Skip to content
Data flow diagram templates

DFD — Patient Portal (PHI)

Level-1 flow of a patient portal across public internet, a portal DMZ and the clinical PHI network, balancing 14 nodes against 17 flows and listing all 10 boundary crossings as the attack surface.

Template previewData flow diagram
Patient portal — appointments and resultsLEVEL 1Public internetPortal DMZClinical network (PHI)PatientClinicianPathology lab(LIS)SMS gatewayNHS login1Authenticatepatient2Book appointment3Release test result4Send reminder5Ingest lab resultD1PatientdemographicsD2Appointment slotsD3Results (HL7 FHIR)D4Access audit logemail + one-time codeOIDC auth requestsession + NHS numberpatient recordslot requestslot hold (15 min)booking confirmedreminder textHL7 ORU^R01validated resultresult + reference rangeauthorise releasewho read whatresult + clinician noteid_token (LOA2)free slotsprior access check5 entities · 5 processes · 4 stores · 17 flows · 10 boundary crossingsCrossing — “email + one-time code”: Patient (Public internet) → Authenticate patient (Portal DMZ).Crossing — “OIDC auth request”: Authenticate patient (Portal DMZ) → NHS login (Public internet).Crossing — “id_token (LOA2)”: NHS login (Public internet) → Authenticate patient (Portal DMZ).Crossing — “session + NHS number”: Authenticate patient (Portal DMZ) → Patient demographics (Clinical network (PHI)).Crossing — “patient record”: Patient demographics (Clinical network (PHI)) → Book appointment (Portal DMZ).Crossing — “slot request”: Patient (Public internet) → Book appointment (Portal DMZ).Crossing — “slot hold (15 min)”: Book appointment (Portal DMZ) → Appointment slots (Clinical network (PHI)).Crossing — “free slots”: Appointment slots (Clinical network (PHI)) → Book appointment (Portal DMZ).Crossing — “reminder text”: Send reminder (Portal DMZ) → SMS gateway (Public internet).Crossing — “result + clinician note”: Release test result (Clinical network (PHI)) → Patient (Public internet).

Make it your own.

title "Patient portal — appointments and results"
level 1

entity Patient
entity Clinician
entity "Pathology lab (LIS)"
entity "SMS gateway"
entity "NHS login"

process 1 "Authenticate patient"
process 2 "Book appointment"
process 3 "Release test result"
process 4 "Send reminder"
process 5 "Ingest lab result"

store D1 "Patient demographics"
store D2 "Appointment slots"
store D3 "Results (HL7 FHIR)"
store D4 "Access audit log"

boundary "Public internet" { Patient, "SMS gateway", "NHS login" }
boundary "Portal DMZ" { 1, 2, 4 }
boundary "Clinical network (PHI)" { 3, 5, D1, D2, D3, D4, Clinician, "Pathology lab (LIS)" }

Patient -> 1 : "email + one-time code"
1 -> "NHS login" : "OIDC auth request"
"NHS login" -> 1 : "id_token (LOA2)"
1 -> D1 : "session + NHS number"
D1 -> 2 : "patient record"
Patient -> 2 : "slot request"
2 -> D2 : "slot hold (15 min)"
D2 -> 2 : "free slots"
2 -> 4 : "booking confirmed"
4 -> "SMS gateway" : "reminder text"
"Pathology lab (LIS)" -> 5 : "HL7 ORU^R01"
5 -> D3 : "validated result"
D3 -> 3 : "result + reference range"
Clinician -> 3 : "authorise release"
D4 -> 3 : "prior access check"
3 -> D4 : "who read what"
3 -> Patient : "result + clinician note"