Search all 478 artefacts by title, document ID or content.
Printed on the standard letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Pensieve Labs
The operating system for hospitals
STM-NO-002
v1.0.0 | 01 August 2026
STM-NO-002 v1.0.0, Last Modified On 01 August 2026, Tier: Public
Pensieve Labsis not an approved supplier in the Norwegian health network, has not signed the supplier terms, has not passed the identity-service code review, and holds no national service integration approval as at01 August 2026. Every one of those is a prerequisite to exchanging health data with Norwegian national services. This document states what each gate is, what it costs, and, importantly, what a Norwegian hospital can do with the Platform before they are cleared.
| DM-1 Dedicated | DM-2 Shared | DM-3 Customer Cloud | DM-4 On-Premise |
|---|---|---|---|
| Recommended | , with credential isolation demonstrated | Yes | Yes |
The gates below attach to the supplier and the software, not to the hosting arrangement. Choosing
DM-4 does not avoid them.
Helsenettet is the closed sector network operated by the national health network undertaking. Any system exchanging health data with Norwegian national services runs over it, and the network is genuinely closed: with a health network connection, only sites inside it are reachable without a client-side change.
This is the hardest single gate in any of Pensieve Labs's five markets, not because any step is
individually difficult but because step 6 is a code review conducted by a state body with no published
service level. No amount of commercial pressure shortens it, and there is no paid expedite path.
Membership terms changed with 2026 as a transition year, and two changes matter:
Point 2 is the trap. Edsol Edtech Pvt. Ltd. does not join the health network. It is instead governed
by a separate supplier instrument (the terms for suppliers integrating with health network services),
and signing those terms is stated to be a requirement for participating in trials and for ordering services
going forward.
[UNVERIFIED: the current version of the supplier terms was not parsed in the research pass. They govern liability, security obligations, incident reporting and termination. **Obtain and read them in full before committing to any Norwegian timeline.** no/README.md Section 6 item 1.]
Who pays for the network. The membership charge falls on the hospital, not on
Pensieve Labs: supplier processors are outside the membership regime entirely. The published monthly
charges for health service providers are modest. Health network cost is not a sales objection; the
integration effort is.
| # | Step | Instrument | Who | Realistic elapsed |
|---|---|---|---|---|
| 1 | Obtain a Norwegian organisation number | Registration of a Norwegian-registered foreign undertaking. A Norwegian company is not required: the foreign-undertaking registration is explicitly named as acceptable, and this is the single most useful cost-saving fact in the Norwegian analysis | Pensieve Labs |
10 to 25 days |
| 2 | Obtain a Norwegian business certificate from an approved certificate authority | A commercial enterprise certificate. The consumer eID route requires a Norwegian national identity number for the signatory and is not available to a foreign-owned entity | Pensieve Labs |
5 to 15 days |
| 3 | Sign the supplier terms for integration with health network services | The health network undertaking | Both | 5 to 20 days |
| 4 | Obtain access to the identity service's test environment | Self-service portal | Pensieve Labs |
1 to 5 days |
| 5 | Build to the identity service security profile: separate profiles for clients and for interfaces | Engineering | Pensieve Labs |
20 to 60 days |
| 6 | Pass the code review | The identity team confirms the implementation conforms to the security profile. Production access is not granted until it is passed | The health network undertaking | 10 to 45 days including rework, with no published service level |
| 7 | Per-service approval for each national collaboration service | Varies by service | Both | 60 to 180 days each |
| Total to first production data exchange | ā110 to 350 days |
A separate approval exists for suppliers of health network connectivity itself. Pensieve Labs does
not supply connectivity and does not seek it.
The identity service is the sector's identity and access service. Its documentation is explicit: before going into production, a supplier must have passed a code review in which the identity team confirms the software was built in accordance with the security profile.
Signing the supplier terms also creates an ongoing obligation: the company must stay current with changes to the security profile and introduce the corresponding changes in its software. It is not a one-off.
A third-party code review by a national authority, with no published service level, is not compatible with a fourteen-day sales cycle. It is also the closest thing to a certification Norway will give
Pensieve Labs, and it is free. Once passed, it is a real, checkable, health-specific claim that no general-purpose security certificate substitutes for.Pensieve Labstreats it as the highest-value Norwegian credential to acquire.
The health network undertaking publishes a public register of systems with approved integrations,
mirrored by the health directorate. Getting Pensieve onto that list is the single
highest-value Norwegian credibility asset available: it is state-published, checkable in ten seconds, and
costs no certification money.
It is also the direct answer to "you have no security certification", not a rebuttal, but a different and more specific credential.
Pensieve Labs is not on it as at 01 August 2026.
Integration with the national collaboration services is a mandatory requirement class in Norwegian patient record procurement, with a regulatory hook behind it.
| Service | What it is | Pensieve Labs's position |
Sequence |
|---|---|---|---|
| National person/demographics service | Patient identity and demographics | Foundational. Nothing works properly without it | 1st |
| National shared summary record | The cross-provider summary of a citizen's care | Offered both as a portal integration (embedded browser) and as a tight interface integration. The portal route is the fast path and the Platform is web-based, so the documented route for web-based record systems applies | 2nd |
| National e-prescribing / central prescribing module | Prescribing | Pensieve Labs integrates; it does not build prescribing. Every competitor is already approved: this is table stakes, not differentiation. Governed by published general terms of use |
3rd, only if prescribing is in scope |
| National medication list | The citizen's consolidated medication list | Downstream of prescribing. Sequence after it | 4th |
| Address registry and structured clinical messaging | Sector address registry; referral and discharge messaging | Required wherever the workflow exists. Governed by the national standards catalogue | 4th |
| Registry reporting | Mandatory reporting to national health registries | Statutory, via the reporting duty in the health-record regulation. DIS-NO-003 Section 5 |
Required for a production hospital |
| Citizen-facing national portal | Patient-facing national services | Only relevant if Pensieve Labs exposes patient-facing services through it. Defer |
Not applicable |
| Welfare-technology hub | Hub between municipal welfare-technology solutions and record systems | Deprioritise. It is being replaced by standalone interface-based services, and a stop has been recorded. Do not build to it. [VERIFY the replacement roadmap before allocating any engineering.] |
None |
A Norwegian health undertaking delegates rights to its record-system supplier through the national
business portal, so that Pensieve Labs can act on the hospital's behalf in the identity service.
That is a per-customer task on the critical path to go-live, performed by the hospital's authorised
signatory, not by Pensieve Labs. It must appear in the onboarding runbook as a named customer task
with an owner and a service level, because a delegation that nobody chased is a go-live delayed by a week
for a five-minute action.
RBK-GL-001 carries it; CHK-NO-001 Section G verifies it.
Edsol Edtech Pvt. Ltd. does not become a Norwegian health-sector participant in its own name, does not
hold the hospital's national-service entitlements, and does not represent that it does.
| Held by the hospital | Held by Pensieve Labs |
|---|---|
| Health network membership | The supplier terms for integration |
| The delegation in the national business portal | The identity-service client registrations created under that delegation |
| Its own national-service entitlements and organisational credentials | The per-tenant vault those credentials are stored in |
| The controller role and the statutory reporting duties | The processor role and the system conformance |
Pensieve Labs calls the national services as the hospital, on the hospital's own authority.
DIS-GL-024 states the integration boundary and DIS-GL-025 the credential custody, rotation, revocation
and offboarding model. It is the same doctrine Pensieve Labs applies to every national digital health
scheme, stated as a deliberate architectural position rather than as an apology.
DM-2 note. A shared platform reaching national services for several hospitals must demonstrate
per-tenant credential isolation in writing before it touches those services. The questions and answers are
the same as in the Danish pack; DIS-GL-032 and DIS-GL-025 are the evidence. DM-1 is the
recommendation and it is also the fastest.
This section exists because the honest answer is not "nothing", and a hospital deserves to know exactly where the line falls.
| Can be delivered before the gates | Cannot be delivered before the gates |
|---|---|
| Scheduling, theatre and capacity management | Any exchange with a national collaboration service |
| Inventory, procurement, pharmacy stock | Prescribing through the national e-prescribing service |
| Finance, billing, payer administration | The national shared summary record |
| Human resources, rostering, competence | Structured clinical messaging over the health network |
| Quality, deviation, incident management | Statutory registry reporting |
| Operational analytics and reporting | None |
Internal clinical documentation, subject to DIS-NO-003 |
None |
But be careful with this table in a Norwegian sales conversation. Unlike Denmark, where the national gate blocks clinical scope and a phased operating-substrate deployment is genuinely viable, a Norwegian hospital's registry reporting duty is statutory, and a production hospital cannot operate indefinitely without it. The Norwegian phased offer is therefore narrower and shorter than the Danish one, and
Pensieve Labsshould not oversell it.
| Item | Status as at 01 August 2026 |
|---|---|
| Norwegian organisation number | None (REG-NO-005 Section 2) |
| Norwegian business certificate | None |
| Supplier terms signed | No |
| Supplier terms read in full | No: no/README.md Section 6 item 1 |
| Identity-service test environment access | None |
| Security profile conformance | Not built |
| Code review passed | No |
| Listed in the public register of approved integrations | No |
| National person service | Not integrated |
| National shared summary record | Not integrated |
| National e-prescribing | Not integrated |
| Registry reporting | Not built |
| National FHIR profile conformance statement published | No (DIS-NO-003 Section 6) |
| Norwegian-language product and documentation | Not available |
11.1 The supplier terms have not been read in full. Any Norwegian timeline built before they are read is provisional. This is the single highest-priority Norwegian action.
11.2 The code review has no published service level. The 10 to 45 day figure is an estimate drawn from the
research and is [ESTIMATE]. It may not be quoted to a customer.
11.3 Per-service approval durations vary widely and depend on the service and on the health network undertaking's own capacity.
11.4 The welfare-technology hub roadmap is unresolved. [VERIFY] before allocating engineering. The
current recommendation is to allocate none.
11.5 This statement claims no approval. Every row of Section 10 that says "no" means no.
| ID | Artefact |
|---|---|
STM-NO-001 |
Normen Supplier Conformance Statement |
DIS-NO-003 |
Pasientjournalloven Conformance Disclosure |
REG-NO-005 |
Norway Entity, Tax and Invoicing Register |
DIS-GL-024 |
Integration Boundary Statement |
DIS-GL-025 |
BYOK / BYOC Credential Handling Disclosure |
DIS-GL-029 |
Interoperability & Standards Disclosure |
DIS-GL-032 |
Multi-Tenancy Isolation Disclosure |
RBK-GL-001 |
Master Onboarding Runbook (carries the delegation task) |
CHK-NO-001 |
Norway Deal Readiness Checklist |
Issued by Edsol Edtech Pvt. Ltd..
| Role | Name | Signature | Date |
|---|---|---|---|
| Product owner, Norway | Roadmap norway owner |
||
| Authorised signatory | [TO BE SUPPLIED] |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 01 August 2026 |
Product | First issue. The 2026 membership change that excludes suppliers, the seven-step prerequisite chain, the code review as both the hardest gate and the best credential, the public register, service sequencing, the per-customer delegation task, and an honest status table with the narrower Norwegian phased offer. |