Suitable for client review and workflow discussion, not production clinical use.
Prototype roadmap
A stakeholder view of what the heart failure portal prototype supports today, what is planned next, and how privacy and security should be considered before production use.
Suitable for client review and workflow discussion, not production clinical use.
Public, patient, clinician, curator, committee, and administrator roles are represented.
Resources, FAQs, referral items, pages, documents, and media are managed through CMS tools.
What is currently implemented
The current codebase supports public information, role-aware content, CMS-managed resources, and demonstration administration areas.
Homepage content, safety messaging, resource navigation, FAQs, search entry point, and public visitor access.
Users can be assigned public, patient, clinician, curator, committee, or administrator roles with filtered page and snippet visibility.
Curated resource items support external links, uploaded documents, media, audience labels, publication status, and broken-link flags.
Referral items can be managed as active external links or uploaded documents and are displayed from the resource library.
Published FAQ records are managed in Wagtail and filtered for the current visitor role.
Curators can review resource counts, recent resources, referral tools, FAQ tools, and Wagtail content management links.
Administrators can view user totals, pending clinician approvals, rejected clinicians, demonstration registry metrics, and account tools.
Clinician accounts include pending, approved, and rejected statuses, with approve and reject actions available to administrators.
Planned improvements
These items reflect the client discussion and would need further design, security review, and implementation planning.
Privacy and security design
The prototype should be treated as a foundation for privacy-aware design, not as a production system.
Use security by design from the start, especially before any sensitive health data is introduced.
Keep admin, curator, patient, clinician, and committee access separated by clear roles and permissions.
Avoid unnecessary patient data collection and keep patient profiles minimal.
Verify clinicians before granting access to sensitive clinical areas or restricted resources.
Plan encrypted storage, encrypted backups, and secure operational procedures before production rollout.
Design technical administration so support staff do not need to view sensitive user data.
Secure future notifications so SMS and email messages do not expose private health information.
Prototype limitations
These limits should be clearly understood during demonstrations and before any production planning.
Not production-ready and not approved for real clinical workflows.
Not handling real sensitive patient data in the current phase.
No full heart failure registry integration yet.
No real SMS or email notification system yet.
No complete MFA implementation yet.
No full clinician vetting workflow beyond the current approval status controls.
No mobile app in the current phase.
No full editorial workflow beyond Wagtail and curator-managed publishing controls.
External resources are mainly linked or referenced rather than copied into the portal.
Future scalability
The current heart failure prototype can inform a repeatable model for other disease-specific portals: public education, role-based professional content, curated resources, governance dashboards, and future secure data integration.