A medical record assembled from five sources is only as trustworthy as its least trustworthy source, unless you can tell which value came from where. Most aggregation tools flatten this: you get a medication list, and you have no idea whether 'Atorvastatin 20mg' came from a pharmacy claim last week or an OCR'd fax from 2019.
We made a rule early: no field leaves Retrievant without a source. Every FHIR resource carries meta.source and a Retrievant provenance extension with provider, retrieval method (api, browser, voice, fax), the source document reference, the timestamp, and for extracted values, a confidence score.
The cost is real. Bundles are roughly 35% larger. Reconciliation is harder, because merging two Observations means merging two provenance chains, not picking one. And our UI has to show provenance without drowning the clinician in metadata; we settled on a small source chip per field that expands on hover.
The payoff is that every downstream question has an answer. An underwriter can auto-accept API-sourced values and route OCR'd ones below 0.9 confidence to a human. A litigator can cite the page. A patient can see that the wrong allergy came from a specific clinic and ask them to fix it.
If you build on health data and you are not carrying provenance, you are asking your users to trust you instead of the record. We would rather they trust the record.