Strict-typing patches + Arabic RTL locales + E2E tests across 9 locales.
Transparency by design.
My Data My Care progressively releases the key technical components of its sovereign health architecture. Not all at once, not as marketing — following a public roadmap with explicit licences.
- MIT licence
- AGPL licence
- Public roadmap
Why open source
Open source isn't an end in itself but the lever for a broader promise: patient sovereignty rests on the ability to audit the code, not on blind trust.
Independent audit possible
Any security researcher, DPO or hospital CIO can read the code of the critical components without an NDA or special request. Transparency isn't a bonus, it's a prerequisite.
Real technical portability
An open source FHIR R4 FR Core SDK lets any patient or organisation leave MDMC with their passport — to another operator, a DMP, a practice, without lock-in.
Healthcare commons
French digital health needs shared building blocks: HDS validator, medical i18n presets, FHIR parsers. MDMC doesn't capture, MDMC contributes.
Components to release
Progressive release schedule. V1 = technical blocks usable on their own. V2 = full health framework.
TypeScript library to consume our patient API + FHIR R4 passport export. Compatible with Node, Deno, Bun, browser. Target Q3 2026.
CLI self-audit tool for HDS v2 compliance for health hosts. Exhaustive checklist + verification scripts. Target Q3 2026.
next-intl module pre-configured for medical terminology in 9 locales (fr-FR/CH/LB, de-DE/CH, it-CH, en, en-LB, ar-LB). Target Q3 2026.
HKDF + WebCrypto cryptographic module for patient-side end-to-end encryption. Multi-profile family (HKDF sub-key per member). Target Q1 2027.
Consultation scheduling engine + health calendar. Compatible with iCal + INS-API. Target Q2 2027.
Open source CareFlow conversational bot (PHI anonymisation + Mistral/Groq/Ollama provider abstraction). Target Q3 2027.
What we give back
Beyond MDMC's own code, we contribute regularly to the projects we use. Non-exhaustive list.
Issues on FR Core profiles + field feedback on Ségur V2 implementation.
PostgreSQL migration performance reports + tests on health JSON fields.
WCAG 2.2 AA accessibility components + health form presets.
Which legal framework
Two main licences depending on the nature of the component. No proprietary-friendly licence like BSL or SSPL — a real copyleft commitment on the critical health blocks.
Reusable technical blocks without constraint. No copyleft. Enables maximum adoption by any ecosystem (commercial OK).
Critical health blocks: any SaaS fork MUST republish its changes. Prevents commercial capture without giving back. Protected commons.
Open source and sovereignty are inseparable: code auditability = a necessary condition for patient trust. End-to-end encrypted architecture without public code remains an act of faith.
See the Sovereignty pageA suggestion, an audit, a contribution?
Our technical team answers security researchers, health developers, CIOs and tech journalists. Responsible disclosure report within 48 working hours.