Skip to content
CBS Health
  1. Home
  2. User guide
User guide & testing protocol — 2026-10-07

Every screen, what it does, how to test it, and what the lawyers still have to settle.

One page for the establishment evaluating CBS, the staff who will test it, and the legal department that has to read the paperwork before anything is signed. The feature list is generated from the same register the build status page is generated from, so it cannot drift from what is actually running.

4 Modules — Dock, Medico, Care and Counter, behind one sign-in
82 Numbered screens in the register, of which 81 are serving requests today
12 Platform layers live beneath the screens — encryption, audit, compliance, CI
5 Jurisdictions with their rules enforced in code, not in a policy document
1 · The four modules

One platform, four doors.

CBS Health is the platform. The four modules are doors within it, not separate products and not separate logins: a single sign-in carries across every door the signed-in person's role permits. Every permission is scoped to the role and to the establishment, so a clerk at one nursing home cannot reach another's patients by any route.

CBS Dock

40 of 41 screens live

Hospital and nursing-home staff — front desk, wards, pharmacy, stores, accounts, administration · /dock/login

The hospital's own working surface, and the largest of the four. A patient is registered here, given a bed, billed, discharged and followed up here; the store, the duty roster, the vendors, the laboratory, the audit trail and the staff roll are all here too. If a task belongs to the establishment rather than to one clinician or one patient, it is in Dock.

  • Every screen is scoped to a facility. A clerk at one nursing home cannot open another's patients, and that is enforced by the API rather than by hiding a menu item.
  • The administrator decides and CBS records. Dock suggests, warns and audits; it does not overrule the person who is legally responsible for the patient.

CBS Medico

17 of 17 screens live

The clinician — doctor, AYUSH practitioner, and the nurse at the bedside · /medico/login

One doctor's own view, carried across every establishment they practise at. Their patients, their queue, the consultation, the prescription, the ward round, the discharge narrative and their own earnings statement. Where Dock answers 'what is happening in this hospital', Medico answers 'what is waiting for me'.

  • A consultant sees their own earnings and cannot open another's — the statement is scoped by the signed-in token, not by a parameter in the address bar.
  • Every AI suggestion is labelled, cited and logged, and none of it acts on its own. A clinician remains in the loop for anything that reaches a patient.

CBS Care

13 of 13 screens live

Patients, the family member who looks after them, and the home device estate · /care/login

The patient's own door. Their record, their appointments, their medicines, the bills and reports the hospital has released to them, and the people looking after them. It also carries the home side of the CB device — the check-in, the fall, the SOS — and the refill request that asks the medical shop to prepare a repeat.

  • A patient signs in by one-time code against their own phone number, not with a hospital password.
  • Care asks and never dispenses. A refill request closes by attaching a bill the shop's till made, so stock leaves one place and one place only.

CBS Counter

11 of 11 screens live

The medical shop — the owner, and whoever is standing at the till · /counter/login

The shop counter, and a different business from the hospital even when the same family owns both. Ringing up a sale, dispensing against a prescription, the credit book, the day book, stock in and stock out, expiry, and the statutory registers a drug inspector asks for. It carries over-the-counter goods as well as medicines.

  • The shop's ledger is separate from the hospital's consumable store by design, ruled on 2026-09-11. Two businesses, two stocks, two sets of books — one login.
  • Schedule H1 and Schedule X registers print as PDFs. Whether a particular state also requires a bound paper register is a question still to be settled with a working shop.
Data protection is enforced per country, in code.

India (Digital Personal Data Protection Act) · United Kingdom (UK GDPR) · United States (HIPAA) · Singapore (Personal Data Protection Act) · Malaysia (Personal Data Protection Act (Malaysia)). Patient names, telephone numbers and addresses are encrypted before they reach the database, and every read of a patient record is written to an audit trail that names who looked and when.

2 · Feature list

Every screen, grouped the way the software groups it.

Each row carries the screen's permanent number. That number is printed on the screen itself, it never changes when a screen is renamed or moved, and it is the only thing a bug report needs in order to be actionable. The grouping below is the navigation grouping, so this table reads in the same order as the menu your staff will see.

The third column says what a screen does and what it still lacks, in the same sentence. A row can therefore read “Live” and still name something missing — “no facility-wide search”, “no export” — and that is not a contradiction. Live means the screen and the API beneath it are both built and working; the clause after it is the next piece of work on that screen, written down where a hospital can see it before deployment rather than discover it in its second week.

Live the interface and the API beneath it are both working Partial one of the two, or part of one Yet to start a labelled placeholder, shown rather than hidden

CBS Dock — 41 screens

CBS Dock · Overview
No. Screen What it does, and what it still lacks Opens at State
DK-13 Facility dashboard The facility's day at a glance, over one aggregate read and no writes /dock Live
CBS Dock · Front desk
No. Screen What it does, and what it still lacks Opens at State
DK-01 Patient registration Register, MRN, duplicate detection, consent rows. Four fields the design draws have no column yet: language, next of kin, insurance, Care claim code /dock/registration Live
DK-14 Patient index -- search, list, edit, export Read, search, the facility list, correction of a registered record, and CSV export /dock/patients Live
DK-05 Billing -- OP, IP, pharmacy Invoice, lines, part-payments, discount, auto-lock, dashboard filters. Money is integer paise on the wire /dock/billing Live
CBS Dock · Operations
No. Screen What it does, and what it still lacks Opens at State
DK-15 Ward board and bed management Wards, beds, occupancy, snapshots, device pairing /hms/wards Live
DK-16 Admission Admit, assign bed, transfer Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token /hms/admissions Live
DK-17 In-patient census Census and summary, on a screen of its own /dock/census Live
DK-18 Discharge -- the operational half Screen built. The endpoint can be called once and never re-read or amended -- needs GET and PATCH on the discharge record Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token /dock/discharge Live
DK-19 Admission history By number, open-for-patient, the facility's history list, and CSV export /dock/admissions/history Live
DK-21 Follow-up desk and reminders Overdue and summary live, and the appointment reminder is emitted on the event spine /dock/followups Live
DK-20 Prescription register Create, the active list, and the facility's register with a medication search /dock/prescriptions Live
DK-02 Appointment desk Slots, next-free, book, reschedule, cancel Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token /hms/appointments Live
DK-03 Incoming appointment requests Requests triaged, then scheduled or declined with a reason. A request is not an appointment until the slot engine schedules it /dock/requests Live
DK-22 Formulary Search, stock flag, discontinue, formula-injection guard Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token /hms/formulary Live
DK-23 Formulary import Template columns, import, batch history, on a screen of its own Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token /dock/formulary/import Live
DK-07 Consumable inventory The hospital's own consumable store, on a ledger separate from the shop's — ruled 2026-09-11. Issues to a ward, expiry, reconciliation /dock/inventory Live
DK-08 Vendors and purchase orders Vendors, purchase orders and goods receipts. A receipt writes the store's movements in one transaction, validated before any line lands /dock/procurement Live
CBS Dock · Diagnostics
No. Screen What it does, and what it still lacks Opens at State
DK-40 Lab orders Raise, track and cancel a lab order. The ordering half of the specimen lifecycle; no result is shown here because at this stage the specimen has not been taken /dock/lab/orders Live
DK-41 Specimen collection The collection round, with recollection recorded rather than overwriting the original /dock/lab/collection Live
DK-42 Result entry Entry, verification and retraction. The API withholds a value until it is verified, and the screen says why the cell is empty /dock/lab/results Live
CBS Dock · Clinical oversight
No. Screen What it does, and what it still lacks Opens at State
DK-29 Clinical handovers Endpoints mounted and role-guarded — doctor and nurse /dock/handovers Live
DK-04 SOS and alert desk Events and notification live, and the facility's own alert queue with the counts behind the desk tiles /dock/alerts Live
DK-45 AI Referral approvals Approve or decline an AI-suggested referral before it leaves the hospital. The service, the API and the audit trail are live; the screen is built and currently unreachable, because no role has been granted it yet /dock/ai-referrals Partial
CBS Dock · Documents
No. Screen What it does, and what it still lacks Opens at State
DK-06 Discharge summary print Renders as PDF on the facility letterhead; nine locales, refusing rather than printing boxes. Printed from Dock /dock/documents/discharge Live
DK-12 Consent forms and certificates Prints the facility's own wording, and a marked preliminary draft where it has none. MTP and sterilisation get no draft — the prescribed text governs, and the form says so /dock/documents/consent Live
CBS Dock · Administration
No. Screen What it does, and what it still lacks Opens at State
DK-24 Users and roles Invite by Google address, list, change role, turn access on and off. The last active administrator cannot be turned off /dock/admin/users Live
DK-44 Staff records Employment and fitness for duty — joining, confirmation, exit, who to telephone, and whether somebody may be worked long hours. The only screen holding staff health information, administrator-only; the roster is told that a restriction exists and never why /dock/admin/employment Live
DK-27 Facility profile -- name, address, letterhead Registry, letterhead block, GSTIN and registration number /dock/admin/facility Live
DK-30 Departments Department is on neither the user nor the token /dock/admin/departments Live
DK-31 Integrations -- FHIR, ABDM Both clients exist; neither has a configuration screen /dock/admin/integrations Live
DK-32 Device estate Bedside devices: pairing, unpairing and the boot lookup, on real data. Home devices register but cannot yet be listed /dock/admin/devices Live
DK-33 Support desk Ticket desk, SLA sweep, notifications /dock/admin/support Live
DK-26 System and error log The ring buffer, and the delivery failures that survive a restart. Says on the page that its buffer is one worker's memory /dock/admin/logs Live
DK-10 Duty roster The week, with leave beside the shifts. Says who was expected, never who attended /dock/admin/roster Live
DK-09 Doctor payments Terms, payouts and what is owed. The whole run; a doctor sees only their own on MD-05 /dock/admin/payments Live
DK-11 Finance metrics to Vitta The hospital's own money — billed, collected, owed, by category and by payer. Reports and sends nothing outward /dock/admin/finance Live
DK-25 Audit log Ten route guards and a read permission, with a screen over them /dock/admin/audit Live
DK-43 Navigation policy A hospital edits its own rail. Replaces the CBS default per destination; an empty role list turns one off for everybody /dock/admin/navigation Live
DK-34 Policies and compliance The establishment's policies and what CBS observed. It records and reports and does not block: the administrator decides, and CBS keeps the account of what was decided /dock/admin/policies Live
DK-35 My profile Profile reads; no password to change, by design -- staff use Google /dock/profile Live
MD-17 Help Answers all three modes. The top-bar help icon used to 404 on every Dock and Care page /dock/help Live
CBS Dock · Getting in
No. Screen What it does, and what it still lacks Opens at State
DK-28 Sign in OAuth2, Google SSO, rate limiting, lockout /dock/login Live

CBS Medico — 17 screens

CBS Medico · Everyday
No. Screen What it does, and what it still lacks Opens at State
MD-11 Home -- today's work Today's work, over one aggregate read /medico Live
MD-12 My patients The clinician's own list, distinct from the desk view /medico/patients Live
CBS Medico · The consultation
No. Screen What it does, and what it still lacks Opens at State
MD-02 Consult, prescribe, save Prescribing and interaction checks, written against a real encounter record /medico/consult Live
MD-01 Patient timeline One patient's record as a single ordered stream, with the filter chips served from the API /medico/timeline Live
MD-06 Prescription print Prints with the prescriber's registration and the interactions caught at prescribing. Printed from Medico /medico/prescription Live
CBS Medico · My work
No. Screen What it does, and what it still lacks Opens at State
MD-13 Reviews queue The review queue, over its own endpoint /medico/work/reviews Live
MD-07 Ward round notes Read and write, per admission Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token /medico/rounds Live
MD-03 Discharge authoring The narrative is written at discharge, and DK-18 reads it back and amends it afterwards Known gap: B4a — writes take facility_id from the JSON body and no handler checks it against the token /medico/discharge Live
MD-09 My follow-ups Due, overdue and summary, on a screen. It is the facility's list, not mine -- the endpoints carry no attending clinician /medico/work/followups Live
— Alerts BE-6 — no per-user alert queue endpoint /medico/work/alerts Yet to start
CBS Medico · Everyday
No. Screen What it does, and what it still lacks Opens at State
MD-08 Clinical Buddy Mounted and role-guarded on all three routers — asking the assistant a clinical question is separated from curating what it knows /medico/buddy Live
MD-04 Messages -- in- and out-patient Threads, participants, priority, offline queue /medico/messages Live
CBS Medico · More
No. Screen What it does, and what it still lacks Opens at State
MD-14 Reports Reports, with saved views and a server-side export /medico/reports Live
MD-05 My earnings A doctor's own statement, scoped by the token rather than by a parameter, so one consultant cannot open another's /medico/earnings Live
MD-15 Institution A clinician's read-only view of the facility profile /medico/institution Live
MD-16 Settings Notification preferences, on a settings screen of their own /medico/settings Live
MD-17 Help Answers all three modes. The top-bar help icon used to 404 on every Dock and Care page /medico/help Live
CBS Medico · Getting in
No. Screen What it does, and what it still lacks Opens at State
MD-10 Sign in Shared with DK-28 /medico/login Live

CBS Care — 13 screens

CBS Care · Now
No. Screen What it does, and what it still lacks Opens at State
CR-05 My health The patient's own summary of their record, patient-scoped /care/health Live
CR-09 Today's plan Today's plan for this patient, patient-scoped /care/plan Live
CR-03 SOS The in-app button and the paired device both raise it. No automatic escalation ladder: a person answers, which is the design /care/sos Live
CBS Care · My care
No. Screen What it does, and what it still lacks Opens at State
CR-02 Book an appointment Clinics, free slots, and a booking that becomes a request the desk answers — patient-scoped throughout, and a slot taken while the patient decides is said in the server's own words /care/appointments Live
CR-06 Medicines and adherence What this patient is on and whether it is being taken, patient-scoped /care/medicines Live
CR-11 My medicines What the patient can collect at the shop and has already collected — the prescription joined to the shelf and the bills. Not a second CR-06 /care/shop-medicines Live
CR-12 Refill request Asks the shop to prepare a repeat. A request, never a dispensing: it closes by attaching a bill the till made, so stock leaves one place /care/refill Live
CR-13 Order status What the shop has accepted, prepared and handed over /care/refill-status Live
CR-04 Reports and bills The results and invoices this patient may see, patient-scoped /care/reports Live
CR-07 Messages to the care team Thread engine and patient identity live; a patient is still not a participant on a thread /care/messages Live
CR-08 Care team The care team as the patient sees it, patient-scoped /care/team Live
CBS Care · Access
No. Screen What it does, and what it still lacks Opens at State
CR-01 Sign in and link record OTP, account, and the link to a patient record -- twelve routes. The sign-in page exists; the linking screen does not /care/link Live
CR-10 People I care for Delegation is live -- read, list and revoke, scoped. Screen to build /care/delegations Live
CBS Care · Estate
No. Screen What it does, and what it still lacks Opens at State
— Devices No Device entity exists, so hms-care.js renders a labelled placeholder /care Yet to start

CBS Counter — 11 screens

CBS Counter · Counter
No. Screen What it does, and what it still lacks Opens at State
CN-01 Counter sale Counter sale — discount, khata credit and tender modes, over the till API /counter Live
CN-02 Prescription queue Prescription queue across Medico, paper and photograph sources /counter/prescription Live
CN-08 Day book Day book, including the held-bill sync queue /counter/daybook Live
CN-11 Khata — credit accounts The shop's credit book — customer accounts, credit limit, what is owed and what was collected. A limit of zero, the default, means cash only; a walk-in with no account must pay in full /counter/khata Live
CBS Counter · Stock
No. Screen What it does, and what it still lacks Opens at State
CN-03 Item master Item master with composition provenance and per-item GST /counter/items Live
CN-04 Receive stock Receive stock, distributor invoice reconciled /counter/receive Live
CN-05 Purchase Reorder by days of cover rather than by shortfall. The shop's own purchasing, separate from DK-08 since the ledgers are separate /counter/purchase Live
CN-06 Expiry board Expiry board and dead stock /counter/expiry Live
CN-09 Stock take Stock take and variance /counter/stocktake Live
CBS Counter · Law and business
No. Screen What it does, and what it still lacks Opens at State
CN-07 Statutory registers H1 and X registers with the printed PDF. Whether Karnataka requires a bound register is still to be settled with a working shop /counter/registers Live
CN-10 Owner metrics Owner metrics — valuation, reorder, dead stock, takings /counter/metrics Live
What this table is not.

It counts screens. It does not count the platform beneath them — the mounted API routes, the encryption core, the compliance plugins, the audit trail, the public site and continuous integration are listed separately on the build register, precisely so that counting screens is not mistaken for counting the product.

3 · Recent additions

Public network features, offline-first PHC support, and India's national integrations — added since the previous revision.

None of these add to the screen count above — they are new public pages, new backend capability, and one live demo, not new entries in Dock, Medico, Care or Counter's own navigation rail. Named here because they are real and working today, with exactly what is honestly still a placeholder said plainly rather than implied.

The Doctor Credentials Wall

A hospital's physical lobby signboard, digitised — name, recognised qualifications, registration number, specialty. No rating, no testimonial, no free-text field a doctor could turn into an advertisement. A credential appears only once a facility administrator has verified it against the practitioner's real documents.

Empanelment & the network directory

cbshealth.in's own public listing of empanelled facilities and their doctors, distinct from a hospital's own subdomain wall. A facility applies; only a platform-side supervisor can approve it — never the facility's own administrator.

Hospital-branded subdomains

A hospital reachable at its own domain, resolved automatically to the right facility, showing its own credentials wall with nothing for a visitor to know or type.

Offline-first PHC booking

A front desk with no live connection can take a booking, queue it locally, and sync the moment a connection appears. Two devices queuing the same slot while both offline resolve honestly — one accepted, one a real conflict with a real suggested alternative, never a silent overwrite.

Free-drug scheme flagging

A formulary entry marked free under a named state or national scheme shows inline in the prescribing picker, and is filterable on its own — what costs the patient nothing, in the same glance as the drug name.

Voice prompts, low-literacy first

Pre-recorded audio, not a live cloud call that fails silently with no signal. Falls back to a default language when a specific one has not been recorded yet.

India’s national integrations, scoped honestly

Integration What is real today
ABDM (Ayushman Bharat) Real CBS-side patient data builds the health-record bundle; the external gateway call itself is a documented mock pending sandbox access.
e-Sanjeevani A real, tracked, de-identified referral record — an age band and gender reach the external system, never a name or record number.
HMIS monthly export Real aggregation against CBS's own records; the government portal's exact field format is not yet verified against a live reference.
What "real" means on this page.

A feature is only called live here once it has been run against a real database with a real request, not merely written. Where an external government system is involved and no sandbox credential exists yet, that is said plainly rather than implied by silence.

4 · Testing protocol

For your own staff, in a browser. No command line.

Work through the phases in order. Each scenario says what to do and what should happen. If what you see differs from what is described — even slightly, even where it looks harmless — that is a finding and we want it. You do not need to understand how CBS works to test it well. You need to be stubborn about numbers that disagree with each other.

Never type a real patient's details into a test system.

Everything in a test instance is invented, and it is not covered by the protections a live deployment has. A real name, telephone number or address typed into it creates a data-protection problem rather than a test result. Use the demonstration patients you were given.

T0 · The five-minute health check

Who should do it: Whoever is setting the session up

Everything after this is unreliable if the instance is misconfigured, and a day spent testing a misconfigured instance produces findings that are all environment and no product.

No. Do this You should see
T0.1 Open the address you were given. The public CBS site. Not an error, not a blank page.
T0.2 Add /dock/login to it. A sign-in page that says CBS Dock.
T0.3 Look for a coloured 'demo mode' banner. There should be none. If there is, sign-in is switched off and no permission test below means anything — stop and report it.
T0.4 Sign in with the account you were given. You land on a working screen, not back at sign-in.
T0.5 Check the address is not one ending .run.app. If it is, ask for a different one. That address refuses everything by design and every screen will look missing.

T1 · The numbers must agree with each other

Who should do it: A ward sister, or whoever counts beds today

This is the highest-value testing in the whole protocol. Two screens disagreeing about how many patients are in a ward is the most serious class of defect CBS can have, and it is invisible to any automated test that checks one screen at a time.

No. Do this You should see
T1.1 Open the ward board. Write down the occupied count for one ward. A number you can read without interpretation.
T1.2 Open the in-patient census for the same ward. The same number. A difference of even one is a finding, and an urgent one.
T1.3 Admit a test patient to that ward. Return to both screens. Both go up by exactly one.
T1.4 Discharge that patient. Return to both screens. Both return to what you wrote down in T1.1, and 'discharged today' goes up by one.
T1.5 Transfer a patient between two wards. One ward goes down by one, the other up by one, and the hospital total does not move.
T1.6 Repeat T1.3 with two people working at once, on two computers. Still exactly one. Two clerks admitting at the same moment must not produce two beds or none.

T2 · A patient's whole journey, once, end to end

Who should do it: A front-desk clerk and a doctor, working together

Each screen can pass on its own and the journey between them still break. This is the only phase that tests the joins, and the joins are where a real clinic gets stuck.

No. Do this You should see
T2.1 Register a new patient at the front desk. A hospital number is issued. Registering the same person twice is noticed and flagged.
T2.2 Book them an appointment. The slot disappears from the free list. Booking the same slot twice is refused, not quietly accepted.
T2.3 As the doctor, open the consultation and prescribe. The drug is checked against what they already take, and an unknown code is refused rather than stored.
T2.4 Print the prescription. It carries the establishment's letterhead and the prescriber's registration number.
T2.5 Admit them, record a ward round, write the discharge and print the summary. Each step finds the previous one. The summary prints on the letterhead in the language chosen.
T2.6 Raise the bill, take a part-payment, then the balance. The outstanding figure is right at each step and the bill locks when settled.
T2.7 Find the same patient again from the patient index a day later. Everything above is on their record, in order.

T3 · Try to see what you should not

Who should do it: Two testers with different roles, deliberately misbehaving

A permission that is merely a hidden menu item is not a permission. This phase attacks the guarantee rather than the interface, and a single finding here outranks every other finding in this document.

No. Do this You should see
T3.1 Signed in at one establishment, edit the address bar to name another's. Refused. Any patient data returned here stops the test session and is reported privately, never in a tracker.
T3.2 Copy a patient's internal identifier from one establishment and request it from another. Refused, the same way.
T3.3 As a nurse, open a billing screen. As a billing clerk, open a clinical one. Refused in both directions, by the server and not merely by a missing link.
T3.4 Sign out, then press the browser's Back button. You are not signed in again. You are sent to sign-in.
T3.5 Read a patient record, then ask an administrator to show the audit trail. Your read is on it, with your name and the time. A way of reading a record that leaves no trace is a finding.
T3.6 Have an administrator switch your access off while you are signed in. Your next action is refused.

T4 · The shop, and the hospital store beside it

Who should do it: The person who actually runs the counter

Counter is the newest module and the one with statutory paperwork attached. It is also the one where stock leaving twice, or not at all, costs real money.

No. Do this You should see
T4.1 Ring up a cash sale of two items, one with a discount. The total, the tax and the discount are right, and the stock falls by exactly what was sold.
T4.2 Put a sale on a customer's khata, then collect against it later. The balance rises and falls correctly. A customer with no credit limit cannot be given credit.
T4.3 Dispense against a prescription raised in Medico. It arrives in the queue and closes when dispensed. It cannot be dispensed twice.
T4.4 Receive a distributor's delivery against its invoice. Every line lands or none does. A part-posted delivery is a finding.
T4.5 Print the Schedule H1 and Schedule X registers. They print, and what they show matches what was actually dispensed.
T4.6 Close the day book and compare it with the cash in the drawer. They agree, and what went on credit is shown separately from what was taken in cash.
T4.7 Issue a consumable from the hospital store to a ward, then check the shop's stock. The shop's figures have not moved. The two ledgers are separate and must stay so.

T5 · The patient's own door

Who should do it: Someone who is not clinical, and preferably not young

Care is used by patients and by the family member looking after them, on their own phone, without training. Anything that needs explaining is a defect even when it works.

No. Do this You should see
T5.1 Sign in as a patient with a one-time code. It arrives, it works once, and an old code does not.
T5.2 Look at your own record, appointments and medicines. Only your own. Never anybody else's, by any route.
T5.3 Ask the shop for a refill and follow it to collection. The status is truthful at each step, and nothing is dispensed by the request itself.
T5.4 As a family member, open the record of the person you care for. Permitted only where that delegation was actually granted, and withdrawable.
T5.5 Press SOS. It reaches somebody, and the fact that it did is recorded.

T6 · Language, printing and the things people actually complain about

Who should do it: Anybody

A hospital abandons software over a printed page that is wrong, far more often than over a failure in the clinical logic.

No. Do this You should see
T6.1 Change the language and move between screens. It stays changed. Nothing falls back to English half-way.
T6.2 Print a discharge summary in a non-English language. The letters are letters. Empty boxes mean a missing font, and CBS should refuse to print rather than print boxes.
T6.3 Print a bill, a consent form and a register. Each carries the establishment's own name, address and registration number — not CBS's.
T6.4 Use CBS on a phone, on the smallest screen you have. Every screen is usable. Nothing is cut off and nothing needs sideways scrolling to complete a task.
T6.5 Lose the network half-way through writing a note. You are told. Nothing is silently discarded and nothing is silently duplicated when the network returns.
Reporting what you find

How to write it down so it can be acted on.

Report by screen number.

Report a bug by its screen number and nothing else — DK-05, MD-09, CN-11. The number is printed on every screen, it is permanent, and it never changes when a screen is renamed or moved. A report that describes 'the billing page' costs somebody a search; a report that says DK-05 does not.

Severity What it means What to do
S1 One establishment can see another's patients; sign-in can be got around; patient information is exposed; data is lost. Report privately to the named contact, not in a tracker. A written description of how to read another hospital's patients is itself the incident.
S2 Clinical information is wrong; a normal action produces an error page; something happened and the audit trail does not show it. Report the same day, with the screen number and what you did.
S3 A task cannot be completed, or completes wrongly but there is a way round it. Report with the workaround you used.
S4 Wording, layout, spacing, a wrong label. Collect them and send them together.

A module passes when every scenario for it returns its expected result or the deviation is filed and triaged, no S1 or S2 is open against it, and the automated suites are green on the same commit. Record the date, the tester and the version tested — a pass is a pass on a stated version, not in general.

Send this page to your lawyer, and your ward sister.

They are the two readers it was written for. We would rather answer a hard question before a deployment than explain an answer after one.