Corrections never rewrite history
When something needs fixing, the system posts a reversal linked to the original entry instead of editing it. The record an auditor sees is the record as it happened.
Security here is architectural, not a feature bolted on the side. Access is decided by role and enforced at the API; the record keeps its own history; and the bill can always be traced back to the chart it came from.
Twenty-three permissions map onto seven roles and decide every route, action and column. Access is not a menu that hides links — the API enforces it independently of the interface. The exact permission set is editable per hospital from Users & Roles.
Everything, plus users, roles and the 23-permission matrix.
Consultations, clinical charts, orders and discharge summaries.
Vitals, medication rounds, intake/output and progress notes.
Registration, appointments, the token queue and the bed board.
Invoices, receipts, refunds, the ledger and TPA pre-auth.
POS, inventory, purchases, GRN and the returns register.
Investigation orders, sample status and result entry.
The parts of the system that touch money and the clinical record are built so the history behind any number is always recoverable — nothing is edited in place, nothing simply disappears.
When something needs fixing, the system posts a reversal linked to the original entry instead of editing it. The record an auditor sees is the record as it happened.
An invoice or discharge document locks when it is issued, so a figure cannot be quietly changed after the fact.
Nothing is erased. A removed record leaves the working view but stays in the trail, so the history behind a decision is always recoverable.
Admission, discharge and a POS sale each commit inside one transaction — either the whole operation lands or none of it does, so stock, bed and ledger never drift apart.
A deterministic engine assembles every bill from the chart at read time, so an invoice cannot diverge from the treatment it bills for. Money is handled as BigDecimal end to end — no float drift.
Once a patient is discharged the clinical chart is closed, keeping the documentation that supports NABH readiness fixed and defensible.
Accreditation, tax and interoperability are not afterthoughts — they are wired into the record, the billing engine and the platform.
Access is enforced server-side, not only in the interface — the API refuses what a role is not entitled to. A pharmacist never reaches a clinical chart; a nurse never sees a refund voucher.
See how RBAC worksTax is GST computed backwards from an inclusive MRP, in Indian Rupees, on both the pharmacy POS and hospital invoices — the numbers reconcile the way your accountant expects.
Inside the billing engineThe clinical record carries the assessments, consents, investigations and discharge summaries that accreditation asks for — with an audit trail and role-based access behind every entry.
Read the NABH guideThe platform is HL7-ready for clinical interoperability and traffic is 128-bit encrypted, the same posture the product carries on its login.
Security questions in the FAQTell us how your wards, pharmacy and billing desk work today. We will set up a walkthrough on data that looks like yours.