DFD — Patient Portal (PHI)
Level-1 flow of a patient portal across public internet, a portal DMZ and the clinical PHI network, balancing 14 nodes against 17 flows and listing all 10 boundary crossings as the attack surface.
Make it your own.
title "Patient portal — appointments and results"
level 1
entity Patient
entity Clinician
entity "Pathology lab (LIS)"
entity "SMS gateway"
entity "NHS login"
process 1 "Authenticate patient"
process 2 "Book appointment"
process 3 "Release test result"
process 4 "Send reminder"
process 5 "Ingest lab result"
store D1 "Patient demographics"
store D2 "Appointment slots"
store D3 "Results (HL7 FHIR)"
store D4 "Access audit log"
boundary "Public internet" { Patient, "SMS gateway", "NHS login" }
boundary "Portal DMZ" { 1, 2, 4 }
boundary "Clinical network (PHI)" { 3, 5, D1, D2, D3, D4, Clinician, "Pathology lab (LIS)" }
Patient -> 1 : "email + one-time code"
1 -> "NHS login" : "OIDC auth request"
"NHS login" -> 1 : "id_token (LOA2)"
1 -> D1 : "session + NHS number"
D1 -> 2 : "patient record"
Patient -> 2 : "slot request"
2 -> D2 : "slot hold (15 min)"
D2 -> 2 : "free slots"
2 -> 4 : "booking confirmed"
4 -> "SMS gateway" : "reminder text"
"Pathology lab (LIS)" -> 5 : "HL7 ORU^R01"
5 -> D3 : "validated result"
D3 -> 3 : "result + reference range"
Clinician -> 3 : "authorise release"
D4 -> 3 : "prior access check"
3 -> D4 : "who read what"
3 -> Patient : "result + clinician note"