Personal health intelligence, with boundaries

Build dossier · Not shipped · Updated July 25, 2026

Food, supplements, laboratory results, exercise, sleep, family history, and genetics usually live in separate systems. This dossier designs one consent-first record that can reveal patterns, prepare better questions for a clinician, and make uncertainty visible, without turning a wellness product into an unvalidated diagnostic.

Boundary: this is a portfolio build plan, not a deployed health product. The intended use is wellness and research-support: organize records, describe trends, and support clinician conversations. It would not diagnose disease, prescribe medication or supplements, calculate a disease-specific risk score, or replace professional care.

The product contract

A useful home screen answers three modest questions: what changed, what evidence supports it, and what remains unknown? A person could review a twelve-week trend joining meal composition, activity, sleep, and a lab result; inspect the original record behind any point; and export a concise, timestamped summary for a clinician. The system describes associations as associations. It does not turn temporal proximity into causality.

Each insight includes its source, observation window, missing-data pattern, and uncertainty. Manual entries are labeled manual; estimated nutrients stay estimated; device measurements retain their vendor and sampling cadence. A user can disconnect a source, revoke future access, and request deletion of derived features tied to that source.

A personal record spine

Consent-first personal health intelligence architecture Food, laboratory, supplement, activity, sleep, history, and optional genetic records pass through source-specific consent and provenance controls. They are normalized into a longitudinal record, transformed into time-windowed features, and shown as descriptive trends and clinician-ready exports with uncertainty. USER-CONTROLLED SOURCES Food + supplements manual / barcode / photo review Labs + clinical record FHIR import / file / manual Activity + sleep device + self report History + genetics family history + optional import separate, revocable consent Consent + provenance purpose per source original value + unit recorded / observed time transform version quality + missingness revocation propagates to derived records Longitudinal record FHIR-shaped resources FoodData nutrients raw values preserved Feature windows daily / weekly / lab-to-lab personal baseline uncertainty retained Wellness view descriptive trends evidence links missing-data flags uncertainty bands Safe handoff clinician-ready export not diagnosis or dosing PRIVACY AND SAFETY CONTROL PLANE least-privilege access · encryption · audit trail · retention controls · deletion verification · abstention

The original observation is never replaced by a cleaned feature. A visible lineage chain connects the two.

The interoperability layer would use HL7 FHIR R5 where records arrive in FHIR form, including the NutritionIntake resource for recorded consumption. The USDA FoodData Central API can supply food and nutrient reference data. Neither vocabulary solves measurement error: restaurant portions, recipes, supplements, wearable gaps, and laboratory reference ranges still need explicit provenance and uncertainty.

South Asian health without an ethnicity shortcut

South Asian cardiometabolic risk deserves focused evaluation, not a hard-coded “South Asian multiplier.” A review of findings from the MASALA cohort describes elevated type 2 diabetes and atherosclerotic cardiovascular disease risk alongside differences in insulin secretion, insulin resistance, and body composition. An American Society for Preventive Cardiology practice statement likewise addresses risk assessment and prevention for South Asian adults in the United States.

The engineering response is to measure the individual: longitudinal labs, blood pressure, waist and body-composition measures when available, activity, dietary pattern, sleep, family history, medication, and social context. Ancestry and self-identified background can define evaluation strata and prompt culturally relevant questions, but they should not stand in for those observations. The app would test whether errors and calibration differ within South Asian subgroups and across intersections such as age and sex; it would not assume that a diverse population is internally uniform.

Dietary support should also be evaluated in context. A MASALA analysis of a Mediterranean-style diet pattern offers population evidence worth representing, but not a basis for claiming a personalized treatment effect from a person’s meal log.

Genetics is optional, separate, and uncertainty-heavy

Genetic data would require a distinct consent flow, storage boundary, deletion path, and explanation of secondary-use risk. The normalized representation can follow the FHIR Genomics Reporting implementation guide, while the user-facing layer keeps variants, family history, and phenotype observations separate.

I would not ship a polygenic score in the first version. NIH’s report on the All of Us genomic dataset notes both the scale of newly identified variation and the importance of diversity in genomic research. That reinforces the validation requirement: a genetics-based feature needs documented ancestry coverage, uncertainty, and subgroup performance before it can inform even a research view. NIH’s summary is here.

Validation before personalization

Validation plan for personal health insights A synthetic public demo comes first, followed by consented retrospective data split by person and time. Performance is checked for data integrity, calibration, subgroup gaps, and safe abstention before any prospective wellness pilot. STAGED EVIDENCE, WITH A STOP GATE AT EACH HANDOFF 1 · Public demo fully synthetic people planted edge cases no real health records 2 · Retrospective consented, de-identified split by person + time no cross-person leakage 3 · Silent trial prospective, no advice drift + missingness clinician review 4 · Wellness pilot descriptive insights only feedback + safety review requires prior gates RELEASE MATRIX Data integrity units · lineage · missingness Calibration reliability · interval coverage Fairness error + calibration gaps Abstention coverage · unsafe-output audit STOP / REDESIGN broken provenance · material subgroup gap · poor calibration · boundary-violating advice A larger average score cannot compensate for a safety or fairness failure.

The public portfolio artifact would use synthetic records with planted unit errors, gaps, and confounders so the audit can be inspected without exposing anyone’s health data.

The first model should be a transparent baseline: personal rolling averages, robust trend estimates, and rules for incompatible units and implausible values. Learned models enter only where they improve a named task, such as meal parsing or missingness-aware forecasting. Evaluation is split by person and time, preventing records from the same person, or their future, from leaking across the boundary.

QuestionMetric or reviewRequired behavior
Is the record correct? Unit, range, timestamp, and source-lineage checks Quarantine conflicts; never silently coerce
Is uncertainty honest? Calibration and interval coverage over time Widen intervals or abstain as evidence weakens
Who receives worse output? Error, coverage, and calibration by prespecified intersections Investigate material gaps before release
Does it stay in scope? Expert review of generated insights and red-team prompts Block diagnosis, dosing, and treatment language

Regulatory and safety design is product design

The FDA’s clinical decision support materials make intended use and software function central to the analysis. A feature that produces a disease-specific probability or directs prevention or treatment is materially different from a wellness trend view. The roadmap therefore treats any movement toward diagnosis or treatment as a new product boundary requiring dedicated regulatory, clinical, privacy, and security review, not as a prompt change.

Build sequence and definition of done

  1. Synthetic record: build FHIR-shaped and food-log fixtures with known gaps, unit conflicts, corrections, and revoked consent.
  2. Provenance UI: make every chart point traceable to its raw record and transformation; implement export and deletion.
  3. Descriptive baseline: ship trends, data-quality warnings, and clinician-ready summaries with no disease prediction.
  4. Validation harness: add calibration, temporal leakage tests, subgroup dashboards, abstention tests, and boundary red-teaming before any real-user pilot.

The portfolio version is done when reviewers can run the synthetic cohort, reproduce every chart and audit result, revoke a source and see its derivatives disappear, and verify that unsafe requests produce a clear boundary rather than confident medical language.

Primary and institutional sources

  1. HL7, FHIR Release 5, NutritionIntake, and the Genomics Reporting implementation guide.
  2. U.S. Department of Agriculture, FoodData Central API guide.
  3. Kanaya and colleagues, review of cardiometabolic findings from the MASALA study.
  4. American Society for Preventive Cardiology, South Asian cardiovascular prevention practice statement.
  5. National Institutes of Health, All of Us genomic variation announcement.
  6. U.S. Food and Drug Administration, clinical decision support software function guidance materials.