TOPx HHS Tech Sprint · Phase 2 · Lyme Innovation track

A record the patient owns, and a county that can count

In 2023, CDC surveillance counted 89,469 Lyme cases. CDC-published analyses of insurance claims estimate roughly 476,000 people may be diagnosed and treated each year — which CDC notes may be an overestimate. The gap between those two numbers is the problem: a patient’s labs, symptoms, bills and tick are scattered across portals, paper and memory, so nobody — not the patient, not the clinician with a short appointment, not the county — can see the whole picture. LymeHQ is one record the patient holds the keys to. It is in demo on invented data, and each capability in its register is labelled built or not built.

Phase 1 winner · Phase 2 closes 2026-10-15Surveillance figures: CDC, data.cdc.gov, retrieved 2026-08-27 · the476,000 estimate: Kugeler et al., Emerging Infectious Diseases, 2021 · CDC, Lyme disease data & surveillance (opens in a new tab), read 25 September 2026

01 · Patient pain points

Results for the American People

250 / 250 words

The first user is a person with a tick-borne illness who has seen four clinicians, holds lab PDFs from three of them, and cannot remember which month the fatigue started. LymeHQ gives that person one record they own: lab values shown against the performing lab’s own reference range, a daily check-in in five plain words rather than a score, medicines as names and start dates, visits, findings on the body and places in their own words, and a timeline that draws a missed day as a gap. What the illness has cost is a ledger of dated lines, never projected.

The second user is the clinician with a short appointment. When the patient shares their record and turns sharing on, they receive a short printed pre-visit brief holding exactly what was granted: dates, figures and medication names, no dosages and no conclusions. The patient reads it first. Turn either lock off, or let the patient’s last day pass, and it is gone on the clinician’s next request, with no copy left behind.

The third is the researcher, who gets counts and never a list, with a floor of five enforced inside the database rather than in a template. A caregiver seat is a preview: drawn in full, with nothing behind it running.

The workflow is the one patients already run on paper: find a tick, record it, take the brief to the visit. What LymeHQ removes is the retyping, and every consent stays off until the patient turns it on.

02 · Open data and evidence

Data, Tech & Evidence-Driven Approach

296 / 300 words

Three kinds of data meet in the record and are kept apart by their origin.

Federal open data. CDC’s national Lyme surveillance series, 1992 to 2023, is pulled from data.cdc.gov under fixed controls: the extractor refuses to write unless its 2019 figures match CDC’s published numbers and every year reconciles to the national total. The charts mark the two definition changes, and a missing count is never drawn as zero. NHANES was probed and retired; HCUP was assessed and not wired; Blue Button 2.0 is built to CMS’s sandbox, which fails on CMS’s side, and its production path, CMS Aligned Networks, is designed. Every verdict is dated on the open data register.

Three federal instruments, three blind spots. CDC surveillance counts reported cases, well below CDC’s own claims-based estimate, which CDC says may itself be an overestimate. MEPS releases a condition code only when at least 30 sampled people have it, and recent years often fall short for the code containing Lyme (written feedback from AHRQ’s Thomas Selden, 24 September 2026): too few cases to estimate cost. HCUPnet cannot query an individual Lyme code; Lyme’s codes fall into broader categories. A record the patient holds sees what each misses, and it is self-selected and self-reported.

Patient data is entered by the patient and carries its origin. Nothing is scored, and no model computes a trend.

Sentinel data. A household records its own dog’s tick-panel result, framed as where ticks are and never as what a person has.

Beacon, the assistant, needs the patient’s switch, and every reply passes a safety floor, tested without a model, that withholds a reply naming a diagnosis, giving a dose or scoring the person. Research output is suppressed at a floor of five inside the database, before any aggregate leaves it.

03 · A working MVP

Execution, Efficiency & Delivery

203 / 250 words

What ships today is a working prototype on invented data with real CDC surveillance, a published element set, and an assistant behind a tested safety floor. Capabilities are listed in one register in five states — working, blocked, preview, designed, ruled out — that a script grades against the codebase on every push. A feature that ships while still listed as not built fails the automatic checks on the change that ships it.

The value is time and paper. A patient hands a clinician one document instead of a folder, and the clinician reads the same brief the patient already read. Someone with a tick in their hand gets a seven-step record and a printable handoff, with no account and no medicine named.

The deployment unit is a town, not an app. The Tick Offensive runs a season in one municipality — enrolment, door cards, a public ledger, a September readout. It is designed in full and not built, and no town has been costed: the first town’s figures will be a ledger, not an estimate.

What does not ship is listed below in the register’s own words. Deploying it needs a health-system partner, a lab partner and a county willing to sign.

What the first town costs · not costed

The design for a town season lists six lines a readout will carry: households enrolled, kit cost by tier, the neighbours’ fund, volunteer hours, clerk time, and panels for pets. No town has run, so no figure exists for any of them, and none is shown here. The Tick Offensive is designed and not built; when a town runs, its ledger is public to the cent and replaces this note.

04 · Other conditions

Scalability, Reuse & Societal Impact

217 / 250 words

Little of LymeHQ is specific to Lyme. The patient-owned record, the consent switches that start off, the both-locks sharing rule, the gap drawn as a gap, the five-word check-in, and the suppression floor are condition-agnostic. The coinfection coverage guide, the tick-bite workflow and the sentinel-dog lane are tick-borne. A Long COVID or ME/CFS deployment changes the codebook and the education library and keeps the rest.

Standards are the route to reuse, and the honest position is a draft. The element set behind the record is published in full, with the elements this draft has found no standard place for named as gaps rather than filled. A patient’s export is a FHIR R4 bundle — Patient, Condition, Observation, DiagnosticReport, MedicationStatement, Consent — whose coverage statement names every element it does not carry. One element is proposed outside the set: the five-word rating of a day, ordered and never averaged, written down for discussion, submitted to nobody and not exported. Blue Button 2.0 is built to CMS’s sandbox; its production path is designed. TEFCA and USCDI+ are unassessed.

Key assumptions: a health-system partner will register a SMART on FHIR app, a county will sign a data-sharing agreement, and the codebook will be contested in public. Next steps, in order: one county agreement, one town season, then a second condition.

05 · The register’s own rows

What is honest about this submission

Every page on this site labels its own state. This table is the register’s own rows for what does not run today, and a panel should hold us to it.

Working
38
Blocked upstream
5
Preview
19
Designed, not built
30
Ruled out
13
CapabilityStateIn the register’s words
The home page in SpanishOn hold: our decisionHidden until the full journey is translated and reviewed by a person (founder, 2026-10-01). Today only the home’s own strings and the chrome are Spanish; the doors, the systems, the flow and every page behind them are English.
Platform pages in Spanish, machine-translated at build timeOn hold: our decisionHidden until the full journey is translated and reviewed by a person (founder, 2026-10-01): /es/<route> answers a temporary redirect to the English page and the language toggle does not render. Separately, there is no DEEPL_API_KEY in this environment, so the cache holds no page and every guide and platform page would show the “not yet generated” bar; a route that is neither — a tool — answers not found there by design. One run of `npm run build:es` with a key fills the cache; the review is what is missing.
CMS Blue Button 2.0 — your own Medicare claimsBlocked upstreamThe sandbox fails on CMS’s side: its synthetic beneficiary logins fail at medicare.gov SSO, re-tested 24 September 2026 and reproduced on CMS’s own v3 test client in a clean browser with CMS’s published credentials. The production path needs a Medicare App Library listing and a registered JWK Set, and we have neither. No claims data has ever moved.
Pathogen presence at block-group levelBlocked upstreamThe data needs a sharing agreement we do not have.
Canine positives aggregated into a local presence signalBlocked upstreamAggregating across households needs veterinary practices contributing results, and that portal is not built.
What people buy — the in-app guide to purchasesPreviewPreview. The evidence tiers, the Access Fund disclosure and the FTC line are the page. No Stripe, no affiliate agreement and no fulfilment exist behind it, so every price is a marked placeholder. The graded shelves themselves are the DESIGNED row below.
Claiming a directory listingPreviewPreview. The kit’s claim flow at /provider-directory/claim, drawn in full: the chosen listing, the three routes that would verify a clinician is who the listing names (a licence number against the state registry, a one-time link to a practice-domain address, a callback to the registry’s number), the fields a claim would fill, what claiming would never let them do, and what would happen after. Nothing writes. The submit is present and disabled with the reason beside it, no step states a turnaround, and three separate things stop a claim being served: there is no submission surface, a listing is read-only to every signed-in account at two layers, and one module is the only writer with its actor re-resolved from the database.
Provider plan and billingPreviewPreview. Three plans and what each includes, with the rule that a subscription buys a listing and never a verification. No payment processor is connected, so the prices are marked placeholders and nothing can be bought.
The caregiver seat — observations under your own name, never as the patientPreviewPreview. The kit’s caregiver dashboard at /seats/caregiver: a stream attributed to the carer, hours for the patient’s ledger, the carer’s own check-in. No caregiver role exists in users.role, no seat table, no grant between seats — every figure is withheld and every control is designed.
The veterinary-practice seat — every dog a sensor, results by block groupPreviewPreview. The kit’s vet dashboard at /seats/veterinary-practice: contribute results, owner questions answered as the practice, the sentinel module. The pet sentinel that runs today is the household’s (check:sentinel); there is no practice seat and no block-group export.
The health-official seat — block-group aggregates under a data-sharing agreementPreviewPreview. The kit’s official dashboard at /seats/health-official: nightly files, cells withheld under five, the agreement that decides geography. Nothing exports to a county today; the research commons is the only aggregate surface and it is ZIP3 at k ≥ 5.
The vendor seat — listings graded by LymeHQ, never ranked, never inside the recordPreviewPreview. The kit’s vendor dashboard at /seats/vendor: grades, rule flags, a public ledger to the cent. No vendor role, no listings table, no ledger; the shop is itself a preview and /tick-prevention is the only affiliate surface.
The town-organiser seat — a Tick Offensive’s orders, roster and cash, never a recordPreviewPreview. The kit’s organiser dashboard at /seats/town-organiser: pack night, captains, the county agreement. No campaign tables exist; every amount reads illustrative and every count is withheld.
The volunteer seat — a shift, a street, a phone treePreviewPreview. The kit’s volunteer dashboard at /seats/volunteer: doors knocked, a neighbour enrolled, the Saturday shift. No volunteer role and no campaign behind it; the page is the design with its figures withheld.
The admin seat’s dashboard — every queue and job, worst firstPreviewPreview. The kit’s admin home at /seats/admin. The admin ROLE is real (AAL2 at the middleware; /admin/provider-verification and /admin/research-access run today) and has no quick-select by rule; the aggregated overview, the incident queue and the platform-health card are the design, not a screen anything feeds.
The Access Fund — the public page and the rulesPreviewPreview. What it pays for (a denied lab, a first visit, an uncovered prescription, a badged shelf item), paid to the payee and never the person; the whole of the rules; the ledger, empty because no fund has opened. No pool, cap or award figure appears anywhere on it.
Ask the fundPreviewPreview. The seven-step request as designed — category, payee, what, the invoice, fight-the-denial-first, the paper, one sentence — every control inert. No cap is stated and nothing can be sent.
The fund committee — a blind read by three of fivePreviewPreview. The conflict-of-interest declaration, the sealed request, the arithmetic already run, the four grounds and no fifth, the 72-hour clock. No committee exists and no request has ever been read.
Give to the fundPreviewPreview. Once or monthly, a capped earmark, named or anonymous, the fee to the cent on the receipt, a follow-up on the payee class reached. No amount presets, no balance, and nothing can be charged.
Fund admin — payouts, reconciliation and the close, never an awardPreviewPreview. The staff side as designed, on the public tree beside the pages it serves because no fund-admin role exists: W-9 gates, duplicate flags, the refund path, the monthly close, an append-only audit log. Every queue is empty; the two-admin threshold is marked illustrative.
The red-flag card and its escalationPreviewPreview. A printable handover for an emergency room, and a screen that looks like nothing else in the app. Detection is not built and nothing fires: the page shows the card’s shape as a specimen about nobody, links the emergency guidance that exists, and keeps the citation a citation. It stays a preview through the 15 October submission by decision (founder, 2026-09-18): what would fire is a clinical rule, and a card that may never look like an alert is a better argument as a design than as a half-built detector.
The Research Priority CommonsPreviewPreview. Questions with a disposition — answered, not yet answerable, or closed with a reason — including the gap card that names the missing data element, deposits that must carry their plan and their contributors, and the four rules. No question or deposit table exists; the page is the design, with the one real thing named: the floor of five, in the database. It stays a preview through the 15 October submission by decision (founder, 2026-09-18): a public submission surface needs a moderation design first — submission is not publication — and the design is the argument.
The recruitment bridgePreviewPreview. Pull, never push: a researcher composes an invitation and sees how many a cohort holds, never who; patients who match see it in their own record and answer with two equal buttons; the count of yes is withheld below five. No invitation table, no broadcast, no response channel — every control is designed, and the industry label is the one line that derives, from the session’s role. It stays a preview through the 15 October submission by decision (founder, 2026-09-18): a response row per patient is the roster the findings ruling refuses to store, and the ethics gate is not designed under a deadline.
Property defense — the yard measured, not managedPreviewPreview. A profile of the place, a log of what was done to it, and the sentinel as the endpoint: the dog’s test and the block group’s sightings, never “fewer ticks seen”. The block group leaves the page; the parcel never does. No profile or log table exists, every figure is withheld, and choosing an acaricide entry would show a disclosure and never a rate, a mix, a timing or a place to spray.
Logging a day you missedDesigned, not builtToday the record takes an entry only for the day it is written — the server sets the date, so an earlier day cannot be rewritten quietly. As designed, a past day carries its own date and an added-later mark, so the record stays honest about when it was written. The table has no such mark yet.
A state you set — flare, steady, remissionDesigned, not builtThe check-in draws the selector. Nothing holds a state the patient sets, so nothing records one, and nothing on the page infers one from the words.
The nine check-in words with no place in the recordDesigned, not builtThe kit asks fifteen words. Six have a place in the record: five are asked as their own chip and fatigue is the Energy row, asked once. The other nine have none, so they are drawn dashed and cannot be tapped. Adding them widens what the record means, which is a schema change, and the list of symptoms stays six (founder, 2026-09-23).
The energy envelope — where the day’s energy wentDesigned, not builtRest, home, work and people, each in five words. Nothing holds where the energy went, so nothing is recorded. As designed it describes a day and never budgets one for you.
A photo on the check-in — a rash, a tick, a jointDesigned, not builtNothing takes a photograph yet. A picture carries a face, a home and a timestamp as well as the thing it shows, so it is built only when it can stay on the device until the patient chooses where it goes, with every sharing switch off.
Calling a word what you call itDesigned, not builtRenaming any of the five words to the one you actually use. Your screen would show yours and the record would keep the position, so nothing counted or shared changes. Nothing holds your label yet.
Who has ever seen each part of the record — the ledger turned aroundDesigned, not builtThe access log organised by what was opened, under the counting rule on the consent ledger. The log is append-only and exists; a patient cannot read it yet, so the section is the design.
Journal highlights for a clinicianDesigned, not builtBeacon drafts a short set of highlights from the journal notes a patient chooses. The patient reads, edits or deletes every line and approves each one before a clinician they named can read it in the visit summary. Designed and decided, not built: nothing is drafted, nothing is shared, and the journal itself is never sent.
What a check covered, facet by facet, with its own date and expiryDesigned, not builtF09's other half (founder, 2026-09-19). The four facets — identity match, jurisdictional licence, practice details, availability — are separated on the listing today and the badge no longer says “licence” over a registry record. What is NOT held is a row per facet: today one evidence row carries a KIND and no jurisdiction and no expiry, so a licence that was read cannot say which state it licenses or whether it is still current. The model would be one evidence row per facet with its own document, jurisdiction, checked-on date and expiry, and a listing whose licence evidence has expired would drop that facet rather than the whole listing. It is a schema change and the schema is frozen.
The integrative guide inside your accountDesigned, not builtThe guide itself is a public page and it works. The kit’s account sidebar also draws a row for it, and the app never links out to a public page, so an in-app copy is what that row would open. No such page exists and the sidebar row is drawn inert; the public guide is where it is read.
The molecular record — organism by organism, assay and windowDesigned, not builtThe kit’s patient-side view: every organism, the assay that looked for it, the window it was drawn in and the result as the laboratory reported it, with a test that was never run said outright rather than left blank, whether the method is cleared for diagnosis or for research use only, and sequencing beside it. The lab-results page already shows which organisms a record holds a test for, read from the panels’, laboratories’ and tests’ names; nothing holds a per-organism assay, window, method status or sequencing result, so there is no page and the sidebar row is drawn inert.
My protocol — what you take and when, as a daily pageDesigned, not builtThe kit’s page for the medication list as a day: each item with its timing and the date you started it, today’s doses ticked as facts with the server’s time, and reminders that are off until asked for. The medication list is real and is its own row, a record and not an engine. No page treats it as a daily protocol and nothing reminds you to take anything, so the sidebar row and the phone bar’s Protocol tab are drawn inert. A missed dose would be a fact, never a score.
A page of its own for each pet’s sentinel recordDesigned, not builtA pet’s tests are recorded and read on the household page, which works and is its own row. The kit also draws a page for pets — each animal’s preventive calendar, the ticks found on it and its tick-panel results — and it does not exist, so the sidebar row is drawn inert. A positive would still say where ticks are and never what anyone has.
Inviting a caregiver to part of your recordDesigned, not builtThe kit’s page: who you are inviting, what they could see and for how long — a pending grant that exists only once they accept, their observations attributed to them, one tap to end it. There is no caregiver account, so there is nobody to invite and the sidebar row is drawn inert. The caregiver seat’s preview is its own row.
Lyme news, local firstDesigned, not builtThe kit’s news page: public feeds and journals indexed for Lyme and the tick-borne illnesses, ranked by distance and recency, every story showing its source type, with a weekly digest that is off by default. Nothing indexes a feed, so there is no page and the sidebar row is drawn inert.
The audit log, readable by an administratorDesigned, not builtThe kit’s admin page: a log in which every entry names who acted, what they did, when and under which grant or rule, filtered by actor, action and window, with no edit and no delete. The log itself is real: it is append-only, and access to a record is written to it. No page reads it back for an administrator, so the sidebar row is drawn inert. The patient’s own view of it is a separate designed row, “Who has ever seen each part of the record”.
Search this area — the map as a live filterDesigned, not builtThe kit defines the contract (a `care-bounds` message from the map, a `care-map-cmd` message back); nothing in the directory handles it yet. Nothing is wired to a tile server and nothing draws a map — the directory shows an empty frame — so searching an area is the design. Listings do carry a place, and a listing’s page shows the practices closest to it as a straight line, but nothing lets a map set the search.
Patient portal importDesigned, not builtThe live connection: signing in to a portal from here and pulling records with no file in between. The route is Epic Individual Access Services under TEFCA — patient-directed, USCDI v3, free to developers. Designed, not built. A C-CDA or FHIR JSON file you download from a portal already works: it is read into pending lab reports for you to check and confirm, under “Add a lab report — your document kept, the values typed by you or read from a portal file”.
Two shelves — prevention and supplementsDesigned, not builtGraded, never ranked. Commission disclosed, and with no effect on either the grade or the order.
A verified listing-level data sourceDesigned, not builtListing counts are illustrative until a real catalogue backs them.
The Tick Offensive — landing, town page, trackerDesigned, not builtPets first, people second, yards last, then measure whether it worked.
Organiser and volunteer coordinationDesigned, not builtTen further screens — enrolment, shifts, door cards, packing, backers, recognition. Designed in full. They only mean something with real towns in them.
A published post-season result for every townDesigned, not builtThe campaign promises measurement. That promise is not yet kept anywhere.
Beacon reading a tick photoDesigned, not builtSpecies and engorgement as observations to hand a clinician, never a risk number. Needs image input and the same output floor as every other Beacon reply.
First sign-in — one question, once per accountDesigned, not builtSets the default seat for an account holding more than one. It never grants a verified seat; options that need a grant say so and open as pending.
A narrated pre-visit brief, edited by youDesigned, not builtBeacon phrasing the thirty-day figures INTO the short printed brief a clinician reads, with a provenance stamp and the patient’s edits. The brief today is figures and dates and calls no model; the narrated form needs a branded disclosure, a causal-calibration floor and an injection backstop, and building it is a founder decision not yet taken. The reading Beacon gives you on the brief page is for you and never leaves.
A dated changelog of what changed on the siteDesigned, not builtEvery entry a date and the decision behind it, with a correction route. Until it exists, the commit history is the changelog.
Outcome capture on the pre-visit delta — a clinician’s three tapsDesigned, not builtThe kit’s delta lets a clinician record an outcome in three taps, "nothing changed today" one of them. Not built, and held out of Migration 06 on purpose (founder, 2026-09-18): a provider-written row the patient must be able to read is a disclosure direction this schema does not have, and inventing a consent model under a deadline is how a consent model gets invented badly. The delta’s READ half is on the plan; the write half waits for its own consent design.
Beacon on the public guides — a reading aid for a strangerDesigned, not builtThe kit puts Beacon on every education guide. Deferred (founder, 2026-09-18): a stranger asking on a public page is a different risk surface from a patient asking about her own record, and the output floor has no public-page arm — building one under a deadline puts a hole in the floor. The guides carry the "explain it like I’m exhausted" toggle, which changes the type and calls no model.
A fourth review state — published without clinical sign-offDesigned, not builtThe kit marks some guides "published without clinical sign-off": shipped deliberately, unreviewed, because withholding them helped nobody — a statement about editorial policy that the three states here cannot make. Worth adopting, and a post-submission change (founder, 2026-09-18), since three surfaces render the review vocabulary; until then those guides read "pending clinical review", which is the honest mapping.

No dates. What is next, in what order, is on the public roadmap, which explains why this site orders rather than schedules. The full register, with what works and what was ruled out, is at what is not built.

06 · Who built this

Team and lived experience

LymeHQ is patient-built and, at the time of writing, built by one person. Nobody on it is a federal employee. The clinical copy is held to the one rule this site keeps above every other: no dose, frequency or duration anywhere, and never a score about a person.

Founder to write · readiness item 14

[FOUNDER] Lived-experience statement and the 100-word team description for the crowdicity entry. Nothing here is drafted on the founder’s behalf.

Rules we are working under

Participants retain their intellectual property; HHS receives a non-exclusive licence to display and practise the submission. Nothing on this site implies endorsement by HHS, NIH or the federal government, and no federal logo appears anywhere. Every figure here is invented unless it names its source, and the one federal dataset consumed is listed with its licence in the register.