned, free at the point of need, cheaper per head as it grows.
Access for those who can't paySponsored memberships from a city or insurerThe sponsor funds a seat, never the product.
Advice layer (medic-linked)Medics and/or insurersA separate clinical layer, where clinical money and liability belong.
StewardshipFoundation outside the operating jurisdiction plus R&D grantsHolds the consent protocol, copyleft so no one forks it closed.

Federation matters even more here

A central store of everyone's health records is the worst object you can build: a catastrophic breach target and a capture magnet that insurers, the state, and advertisers all want. The federated design is not stylistic here, it is survival. Data stays patient-side or in a store the patient chooses, and the protocol only coordinates consented exchange. No global aggregation, which is the thing that concentrates power and corrupts. It is also the live tension inside the EHDS itself: even a well-meant central health-data space is a honeypot, and the defence is to keep the patient layer federated rather than pooled.

The honest constraints

  • Regulation is real, and the firewall is the answer to most of it. Health data stays special-category, but because the store surfaces patterns and never advises, the medical-device burden falls on the separate clinical layer where it belongs. Hold that line and it stays a line.
  • Providers benefit from lock-in, so getting data out is a fight even where the law grants access. Interop (FHIR adoption) is uneven and is the genuinely hard engineering.
  • Liability cuts both ways: harm from a wrong flag, and harm from a missed one. Governance and scope have to be conservative.
  • Cold start is easier per patient than the trades case, since one person aggregating their own records is useful on day one, but the provider-access fights are harder.

The takeaway

The trades example showed the funding model working cleanly. This one shows it under load, and under load the answer turns out to be two design moves, not one clever funder: a firewall that keeps the store from ever advising, and a mutual that keeps the core owned by its members. Get those right and the dangerous money can be let in at the edges, the advice layer and sponsored access, without taking the middle.

That is the whole argument from the trades piece, at the highest stakes it comes in: the funding model is the governance model. Nowhere is that truer than in the app the patient still does not have.

The patient is the only thread that runs through their own care, yet nobody owns the integration across fragmented providers. The cardiologist sees the heart, the neurologist the brain, the pharmacy the script. So build a patient-owned app that pulls the records together and flags when a symptom recurs under the same treatment. The moment you try, you hit the wall: who funds it.

The app, and its one line

The app is a store of data organised to surface patterns. It never advises. It can show a symptom recurred three times on one drug; it does not say what to do. Advice is a separate layer, attached to a real clinician and funded separately. That firewall is the architecture, not a disclaimer: it keeps the store clear of medical-device rules and the liability where clinical judgment lives.

No ads, no patient fees

Targeting a person on their diagnosis is the worst thing surveillance produces, and it is largely illegal: health data is special-category under GDPR, protected under HIPAA. So the no-ads question is a legal constraint here, not a values one.

Everywhere else, the no-ads question is a preference. In health it is a constraint.

Charging the patient fails: it rebuilds the access tier subscriptions create, pricing out the chronically ill, exactly the ones the recurrence problem is about.

Who pays for the second stroke

The missed recurrence is not free. Someone pays for the second stroke, the readmission, the avoidable ICU week. That payer's interest in prevention is structural, not charitable: the insurer, or a single-payer public budget. They sponsor access and fund the advice layer, never the core.

A mutual, money at the edges

Everyone has this problem, and universal problems are what mutuals are for. A tiny contribution from many funds the commons, and the price per head falls as membership grows. The member side is a few deliberately cheap tiers:

  • A small individual contribution, lower as usage scales.
  • A family plan, since the integration problem runs in families.
  • Free for those who cannot pay, cross-subsidised by members.
  • Sponsored memberships, a city or insurer covering someone who cannot, the way a library card is funded.

Members own the core, so no insurer pays for it or can capture it. Insurer and medic money stays at the edges: the advice layer and sponsored access, never the pattern store. Governance guards hold the residual risk.

Federation is survival, not style: a central store of everyone's records is a capture magnet, so data stays patient-side. Under load the answer is two moves, not one clever funder: a firewall that stops the store advising, and a mutual that keeps the core member-owned. The funding model is the governance model.


This is the hard companion to the local-trades funding piece, and the sequel to monitoring is not understanding. Worked through to stress-test the model, not to claim a plan. The point is that the model survives the harder case, and gets more honest when it does.