The patient’s path is the thread to follow
In a medical or dental practice, software is almost never the problem. The problem is that a patient’s path crosses four or five different systems and between each of them there is a person copying.
Booking, reception, examination, report, filing, recall. The practice system knows the patient record and the diary. The equipment produces images. The reporting system produces documents. The archive keeps them. Each works; the connection is missing.
The result is that somebody renames files, moves them into the right folder, retypes data a system already had, and remembers to call back whoever did not turn up. It is repetitive work on sensitive data, and it is also the point where an image can end up attached to the wrong patient.
What does not get touched
This has to be said before everything else, because it is the constraint that determines the boundary of the work: diagnostic devices stay exactly as the manufacturer delivered them.
The certification applies to that configuration. Modifying the software of an ultrasound scanner or a radiology system to make it integrate better invalidates it, and that is a risk nobody should take. The work happens around the device: the files it produces in the standard formats it exposes are taken, and the rest of the path is brought up to standard.
The same principle applies to the network: the device does not get updated, so it gets isolated in a separate section where it carries on working without being an open door to everything else. We cover it under GDPR for medical practices and IT security.
Where the most time is gained
Automatically attaching images and reports to the patient. It is the most repetitive step and the one with the highest risk of error.
Appointment reminders. They reduce missed appointments, which are a direct cost. They have to be written neutrally, though: a message revealing the treatment to anyone glancing at the phone screen is a confidentiality problem, not a convenience.
Periodic recalls. Check-ups, hygiene, follow-ups. The practice system often already knows when they are due, but nobody has connected that knowledge to a message going out.
Forms and consents. Documents filled in every time with data the system already holds.
Access rights are designed, not set at the end
With health data, permissions are not a final configuration: they are an architectural choice. Whoever sees the diary does not necessarily need to see the records; whoever works at reception has no reason to open reports; a professional collaborating with the practice should reach their own patients and not everyone’s.
It is also why the single shared login — which we find in almost every practice — does not hold: without individual access you cannot say who consulted a record, and with health data that traceability is a protection for you before it is a compliance matter.
The rest
See also IT and GDPR for medical and dental practices, GDPR for medical practices and custom software development for the method.
The first step
We follow a patient’s path from booking to filing and count the manual steps. Out of that comes the list of what can be taken out of the way. Free and without obligation.