Healthcare
Clinics, hospitals and health platforms, where the patient record is regulated data and the claim is a second system of record.
The context
Clinics and hospitals run two records at once: the clinical one a care team writes, and the financial one a payer adjudicates. Both are personal data under the PDPL, and the exchange between them runs on profiles NPHIES defines rather than the product. The software is in the room during care, so a failure is a clinical event before it is an outage.
What makes it hard
The claim outlives the visit
Eligibility, pre-authorization, claim and adjudication each carry their own state, and NPHIES can reject a message long after the patient has left. A record model built around the encounter alone has nowhere to put that rejection.
One patient, several identifiers
A patient arrives as a national ID, an iqama number, a border number or a file number from another facility. Matching and merging those into one record is the decision every later integration inherits.
Reading a chart is an event
Who opened a chart, when and under which role is a record in its own right. Break-glass access matters most, and it belongs where the data is served rather than in application code.
Retention against erasure
The PDPL gives a patient rights over their data, and medical record retention obliges the provider to keep the clinical file. An erasure request therefore has to end in restricted processing and revoked access rather than a deleted row.
How we help
- The first review maps the record model against NPHIES before any screen is drawn: what a claim has to carry, what the encounter holds, and where the two disagree.
- Data residency, consent and retention are decided in the schema and the deployment region, not in a policy document.
- Access control follows the roles a hospital actually has, including the ones that exist for a single shift.
- A feature that computes a clinical output is kept separate in the architecture from one that only displays a record.
- Releases are planned around clinic hours, and an integration that is down degrades to a readable record rather than an error page.
- NPHIES eligibility, pre-authorization and claim exchange
- PDPL consent, residency and data subject rights
- HL7 FHIR profiles, HL7 v2 lab feeds and DICOM imaging
- SFDA rules for software that produces a clinical output
- CBAHI documentation the provider has to produce
- Nafath identity for patient-facing access
Related services
Tell us what you are building.
Send the outline and we will come back with an honest read on scope, sequence and what it takes to run it in production.
