Patient
Record Vault
The master registry of every person who walks through the hospital doors. Think of it as the hospital's—every patient gets a unique ID that follows them for life, connecting every visit, test, prescription, and bill they ever receive.
What is Patient Management?
Patient Management is the central hub where every patient's identity is created, stored, and maintained. When a patient first comes to the hospital—whether for a routine checkup or an emergency—they are registered here with their name, contact details, date of birth, and other important information. The system gives them a unique Medical Record Number (MRN) that acts like their hospital “fingerprint” forever.
Once registered, the system tracks every interaction they have with the hospital—every doctor visit, every lab test, every prescription, every bill—and displays it all on a single timeline. It's the foundation that every other module (OPD, IPD, Emergency, Labs, Pharmacy, Billing) relies on.
Why Does It Exist?
Without a centralized patient registry, hospitals face chaos: duplicate records, lost medical histories, patients being asked the same questions every visit, and critical health information scattered across paper files.
The Patient Vault solves this by giving every patient one unified, searchable, secure record that every authorized staff member can access. It ensures that no matter which department a patient visits—OPD, Emergency, Pharmacy, or Billing—everyone is looking at the same accurate information.
Who Uses This Module?
Front Desk / Reception
Register new patients, search for existing ones, update contact details, issue MRN cards
Doctors & Nurses
View patient history, check past visits, review allergies and chronic conditions before consultation
Administrators
Merge duplicate records, audit data access, manage record-scope permissions
How Patient Management Works
Here's what happens from the moment a patient walks in, explained simply.
Find or Create the Patient
The receptionist first checks if the patient already exists by searching their name, phone number, or MRN. If found, their existing record opens. If new, the receptionist creates a fresh record with basic details (name, DOB, gender, phone, address, blood group, emergency contact).
MRN is Assigned
The system generates a unique Medical Record Number (MRN) for the patient. This number stays with them for life—even across different visits, admissions, and years apart. It's like a social security number for the hospital.
Clinical Timeline Builds
Every time the patient visits, gets a test, receives medication, or has a procedure, it gets added to their Clinical Timeline. This is a chronological feed of everything: OPD visits, admissions, lab results, radiology images, prescriptions, emergency cases, and billing records.
Share or Export (with Permission)
Authorized staff can generate a Patient Handout—a shareable summary of key medical information. This is useful when referring a patient to another hospital or when the patient needs a document for insurance purposes. All exports are logged in the audit trail.
Every Feature Explained
Patient Search
Search by name, MRN, phone number, or any demographic field.
So staff can find any patient in seconds, even with partial information.
The search engine indexes all patient fields and returns results as you type. It also suggests possible matches to catch typos or name variations.
MRN Lifecycle
Every patient gets a unique Medical Record Number at registration.
The MRN is the master key that links all patient data across every hospital department.
The system generates MRNs sequentially or with custom prefixes. Once assigned, an MRN can never be deleted or reassigned—it's permanent.
Profile Pages
A dedicated page for each patient showing all their information in one place.
Doctors and staff need a single place to see everything about a patient before making decisions.
The profile page shows demographics, contact info, emergency contacts, blood group, allergies, and a tabbed interface for clinical timeline, documents, and billing.
Clinical Timeline
A chronological feed of every interaction the patient has had with the hospital.
Gives doctors complete context: past diagnoses, medications tried, surgeries undergone, and lab trends.
Every module (OPD, IPD, Lab, Pharmacy, Emergency) automatically pushes events to the timeline. It's sorted newest-first with filters by module type.
Record Merge
If duplicate records are found, they can be merged into one master record.
Sometimes patients get registered twice (e.g., different hospitals merging, name misspellings). Merging prevents fragmented medical histories.
An admin selects the 'master' record and the 'duplicate' record. The system moves all clinical data from the duplicate to the master, then archives the duplicate. This action is irreversible and fully audited.
Record Scoping (Privacy)
Controls which staff members can see which patients based on their role.
Not every staff member should see every patient. A doctor should see their own patients; a receptionist should see all; a lab tech should see only patients with pending tests.
Permissions like <code>scope:records:self-created</code>, <code>scope:records:self-assigned</code>, and <code>scope:records:all</code> control visibility at the database level.
Patient Handout
A printable summary of key patient information for sharing with other providers.
When referring a patient to another hospital or specialist, the handout provides a complete snapshot without sending the entire medical record.
Generates a clean PDF with patient info, recent visits, active medications, allergies, and diagnoses. All handout generations are logged for audit.
Patient Portal QR Link
A time-limited QR code and URL that lets a patient open their portal without staff login.
Front desk and ward staff need a safe way to hand patients a self-service link without exposing staff credentials or permanent access.
Staff with chart access choose an expiry in days (minimum 1, maximum <strong>30</strong>). The signed link stops working after that window. Regenerate the QR if care continues beyond the chosen period. Default expiry follows hospital settings (<code>patient.portal_qr_expires_days</code>, default 3). Optional <code>modules</code> on create scopes which portal sections the token can load; omitted modules = full chart (legacy).
“Mrs. Sharma's First Visit”
Mrs. Sharma comes to the hospital for the first time with a fever. The receptionist creates her record in 60 seconds—name, age, phone number, address. The system assigns MRN HMIS-10432.
She sees a doctor in OPD, who prescribes medicine and orders blood tests. Both the prescription and the lab order are linked to her MRN. She visits the pharmacy to collect her medicine—the pharmacist sees her prescription instantly because it's attached to her record.
Two weeks later, Mrs. Sharma returns for a follow-up. The receptionist searches by phone number, finds her record immediately, and the doctor can see her previous prescription and lab results on the timeline. No paperwork, no repetition.
Key takeaway
The MRN is the thread that connects every department—OPD, Lab, Pharmacy, Billing—into a single patient story.
What Happens Under the Hood
- Registration
Data is written to the
Patienttable in PostgreSQL. The MRN is auto-generated via a sequence. - Search
A full-text search index on name, phone, and MRN fields returns results in under 100ms.
- Timeline
Events are fetched by joining 10+ tables (appointments, admissions, lab orders, prescriptions) filtered by patient ID.
- Security
Every read and write is logged in the
AuditLogtable with user ID, timestamp, and action type.
Vault
Architecture
The Patient Vault uses a sharded database architecture to handle millions of records while maintaining sub-100ms query performance. Sensitive fields (phone numbers, addresses) are encrypted at the application layer.
Technical Architecture
| Field | Type | Institutional Role |
|---|---|---|
| patient_enclave_id | UUID | Cryptographically signed unique patient identifier. |
| pii_blob | Encrypted_JSON | AES-256 protected demographics and sensitive personal data. |
| fingerprint_hash | Varchar | Biometric mapping hash for identity verification (future use). |
| last_clinical_event | Timestamp | Audit mark for the most recent system mutation on this record. |
Note: Sensitive fields use AES-256 field-level encryption where applicable.
Governance & Power
patients:viewpatients:createpatients:editpatients:mergepatients:exportGovernance Highlights
Field-Level Protection
Specific fields (e.g., date of birth, phone number) are encrypted in the database. They are only decrypted in memory when an authorized role requests them.
Access Transparency
Every time a staff member views a patient file, the system records who viewed it, when, and from which module. This creates a complete audit trail.
Append-Only Records
Clinical records are append-only. Nothing can be permanently deleted—only corrected with a visible amendment trail. This ensures medical history is never lost.
The synthesis engine cross-references lab results, prescriptions, and surgical notes to present a unified Clinical Timeline in the doctor's dashboard—so no critical detail is ever missed.