Tallinn hospitals share a safer cloud record
A new clinical data exchange is trying to make handoffs faster without asking patients to give up meaningful consent.
2 min read

The shared record works. The interesting part is the audit trail, which is the piece patients ask about and the piece that took longest to get right.
What is shared, and what is not
Not a single database. A set of interfaces over records that stay with the institution that created them, with a national index that knows where to look.
That architecture was chosen for governance reasons rather than technical ones. A central store would have been simpler and would have concentrated both the security risk and the political argument in one place. Federation keeps custody with the clinician who is accountable for the record.
Who holds the record is a governance decision that then becomes an architecture.
The audit trail is the product
Every access is logged, and the patient can see the log: who looked, when, and under what justification.
That visibility changed clinician behaviour immediately and in the expected direction — casual browsing of records disappeared once it became attributable. It also produced a category of query nobody anticipated, from patients asking why a department they had never visited had accessed their file. Most had legitimate answers involving referrals or laboratory work. The fact that the answers had to be given at all is the control working.
Emergency access
The hard case is the unconscious patient whose consent cannot be obtained.
The system permits break-glass access with a mandatory reason and an automatic review. The review is the part that matters and the part that is expensive: every break-glass event is examined by a named person, and the volume of events is the number that determines whether that stays sustainable.
Two hospitals have seen break-glass rates high enough to suggest it is being used as a convenience path around a slow consent flow, which is exactly the failure mode the review exists to detect.
What to watch
Watch break-glass rates by department. Watch whether the patient-facing log survives its first serious misinterpretation, since a log people cannot interpret generates alarm rather than trust. And watch whether the review of break-glass events keeps a named reviewer as volumes grow.



