- Home
- User guide
Every screen, what it does, how to test it, and what the lawyers still have to settle.
One page for the establishment evaluating CBS, the staff who will test it, and the legal department that has to read the paperwork before anything is signed. The feature list is generated from the same register the build status page is generated from, so it cannot drift from what is actually running.
- 1 · The four modules Who each one is for, and what it is.
- 2 · Feature list All 82 screens, module by module.
- 3 · Recent additions Public network features, offline-first PHC support, national integrations.
- 4 · Testing protocol 7 phases, for your own staff.
- 5 · Legal documents 6 drafts awaiting vetting.
One platform, four doors.
CBS Health is the platform. The four modules are doors within it, not separate products and not separate logins: a single sign-in carries across every door the signed-in person's role permits. Every permission is scoped to the role and to the establishment, so a clerk at one nursing home cannot reach another's patients by any route.
CBS Dock
40 of 41 screens liveHospital and nursing-home staff — front desk, wards, pharmacy, stores, accounts, administration · /dock/login
The hospital's own working surface, and the largest of the four. A patient is registered here, given a bed, billed, discharged and followed up here; the store, the duty roster, the vendors, the laboratory, the audit trail and the staff roll are all here too. If a task belongs to the establishment rather than to one clinician or one patient, it is in Dock.
- Every screen is scoped to a facility. A clerk at one nursing home cannot open another's patients, and that is enforced by the API rather than by hiding a menu item.
- The administrator decides and CBS records. Dock suggests, warns and audits; it does not overrule the person who is legally responsible for the patient.
CBS Medico
17 of 17 screens liveThe clinician — doctor, AYUSH practitioner, and the nurse at the bedside · /medico/login
One doctor's own view, carried across every establishment they practise at. Their patients, their queue, the consultation, the prescription, the ward round, the discharge narrative and their own earnings statement. Where Dock answers 'what is happening in this hospital', Medico answers 'what is waiting for me'.
- A consultant sees their own earnings and cannot open another's — the statement is scoped by the signed-in token, not by a parameter in the address bar.
- Every AI suggestion is labelled, cited and logged, and none of it acts on its own. A clinician remains in the loop for anything that reaches a patient.
CBS Care
13 of 13 screens livePatients, the family member who looks after them, and the home device estate · /care/login
The patient's own door. Their record, their appointments, their medicines, the bills and reports the hospital has released to them, and the people looking after them. It also carries the home side of the CB device — the check-in, the fall, the SOS — and the refill request that asks the medical shop to prepare a repeat.
- A patient signs in by one-time code against their own phone number, not with a hospital password.
- Care asks and never dispenses. A refill request closes by attaching a bill the shop's till made, so stock leaves one place and one place only.
CBS Counter
11 of 11 screens liveThe medical shop — the owner, and whoever is standing at the till · /counter/login
The shop counter, and a different business from the hospital even when the same family owns both. Ringing up a sale, dispensing against a prescription, the credit book, the day book, stock in and stock out, expiry, and the statutory registers a drug inspector asks for. It carries over-the-counter goods as well as medicines.
- The shop's ledger is separate from the hospital's consumable store by design, ruled on 2026-09-11. Two businesses, two stocks, two sets of books — one login.
- Schedule H1 and Schedule X registers print as PDFs. Whether a particular state also requires a bound paper register is a question still to be settled with a working shop.
India (Digital Personal Data Protection Act) · United Kingdom (UK GDPR) · United States (HIPAA) · Singapore (Personal Data Protection Act) · Malaysia (Personal Data Protection Act (Malaysia)). Patient names, telephone numbers and addresses are encrypted before they reach the database, and every read of a patient record is written to an audit trail that names who looked and when.
Every screen, grouped the way the software groups it.
Each row carries the screen's permanent number. That number is printed on the screen itself, it never changes when a screen is renamed or moved, and it is the only thing a bug report needs in order to be actionable. The grouping below is the navigation grouping, so this table reads in the same order as the menu your staff will see.
The third column says what a screen does and what it still lacks, in the same sentence. A row can therefore read “Live” and still name something missing — “no facility-wide search”, “no export” — and that is not a contradiction. Live means the screen and the API beneath it are both built and working; the clause after it is the next piece of work on that screen, written down where a hospital can see it before deployment rather than discover it in its second week.
CBS Dock — 41 screens
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| DK-13 | Facility dashboard | The facility's day at a glance, over one aggregate read and no writes | /dock | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| DK-01 | Patient registration | Register, MRN, duplicate detection, consent rows. Four fields the design draws have no column yet: language, next of kin, insurance, Care claim code | /dock/registration | Live |
| DK-14 | Patient index -- search, list, edit, export | Read, search, the facility list, correction of a registered record, and CSV export | /dock/patients | Live |
| DK-05 | Billing -- OP, IP, pharmacy | Invoice, lines, part-payments, discount, auto-lock, dashboard filters. Money is integer paise on the wire | /dock/billing | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| DK-15 | Ward board and bed management | Wards, beds, occupancy, snapshots, device pairing | /hms/wards | Live |
| DK-16 | Admission | Admit, assign bed, transfer Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token | /hms/admissions | Live |
| DK-17 | In-patient census | Census and summary, on a screen of its own | /dock/census | Live |
| DK-18 | Discharge -- the operational half | Screen built. The endpoint can be called once and never re-read or amended -- needs GET and PATCH on the discharge record Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token | /dock/discharge | Live |
| DK-19 | Admission history | By number, open-for-patient, the facility's history list, and CSV export | /dock/admissions/history | Live |
| DK-21 | Follow-up desk and reminders | Overdue and summary live, and the appointment reminder is emitted on the event spine | /dock/followups | Live |
| DK-20 | Prescription register | Create, the active list, and the facility's register with a medication search | /dock/prescriptions | Live |
| DK-02 | Appointment desk | Slots, next-free, book, reschedule, cancel Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token | /hms/appointments | Live |
| DK-03 | Incoming appointment requests | Requests triaged, then scheduled or declined with a reason. A request is not an appointment until the slot engine schedules it | /dock/requests | Live |
| DK-22 | Formulary | Search, stock flag, discontinue, formula-injection guard Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token | /hms/formulary | Live |
| DK-23 | Formulary import | Template columns, import, batch history, on a screen of its own Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token | /dock/formulary/import | Live |
| DK-07 | Consumable inventory | The hospital's own consumable store, on a ledger separate from the shop's — ruled 2026-09-11. Issues to a ward, expiry, reconciliation | /dock/inventory | Live |
| DK-08 | Vendors and purchase orders | Vendors, purchase orders and goods receipts. A receipt writes the store's movements in one transaction, validated before any line lands | /dock/procurement | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| DK-40 | Lab orders | Raise, track and cancel a lab order. The ordering half of the specimen lifecycle; no result is shown here because at this stage the specimen has not been taken | /dock/lab/orders | Live |
| DK-41 | Specimen collection | The collection round, with recollection recorded rather than overwriting the original | /dock/lab/collection | Live |
| DK-42 | Result entry | Entry, verification and retraction. The API withholds a value until it is verified, and the screen says why the cell is empty | /dock/lab/results | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| DK-29 | Clinical handovers | Endpoints mounted and role-guarded — doctor and nurse | /dock/handovers | Live |
| DK-04 | SOS and alert desk | Events and notification live, and the facility's own alert queue with the counts behind the desk tiles | /dock/alerts | Live |
| DK-45 | AI Referral approvals | Approve or decline an AI-suggested referral before it leaves the hospital. The service, the API and the audit trail are live; the screen is built and currently unreachable, because no role has been granted it yet | /dock/ai-referrals | Partial |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| DK-06 | Discharge summary print | Renders as PDF on the facility letterhead; nine locales, refusing rather than printing boxes. Printed from Dock | /dock/documents/discharge | Live |
| DK-12 | Consent forms and certificates | Prints the facility's own wording, and a marked preliminary draft where it has none. MTP and sterilisation get no draft — the prescribed text governs, and the form says so | /dock/documents/consent | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| DK-24 | Users and roles | Invite by Google address, list, change role, turn access on and off. The last active administrator cannot be turned off | /dock/admin/users | Live |
| DK-44 | Staff records | Employment and fitness for duty — joining, confirmation, exit, who to telephone, and whether somebody may be worked long hours. The only screen holding staff health information, administrator-only; the roster is told that a restriction exists and never why | /dock/admin/employment | Live |
| DK-27 | Facility profile -- name, address, letterhead | Registry, letterhead block, GSTIN and registration number | /dock/admin/facility | Live |
| DK-30 | Departments | Department is on neither the user nor the token | /dock/admin/departments | Live |
| DK-31 | Integrations -- FHIR, ABDM | Both clients exist; neither has a configuration screen | /dock/admin/integrations | Live |
| DK-32 | Device estate | Bedside devices: pairing, unpairing and the boot lookup, on real data. Home devices register but cannot yet be listed | /dock/admin/devices | Live |
| DK-33 | Support desk | Ticket desk, SLA sweep, notifications | /dock/admin/support | Live |
| DK-26 | System and error log | The ring buffer, and the delivery failures that survive a restart. Says on the page that its buffer is one worker's memory | /dock/admin/logs | Live |
| DK-10 | Duty roster | The week, with leave beside the shifts. Says who was expected, never who attended | /dock/admin/roster | Live |
| DK-09 | Doctor payments | Terms, payouts and what is owed. The whole run; a doctor sees only their own on MD-05 | /dock/admin/payments | Live |
| DK-11 | Finance metrics to Vitta | The hospital's own money — billed, collected, owed, by category and by payer. Reports and sends nothing outward | /dock/admin/finance | Live |
| DK-25 | Audit log | Ten route guards and a read permission, with a screen over them | /dock/admin/audit | Live |
| DK-43 | Navigation policy | A hospital edits its own rail. Replaces the CBS default per destination; an empty role list turns one off for everybody | /dock/admin/navigation | Live |
| DK-34 | Policies and compliance | The establishment's policies and what CBS observed. It records and reports and does not block: the administrator decides, and CBS keeps the account of what was decided | /dock/admin/policies | Live |
| DK-35 | My profile | Profile reads; no password to change, by design -- staff use Google | /dock/profile | Live |
| MD-17 | Help | Answers all three modes. The top-bar help icon used to 404 on every Dock and Care page | /dock/help | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| DK-28 | Sign in | OAuth2, Google SSO, rate limiting, lockout | /dock/login | Live |
CBS Medico — 17 screens
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| MD-11 | Home -- today's work | Today's work, over one aggregate read | /medico | Live |
| MD-12 | My patients | The clinician's own list, distinct from the desk view | /medico/patients | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| MD-02 | Consult, prescribe, save | Prescribing and interaction checks, written against a real encounter record | /medico/consult | Live |
| MD-01 | Patient timeline | One patient's record as a single ordered stream, with the filter chips served from the API | /medico/timeline | Live |
| MD-06 | Prescription print | Prints with the prescriber's registration and the interactions caught at prescribing. Printed from Medico | /medico/prescription | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| MD-13 | Reviews queue | The review queue, over its own endpoint | /medico/work/reviews | Live |
| MD-07 | Ward round notes | Read and write, per admission Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token | /medico/rounds | Live |
| MD-03 | Discharge authoring | The narrative is written at discharge, and DK-18 reads it back and amends it afterwards Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token | /medico/discharge | Live |
| MD-09 | My follow-ups | Due, overdue and summary, on a screen. It is the facility's list, not mine -- the endpoints carry no attending clinician | /medico/work/followups | Live |
| — | Alerts | BE-6 — no per-user alert queue endpoint | /medico/work/alerts | Yet to start |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| MD-08 | Clinical Buddy | Mounted and role-guarded on all three routers — asking the assistant a clinical question is separated from curating what it knows | /medico/buddy | Live |
| MD-04 | Messages -- in- and out-patient | Threads, participants, priority, offline queue | /medico/messages | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| MD-14 | Reports | Reports, with saved views and a server-side export | /medico/reports | Live |
| MD-05 | My earnings | A doctor's own statement, scoped by the token rather than by a parameter, so one consultant cannot open another's | /medico/earnings | Live |
| MD-15 | Institution | A clinician's read-only view of the facility profile | /medico/institution | Live |
| MD-16 | Settings | Notification preferences, on a settings screen of their own | /medico/settings | Live |
| MD-17 | Help | Answers all three modes. The top-bar help icon used to 404 on every Dock and Care page | /medico/help | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| MD-10 | Sign in | Shared with DK-28 | /medico/login | Live |
CBS Care — 13 screens
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| CR-05 | My health | The patient's own summary of their record, patient-scoped | /care/health | Live |
| CR-09 | Today's plan | Today's plan for this patient, patient-scoped | /care/plan | Live |
| CR-03 | SOS | The in-app button and the paired device both raise it. No automatic escalation ladder: a person answers, which is the design | /care/sos | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| CR-02 | Book an appointment | Clinics, free slots, and a booking that becomes a request the desk answers — patient-scoped throughout, and a slot taken while the patient decides is said in the server's own words | /care/appointments | Live |
| CR-06 | Medicines and adherence | What this patient is on and whether it is being taken, patient-scoped | /care/medicines | Live |
| CR-11 | My medicines | What the patient can collect at the shop and has already collected — the prescription joined to the shelf and the bills. Not a second CR-06 | /care/shop-medicines | Live |
| CR-12 | Refill request | Asks the shop to prepare a repeat. A request, never a dispensing: it closes by attaching a bill the till made, so stock leaves one place | /care/refill | Live |
| CR-13 | Order status | What the shop has accepted, prepared and handed over | /care/refill-status | Live |
| CR-04 | Reports and bills | The results and invoices this patient may see, patient-scoped | /care/reports | Live |
| CR-07 | Messages to the care team | Thread engine and patient identity live; a patient is still not a participant on a thread | /care/messages | Live |
| CR-08 | Care team | The care team as the patient sees it, patient-scoped | /care/team | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| CR-01 | Sign in and link record | OTP, account, and the link to a patient record -- twelve routes. The sign-in page exists; the linking screen does not | /care/link | Live |
| CR-10 | People I care for | Delegation is live -- read, list and revoke, scoped. Screen to build | /care/delegations | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| — | Devices | No Device entity exists, so hms-care.js renders a labelled placeholder | /care | Yet to start |
CBS Counter — 11 screens
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| CN-01 | Counter sale | Counter sale — discount, khata credit and tender modes, over the till API | /counter | Live |
| CN-02 | Prescription queue | Prescription queue across Medico, paper and photograph sources | /counter/prescription | Live |
| CN-08 | Day book | Day book, including the held-bill sync queue | /counter/daybook | Live |
| CN-11 | Khata — credit accounts | The shop's credit book — customer accounts, credit limit, what is owed and what was collected. A limit of zero, the default, means cash only; a walk-in with no account must pay in full | /counter/khata | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| CN-03 | Item master | Item master with composition provenance and per-item GST | /counter/items | Live |
| CN-04 | Receive stock | Receive stock, distributor invoice reconciled | /counter/receive | Live |
| CN-05 | Purchase | Reorder by days of cover rather than by shortfall. The shop's own purchasing, separate from DK-08 since the ledgers are separate | /counter/purchase | Live |
| CN-06 | Expiry board | Expiry board and dead stock | /counter/expiry | Live |
| CN-09 | Stock take | Stock take and variance | /counter/stocktake | Live |
| No. | Screen | What it does, and what it still lacks | Opens at | State |
|---|---|---|---|---|
| CN-07 | Statutory registers | H1 and X registers with the printed PDF. Whether Karnataka requires a bound register is still to be settled with a working shop | /counter/registers | Live |
| CN-10 | Owner metrics | Owner metrics — valuation, reorder, dead stock, takings | /counter/metrics | Live |
It counts screens. It does not count the platform beneath them — the mounted API routes, the encryption core, the compliance plugins, the audit trail, the public site and continuous integration are listed separately on the build register, precisely so that counting screens is not mistaken for counting the product.
Public network features, offline-first PHC support, and India's national integrations — added since the previous revision.
None of these add to the screen count above — they are new public pages, new backend capability, and one live demo, not new entries in Dock, Medico, Care or Counter's own navigation rail. Named here because they are real and working today, with exactly what is honestly still a placeholder said plainly rather than implied.
The Doctor Credentials Wall
A hospital's physical lobby signboard, digitised — name, recognised qualifications, registration number, specialty. No rating, no testimonial, no free-text field a doctor could turn into an advertisement. A credential appears only once a facility administrator has verified it against the practitioner's real documents.
Empanelment & the network directory
cbshealth.in's own public listing of empanelled facilities and their doctors, distinct from a hospital's own subdomain wall. A facility applies; only a platform-side supervisor can approve it — never the facility's own administrator.
Hospital-branded subdomains
A hospital reachable at its own domain, resolved automatically to the right facility, showing its own credentials wall with nothing for a visitor to know or type.
Offline-first PHC booking
A front desk with no live connection can take a booking, queue it locally, and sync the moment a connection appears. Two devices queuing the same slot while both offline resolve honestly — one accepted, one a real conflict with a real suggested alternative, never a silent overwrite.
Free-drug scheme flagging
A formulary entry marked free under a named state or national scheme shows inline in the prescribing picker, and is filterable on its own — what costs the patient nothing, in the same glance as the drug name.
Voice prompts, low-literacy first
Pre-recorded audio, not a live cloud call that fails silently with no signal. Falls back to a default language when a specific one has not been recorded yet.
India’s national integrations, scoped honestly
| Integration | What is real today |
|---|---|
| ABDM (Ayushman Bharat) | Real CBS-side patient data builds the health-record bundle; the external gateway call itself is a documented mock pending sandbox access. |
| e-Sanjeevani | A real, tracked, de-identified referral record — an age band and gender reach the external system, never a name or record number. |
| HMIS monthly export | Real aggregation against CBS's own records; the government portal's exact field format is not yet verified against a live reference. |
A feature is only called live here once it has been run against a real database with a real request, not merely written. Where an external government system is involved and no sandbox credential exists yet, that is said plainly rather than implied by silence.
For your own staff, in a browser. No command line.
Work through the phases in order. Each scenario says what to do and what should happen. If what you see differs from what is described — even slightly, even where it looks harmless — that is a finding and we want it. You do not need to understand how CBS works to test it well. You need to be stubborn about numbers that disagree with each other.
Everything in a test instance is invented, and it is not covered by the protections a live deployment has. A real name, telephone number or address typed into it creates a data-protection problem rather than a test result. Use the demonstration patients you were given.
T0 · The five-minute health check
Everything after this is unreliable if the instance is misconfigured, and a day spent testing a misconfigured instance produces findings that are all environment and no product.
| No. | Do this | You should see |
|---|---|---|
| T0.1 | Open the address you were given. | The public CBS site. Not an error, not a blank page. |
| T0.2 | Add /dock/login to it. | A sign-in page that says CBS Dock. |
| T0.3 | Look for a coloured 'demo mode' banner. | There should be none. If there is, sign-in is switched off and no permission test below means anything — stop and report it. |
| T0.4 | Sign in with the account you were given. | You land on a working screen, not back at sign-in. |
| T0.5 | Check the address is not one ending .run.app. | If it is, ask for a different one. That address refuses everything by design and every screen will look missing. |
T1 · The numbers must agree with each other
This is the highest-value testing in the whole protocol. Two screens disagreeing about how many patients are in a ward is the most serious class of defect CBS can have, and it is invisible to any automated test that checks one screen at a time.
| No. | Do this | You should see |
|---|---|---|
| T1.1 | Open the ward board. Write down the occupied count for one ward. | A number you can read without interpretation. |
| T1.2 | Open the in-patient census for the same ward. | The same number. A difference of even one is a finding, and an urgent one. |
| T1.3 | Admit a test patient to that ward. Return to both screens. | Both go up by exactly one. |
| T1.4 | Discharge that patient. Return to both screens. | Both return to what you wrote down in T1.1, and 'discharged today' goes up by one. |
| T1.5 | Transfer a patient between two wards. | One ward goes down by one, the other up by one, and the hospital total does not move. |
| T1.6 | Repeat T1.3 with two people working at once, on two computers. | Still exactly one. Two clerks admitting at the same moment must not produce two beds or none. |
T2 · A patient's whole journey, once, end to end
Each screen can pass on its own and the journey between them still break. This is the only phase that tests the joins, and the joins are where a real clinic gets stuck.
| No. | Do this | You should see |
|---|---|---|
| T2.1 | Register a new patient at the front desk. | A hospital number is issued. Registering the same person twice is noticed and flagged. |
| T2.2 | Book them an appointment. | The slot disappears from the free list. Booking the same slot twice is refused, not quietly accepted. |
| T2.3 | As the doctor, open the consultation and prescribe. | The drug is checked against what they already take, and an unknown code is refused rather than stored. |
| T2.4 | Print the prescription. | It carries the establishment's letterhead and the prescriber's registration number. |
| T2.5 | Admit them, record a ward round, write the discharge and print the summary. | Each step finds the previous one. The summary prints on the letterhead in the language chosen. |
| T2.6 | Raise the bill, take a part-payment, then the balance. | The outstanding figure is right at each step and the bill locks when settled. |
| T2.7 | Find the same patient again from the patient index a day later. | Everything above is on their record, in order. |
T3 · Try to see what you should not
A permission that is merely a hidden menu item is not a permission. This phase attacks the guarantee rather than the interface, and a single finding here outranks every other finding in this document.
| No. | Do this | You should see |
|---|---|---|
| T3.1 | Signed in at one establishment, edit the address bar to name another's. | Refused. Any patient data returned here stops the test session and is reported privately, never in a tracker. |
| T3.2 | Copy a patient's internal identifier from one establishment and request it from another. | Refused, the same way. |
| T3.3 | As a nurse, open a billing screen. As a billing clerk, open a clinical one. | Refused in both directions, by the server and not merely by a missing link. |
| T3.4 | Sign out, then press the browser's Back button. | You are not signed in again. You are sent to sign-in. |
| T3.5 | Read a patient record, then ask an administrator to show the audit trail. | Your read is on it, with your name and the time. A way of reading a record that leaves no trace is a finding. |
| T3.6 | Have an administrator switch your access off while you are signed in. | Your next action is refused. |
T4 · The shop, and the hospital store beside it
Counter is the newest module and the one with statutory paperwork attached. It is also the one where stock leaving twice, or not at all, costs real money.
| No. | Do this | You should see |
|---|---|---|
| T4.1 | Ring up a cash sale of two items, one with a discount. | The total, the tax and the discount are right, and the stock falls by exactly what was sold. |
| T4.2 | Put a sale on a customer's khata, then collect against it later. | The balance rises and falls correctly. A customer with no credit limit cannot be given credit. |
| T4.3 | Dispense against a prescription raised in Medico. | It arrives in the queue and closes when dispensed. It cannot be dispensed twice. |
| T4.4 | Receive a distributor's delivery against its invoice. | Every line lands or none does. A part-posted delivery is a finding. |
| T4.5 | Print the Schedule H1 and Schedule X registers. | They print, and what they show matches what was actually dispensed. |
| T4.6 | Close the day book and compare it with the cash in the drawer. | They agree, and what went on credit is shown separately from what was taken in cash. |
| T4.7 | Issue a consumable from the hospital store to a ward, then check the shop's stock. | The shop's figures have not moved. The two ledgers are separate and must stay so. |
T5 · The patient's own door
Care is used by patients and by the family member looking after them, on their own phone, without training. Anything that needs explaining is a defect even when it works.
| No. | Do this | You should see |
|---|---|---|
| T5.1 | Sign in as a patient with a one-time code. | It arrives, it works once, and an old code does not. |
| T5.2 | Look at your own record, appointments and medicines. | Only your own. Never anybody else's, by any route. |
| T5.3 | Ask the shop for a refill and follow it to collection. | The status is truthful at each step, and nothing is dispensed by the request itself. |
| T5.4 | As a family member, open the record of the person you care for. | Permitted only where that delegation was actually granted, and withdrawable. |
| T5.5 | Press SOS. | It reaches somebody, and the fact that it did is recorded. |
T6 · Language, printing and the things people actually complain about
A hospital abandons software over a printed page that is wrong, far more often than over a failure in the clinical logic.
| No. | Do this | You should see |
|---|---|---|
| T6.1 | Change the language and move between screens. | It stays changed. Nothing falls back to English half-way. |
| T6.2 | Print a discharge summary in a non-English language. | The letters are letters. Empty boxes mean a missing font, and CBS should refuse to print rather than print boxes. |
| T6.3 | Print a bill, a consent form and a register. | Each carries the establishment's own name, address and registration number — not CBS's. |
| T6.4 | Use CBS on a phone, on the smallest screen you have. | Every screen is usable. Nothing is cut off and nothing needs sideways scrolling to complete a task. |
| T6.5 | Lose the network half-way through writing a note. | You are told. Nothing is silently discarded and nothing is silently duplicated when the network returns. |
How to write it down so it can be acted on.
Report a bug by its screen number and nothing else — DK-05, MD-09, CN-11. The number is printed on every screen, it is permanent, and it never changes when a screen is renamed or moved. A report that describes 'the billing page' costs somebody a search; a report that says DK-05 does not.
| Severity | What it means | What to do |
|---|---|---|
| S1 | One establishment can see another's patients; sign-in can be got around; patient information is exposed; data is lost. | Report privately to the named contact, not in a tracker. A written description of how to read another hospital's patients is itself the incident. |
| S2 | Clinical information is wrong; a normal action produces an error page; something happened and the audit trail does not show it. | Report the same day, with the screen number and what you did. |
| S3 | A task cannot be completed, or completes wrongly but there is a way round it. | Report with the workaround you used. |
| S4 | Wording, layout, spacing, a wrong label. | Collect them and send them together. |
A module passes when every scenario for it returns its expected result or the deviation is filed and triaged, no S1 or S2 is open against it, and the automated suites are green on the same commit. Record the date, the tester and the version tested — a pass is a pass on a stated version, not in general.
Drafts. Not one of them is signed, and not one is final.
None of these documents has been read by a lawyer. None is to be signed, published, or sent to a hospital until one has. They exist so that a lawyer is reviewing a draft rather than being asked to write one from nothing, and so that the first establishment has something in front of it.
The contracting party. Shuka Technologies Private Limited, Ramgopalpet, Hyderabad, Telangana 500003. PAN AAXCS9938H, GSTIN 36AAXCS9938H1ZB, incorporated 10 October 2017 as a private limited company supplying services.
Each draft below names what a lawyer is being asked to settle, not merely to read. Those are the points where the drafting has gone as far as it usefully can without a professional opinion, and they are the fastest way to get value from a paid review.
L1 · Master Services Agreement
docs/legal/master-services-agreement.md
The agreement between the implementation company and the establishment that licenses CBS. Written for a practising doctor running a nursing home, not for a corporate legal department.
- Jurisdiction is Hyderabad, on the ground that the company is headquartered there. Confirm this survives a tenant in another state.
- Liability is capped at the fees actually paid for the payment period in which the claim arose, pro rata. The clause is written to be hard to get around — confirm it actually is.
- A dispute between a patient and the hospital is stated not to be ours, and the hospital settles its own at onboarding. Confirm that allocation holds under Indian law.
- The registered-office address on the certificate of incorporation may be fuller than the tax record. Confirm which address belongs in the agreement.
L2 · Privacy Policy
docs/legal/privacy-policy.md
The public-facing statement, written to be read by a patient or a doctor rather than by a lawyer. Short sentences, no defined terms in capitals.
- Whether the plain wording is sufficient for the DPDP Act, or whether prescribed language is required and must displace it.
- Whether the hospital or the company is the data fiduciary on each processing activity described, and whether the page says so clearly enough for a patient to know whom to complain to.
- The retention periods, against what the relevant state's clinical-records rules require.
L3 · Data Processing Agreement
docs/legal/data-processing-agreement.md
Annexed to the Master Services Agreement. Who processes what, on whose instruction, in which country, and what happens on breach or on exit.
- Data currently rests on a managed PostgreSQL instance in Singapore. The move to India is planned and contractual rather than statutory — confirm that is right, and that the agreement describes where the data actually is rather than where it is going.
- The breach-notification clock, and to whom notice runs.
- Sub-processors: whether the list must be exhaustive at signature or may be maintained and notified.
- What the establishment gets on exit, in what format, and for how long it can ask.
L4 · Refund and cancellation policy
docs/legal/refund-and-cancellation-policy.md
Required because an Indian payment gateway will not process payments without a stated refund policy. 'No refunds' is a policy; having none is not.
- Whether a flat no-refund position is enforceable against an establishment, and whether it needs a carve-out for a period billed and never served.
- Whether withholding service for non-payment needs anything said about notice before it happens.
L5 · Consent forms and certificates
docs/regulatory/consent-forms.md
The forms an establishment prints and a patient signs — admission, procedure, anaesthesia, and the certificates a hospital issues.
- The open question D7: whether CBS prints statutory consent wording of its own, or only ever prints the establishment's own wording. Today it prints the establishment's, and a clearly marked preliminary draft where the establishment has none.
- Medical termination of pregnancy and sterilisation get no draft at all, because the text is prescribed. Confirm that is the right treatment and that nothing else belongs in that category.
- Who may consent for a minor or for an incapable patient — open as decision D5 and blocking the patient-facing module.
L6 · Statutory registers — Schedule H1 and Schedule X
docs/regulatory/drug-register/
The registers a drug inspector asks a medical shop for. CBS prints both, with a blank proforma and a worked specimen of each.
- Whether a printed PDF register satisfies the requirement in the state the first shop trades in, or whether a bound register written by hand is still required alongside it.
- Retention: how long a register must be produceable, and whether that obligation sits with the shop or with us.
Questions held for the establishment, not for us.
These are not defects and they are not drafting gaps. Each is a question whose answer belongs to the establishment or to its advisers, and each is named here rather than guessed at in code.
| Ref | Question | Kind | What it holds up |
|---|---|---|---|
| D3 | Self-booking policy -- which specialities, how far ahead, what cancellation window | Commercial and clinical | The Care appointments screen |
| D4 | The ten booking policy defaults -- approve, or amend by line | Commercial and clinical | DK-02 shipping to a facility |
| D5 | Who may consent for a minor or an incapable patient | Legal -- drafted, needs a lawyer | Care reaching the public |
| D6 | Who is the data fiduciary when a facility uses its own AI key | Legal -- drafted, needs a lawyer | Any outward claim about BYOK |
| D8 | Who may countersign -- a role, a seniority, or a named senior per facility | Clinical and organisational | The approvals model, and both phones' primary screen |
| D9 | What may be raised for approval -- any prescription, high-risk drugs only, C-section decisions, discharge | Clinical | The scope of approvals |
| D10 | Unanswered countersignature -- after how long, and to whom does it escalate | Clinical safety | Shipping approvals to a facility |
| D12 | Which requests may a nurse raise, as against a doctor | Clinical and organisational | Recipient rules on the exchange |
| D13 | Escalation clock per request kind | Clinical safety | Shipping the exchange to a facility |
| D14 | Do journey notifications go to the patient, the attendant, or both -- and who nominates the attendant | Legal and product | Sending anything to a patient |
| A1 | Ayurvedic vocabulary -- transliteration, the panchakarma staging, and whether it belongs in demonstration data | Domain truth | The AYUSH catalogue reaching a customer |
Send this page to your lawyer, and your ward sister.
They are the two readers it was written for. We would rather answer a hard question before a deployment than explain an answer after one.