Module 17b · Patient Billing Workspace

Billing
& Invoices

Settlement desk at /dashboard/billing: invoices, payments, advances, discounts, voids, refunds, A4/thermal prints, and patient-verifiable receipt QR. Institutional GL and day-close live in Finance.

Purpose

Capture and settle every chargeable clinical service without revenue leakage. Clinical modules auto-write line items; billing staff review, pay, print, and audit them. Mutations (create/pay/refund/void/advance) stay here — Finance hubs are read/ERP surfaces.

Who uses it

  • → Cashiers & billing clerks (pay, advances, print)
  • → Supervisors (void, refund, discount, SOD)
  • → Reception / walk-in settlement
  • → Insurance coordinators (apply-insurance reprice)
Workflows

Typical Billing Lifecycle

1

Review Auto-Generated Lines

OPD, ER, IPD bed/visits, lab, radiology, cath, pharmacy, OT/anesthesia, and linked services create invoice lines with source-module metadata. Filter by patient, doctor, date, status, or source.

Behind the scenes: Lines stamp clinical branchId from Working-in / encounter campus; catalog prices come from the campus ServiceCatalog.
2

Create or Edit Invoice

Manual invoices pick Working-in campus services. Draft → posted → partially paid → paid. Line/metadata edits on unpaid or partial bills use billing:invoices:edit (not full create/pay).

Behind the scenes: Paid/cancelled invoices block line edits. Currency is enterprise AppSetting — never a BranchSetting overlay.
3

Pay, Allocate Advance, Discount

Record cash/card/bank payments (partial OK). Allocate patient advances. Discounts need billing:discount (or manage). OPD/ER non-refundable holds come from campus BranchSetting.

Behind the scenes: Payment idempotency keys prevent double-post on retries. Finance → Collections is a read-only mirror.
4

Print, Verify QR, Void, Refund

A4/thermal print mints a non-PHI receipt verify QR (/verify/receipt#t=). Void incorrect unpaid bills; refund settled amounts with billing:refund. Optional bill-link SMS resend.

Behind the scenes: Print needs print grants + view geography. Soft-null QR when mint secrets / PUBLIC_APP_URL missing.
Deep Dive

Features

Invoice List & Filters

What

Paginated invoices with status, patient/doctor search, date, totals, and source module.

Why

Discharge rush and end-of-day need fast findability.

How

URL-synced filters; summary cards; record-scope notices when role-scoped.

Advances

What

Deposit → allocate → return lifecycle on Advances tab / patient context.

Why

Surgical and IPD deposits must apply cleanly without over-return.

How

billing:advance-* grants; net-paid validation; printable advance receipt + verify QR.

Receipt Verify QR

What

Public /verify/receipt confirms amount/date/org/campus without PHI.

Why

Patients and auditors validate slips without staff login.

How

JWT typ receipt_verify in URL hash; rate-limited public API; campus timezone on dates.

Campus Billing BranchSettings

What

Per-campus fallback rates, OPD/ER holds, admission transfer/discharge knobs, letterhead footer.

Why

Campuses need different rates/holds without changing enterprise currency.

How

Settings → General overlays stamp Working-in BranchSetting; Viewing All writes enterprise defaults where applicable.

Discount / Void / Refund Controls

What

RBAC-separated write-offs and reversals.

Why

Segregation of duties — cashiers pay; supervisors void/refund.

How

billing:discount, billing:invoices:void, billing:refund (or manage) + edit geography dual-gates.

Apply Insurance Reprice

What

Reprice billable lines from campus insurer tariffs.

Why

TPA negotiated rates must hit the invoice without rewriting doctor-share cash base.

How

Invoice edit + insurance hub read; shareBase* stays cash; see Insurance handbook.

Technical Architecture

FieldTypeInstitutional Role
branchIdUUIDClinical campus stamp (Working-in).
statusEnumdraft, posted/finalized, partially_paid, paid, voided/cancelled.
sourceModuleVarcharOriginating clinical module for auto-billed lines.
totalAmountDecimalBillable header total (post-discount / insurance reprice).
shareBase*DecimalCash share base for doctor-share — not insurer tariff.

Note: Sensitive fields use AES-256 field-level encryption where applicable.

Governance & Power

billing:view
billing:create
billing:payment
billing:invoices:edit
billing:invoices:void
billing:discount
billing:refund
billing:print-a4
billing:print-thermal
1
Clinical trigger

Service completed in OPD, ER, IPD, lab, pharmacy, OT, etc.

2
Line creation

Auto-billing writes a campus-stamped invoice line.

3
Settlement

Cashier pays / allocates advance / discounts / prints QR slip.

4
Discharge gate

IPD cockpit blocks until finance clear or authorized override.