Access & identity
The right people see the right things.
Nothing more.
Cliniqi treats security the way a good hospital treats hygiene: not as a feature, but as a habit built into every counter, ward and till. Open the same patient from three desks and each role sees only the screens its work needs. These are animated recreations of Cliniqi screens with sample data.
Ward nurse. Arjun's doses and vitals, each with her name on it. No bill.
Doctor. The same patient's notes and orders. Still no bill.
Cashier. The bill and the payment. No clinical notes.
Access · 01
Permissions follow the job, not the person.
- A role for every desk. Reception, nurses, doctors, pathologists, cashiers, pharmacists and administrators each see exactly what their work needs, and nothing else.
- Granular, down to the action. Permissions are set per feature, and separately for viewing versus changing. A cashier who can see a bill cannot quietly edit it.
- Assigned in-house. The hospital's own administrator grants and withdraws access from the back office. No vendor ticket, no waiting.
The permission matrix covers 81 areas of the system, each granted separately for viewing, editing, deleting and managing, role by role. High-risk grants are called out in red.
- Pick an areaPayments, for cashiers
- Tick the rightsView and edit only
- SaveFor the whole role
- LoggedWho changed what
Access · 02
Two steps, every time. Sessions you can see and end.
- Two steps, every time. Every sign-in asks for a password and a one-time code: every login, for every person, with no way to switch it off. There is no "trusted device" shortcut and no exception for seniority.
- Sessions you can see and end. Each person can see their own active sessions and sign any of them out. Administrators can review and revoke sessions across the whole hospital.
- Five devices at most. Each account can stay signed in on up to five devices, and a sixth sign-in signs the oldest one out. Because every sign-in needs a code sent to the account owner, a shared password alone gets nobody in.
- Five devicesThe most at once
- A sixth signs inThe oldest signs out
- Sign out anyFrom wherever you are
Clinical record integrity
Nothing silently disappears.
A permanent audit trail records who did what and when: sign-ins, edits, verifications, money actions. No screen in Cliniqi can edit or delete an entry, and the hospital's administrator can review all of it. In one working hospital, that trail already runs past twelve thousand events.
- Sign-insPassword and code
- MoneyPayments and shifts
- ClinicalReports and notes
- SettingsRoles and permissions
- ExportFor an inspection
Records · 01
A removed note is still on file.
- Clinical notes are never hard-deleted. Only the note's author can remove it; the note leaves the chart view but stays on file with who removed it and when, and its original text is kept in the audit trail for review.
- Every dose carries a name. Each administration on the medication sheet records the nurse's identity and the time. High-risk medicines ask for a second nurse as witness before the dose is recorded.
- Her own noteOnly the author can delete
- Off the chartLeaves the chart view
- Still on fileWho, when, original text
Records · 02
The life of a lab result, on the record.
- Entered. The value is recorded with the identity of the person who entered it, and the time.
- Verified. A pathologist with sign-off rights checks the values and signs before anything leaves the laboratory.
- Released. The signed report goes out carrying a QR code that proves it is genuine.
- Reopened, on the record. If a result must be corrected, who reopened it and why join the timeline, permanently.
If a report is questioned a year later, the answer is not a shrug. It is a timeline: entered by, verified by, released when, and by whom.
- EnteredBy name, with the time
- VerifiedSigned by a pathologist
- ReleasedThe moment it is signed
- ReopenedWith a written reason
Records · 03
Proof anyone can check.
Every released report, printed bilingual, हिंदी / English, carries a QR code. A patient, a referring doctor, an insurance desk: anyone can scan it and confirm the report is genuine, without logging in to anything. Scanning opens the original report straight from the hospital's system, so an altered printout shows up the moment the two are compared.
See how results are entered and verified on the laboratory module page.
- Scan the QRNo app, no sign-in
- The original opensFrom the hospital's system
- CompareAn altered value stands out
Money integrity
Prices are computed, never typed.
Most billing disputes start with a typed number. Cliniqi removes the habit: counter staff pick services, and every ₹ on the bill comes from the hospital's own fee book.
Priced by the system.
Counter staff never type an amount. They choose what was done; the price comes from the fee book the hospital maintains. Scheme rates and concessions apply on their own.
Discounts with a name on them.
A discount always carries a reason and an authoriser. There is no anonymous "adjustment": every rupee waived says who allowed it, and why.
Money · 01
Refunds that cancel cleanly.
Refunds are picked line by line from the bill, a partial refund needs a written reason, and refunding work already done needs an administrator's approval. A full refund cancels the bill and reprints the slip marked CANCELLED, so the paper trail matches the money trail.
- Pick linesNot the whole bill
- Give a reasonFor a partial refund
- ApprovalFor work already done
- ApprovedThen the money moves
Money · 02
Shifts that reconcile.
Every cashier's shift closes against the cash the system expected. Any difference is recorded against the shift, and a gap of ₹500 or more cannot be closed without a written explanation.
How this feels at the counter, day to day, is on the billing & revenue page.
- ExpectedWorked out by the system
- CountedEntered by the cashier
- Explained₹500 or more needs a note
- ClosedOn the audit trail
Privacy by design
Privacy is decided when the form is designed,
not audited in later.
Privacy · 01
Every field, tagged the moment it exists.
The registration form designer tags every field for privacy at the moment it is created. Personal identifiers and health information are labelled in line with India's DPDP Act framework, so the hospital can see, at a glance, exactly what personal data it collects and why. Nothing slips in unlabelled.
- Name itA new field
- Class itIt starts as personal data
- Keep it forA retention period
- ListedIts tag shows in the form
Aligned with the DPDP Act, 2023.
Collection is purpose-limited: the hospital gathers what care requires, and can show what it holds. The hospital stays in control of its patients' data as the data fiduciary, with us working strictly as its processor. We say "aligned with" deliberately: it describes how the product is built, not a certificate on a wall.
National health records, on the patient's terms.
ABDM (Ayushman Bharat Digital Mission) integration is consent-driven end to end. Records fetched from other hospitals appear only with the patient's consent, and are removed automatically the moment that consent expires. All three government integration milestones are implemented and verified end to end on the official test network; production use follows the government's certification, which is in progress.
Where the data lives
Hosted in India. Isolated per hospital.
Backed up every day.
Infrastructure · 01
Your records stay in India.
The platform and its database run from data centres in India, in the Mumbai region, and patient records are stored in India. Note drafting, dictation and the other AI drafts run there too. A few supporting services, such as email delivery and the consult scribe's speech recognition, may process data outside India.
- Encrypted in transit. Every connection is encrypted, everywhere: HTTPS on every screen and every device, with certificates managed and renewed automatically.
- SpokenOn the ward tablet
- EncryptedOn its way
- TranscribedIn India
- StoredIn India
One hospital, one space.
Every hospital's data is kept in its own isolated space. One hospital can never see another's records: by construction, not by policy.
Closed to the open internet.
The database that holds patient records is closed to the open internet: it accepts only the application's own authorised connections and a short list of approved addresses. Report links shared with patients work only with a long, unguessable code and expire after 90 days.
Keys live in a vault.
Credentials and keys are held in a managed secrets vault: not written into code, not sitting in files.
Backed up, watched, self-healing.
Automated daily backups with point-in-time recovery. Deployments are monitored, and services restart themselves on failure.
Clinical & statutory compliance
The paperwork the law expects,
kept automatically.
| Law or scheme | What Cliniqi does | Where it lives |
|---|---|---|
| PC-PNDT | An obstetric ultrasound report cannot be released without a Form F serial number. The rule is enforced by the system, not by memory. | Radiology |
| Schedule H1 | The pharmacy keeps the H1 register automatically as it dispenses: complete, current, and ready to print for an inspection. | Pharmacy |
| GST | Pharmacy invoices are GST tax invoices with the HSN code on every line and the CGST and SGST split, and the GST summary and registers export to Excel for the accountant. | Pharmacy |
| Ayushman / CGHS | Scheme billing follows package rates, and the claims paperwork generates as Excel, ready for submission. | Billing |
These registers live where the work happens: inside the pharmacy and billing modules.
An honest note
Security is a practice, not a page.
Everything above describes software that is built and running, not a roadmap. But no page can answer your hospital's particular questions: a purchase committee's checklist, a medical superintendent's worry about one screen, a trustee's question about where a record goes. Ask us anything specific. We would rather show you than reassure you.