One clinical workspace for patient records, vitals, documents, appointments, and teams.
MediFlow helps clinics and healthcare organizations manage patient records, vitals, documents, appointments, and daily team follow-up in one calm clinical operations workspace.
Summarize the day, review operational signals, or draft text. You stay in control; every action is yours to approve.
Summarize todayAppointments, no-shows, and what needs attention next.
Overdue vitalsPatients whose vitals are overdue for review.
Draft a handoffA concise handoff summary for the next shift.
Open follow-upsA scan of tasks that still need attention.
Summarize today's appointments and flag anything that needs attention.
Checking workspace contextQueued
Prompt safety checkQueued
Reading workflow snapshotQueued
Kesharon ClinicDaily brief
Ask Copilot...
Workflow guidance only. Review drafts before sharing them with the care team.
Current workspace
Clinical workflows already in place.
MediFlow currently focuses on the workflows a clinic needs every day: patient lookup, profile updates, medical documents, vitals tracking, appointments, quick notes, and role-specific dashboard views.
Designed around organization roles, server-authoritative mutation paths, structured errors, and audit logging foundations for critical workflow changes.
Draft notes autosave every 5 seconds, then finalize into the patient history timeline when ready.
Quick noteAutosaved 5s ago
Follow-up after labs. Call patient before changing medication.
Draft savedReady for reviewAdded to history
Autosave draft · finalize to history
06 · Dashboards
Role-specific dashboard views
Dashboard screens exist for clinicians, staff, owners/admins, billing users, readonly users, and founder/internal operations.
ClinicianStaffBilling
Today12 patientsFollow-ups5 dueUnread docs3 files
Read-only roleSummary view only
Clinician summary · pending tasks · admin views
— AI assistance
Workflow help, gated and server-side.
MediFlow's AI work is intentionally narrow: start with operational questions, keep execution server-side, gate usage by role and feature flag, and block prompts that appear to contain patient identifiers. Clinical summary generation and grounded research remain roadmap items until their production endpoints and compliance controls are verified.
Workflow-focused
Operations support, not clinical decision-making.
Server-side execution
The copilot runs behind a controlled workflow boundary.
Feature flagged
Usage requires the ai_enabled rollout flag.
Prompt safety
Direct patient identifiers are blocked before execution.
read
Feature-flagged access
AI assistance requires the organization-level ai_enabled flag before the copilot runs.
feature_flag.ai_enabledControlled rollout
read
Prompt safety checks
Prompts that appear to contain patient names, MRNs, emails, phone numbers, or identifiers are rejected.
prompt_safety.checkIdentifier guard
phi-read
Dashboard summary
The current implemented tool surface is narrow and focused on clinician dashboard workflow context.
MediFlow is not presented as compliance-certified. The current foundation is being shaped around server-side access, organization scope, audit-safe metadata, and rollout gates while legal, vendor, operational, and evidence reviews continue.
01
Current foundation
Organization isolation
Organization workspaces are the tenancy boundary, with role checks resolved against membership.
02
Server boundary
Access control
PHI, membership, billing, and administrative mutations are designed to be authorized outside the client UI.
03
Evidence trail
Audit-safe metadata
Critical mutation classes write structured events while avoiding raw PHI in audit metadata.
04
Launch control
Gated rollout
AI and document workflows stay feature-flagged, quota-aware, and human-reviewed as readiness evidence matures.
RBAC matrix
Six roles, scoped to the work.See full matrix ↓Hide matrix ↑
Full Scoped None
Capability
Owner
Admin
Clinician
Staff
Billing
Read-only
Manage org & billing
Invite & manage seats
Manage feature flags
Create / update patients
Read patient PHI
Schedule appointments
Use operations copilot
View audit foundations
— Roadmap
What is implemented, what is next.
MediFlow has a substantial alpha spine. Pilot claims stay separate from production, compliance, commercial, and enterprise claims until the evidence is verified.
Track 1
Alpha workspace foundation
Auth, session restore, active org context, route gates, patient records, appointments, documents, notes, vitals, and dashboard foundations.
Alpha
Track 2
Governance boundary
Pilot role gates, server-side mutation controls, feature flags, PHI-safe audit metadata direction, and organization-scoped access checks.
Alpha
Track 3
Operations Copilot boundary
Manual workflow assistance with server-side execution, approved tools, feature flags, PHI minimization, and human review posture.
Alpha
04Track 4
Pilot readiness gaps
Organization creation, real team management, missing-item facts, incomplete-profile facts, feedback, release notes, and known limitations.
Next
05Track 5
AI pilot hardening
Quota, cache, AI audit events, copy/export controls, disabled state, quota exceeded state, provider-error state, and integration tests.
Next
06Track 6
Verification and launch decision
Unit, integration, E2E, empty/error/unauthorized checks, manual pilot path evidence, and final readiness review.
Next
07Track 7
Commercial and legal evidence
Commercial launch terms, contracts, DPA/BAA/DPIA evidence, data-subject operations, retention policy, and production claim review.
Later
08Track 8
Broader platform capabilities
Enterprise identity, network controls, external audit integrations, patient portal, native apps, EHR integrations, full i18n/PWA, and clinical AI after separate review.
Later
— Later
Held outside pilot claims until scope, verification, and operational ownership are explicit.
01
Commercial launch terms
02
Patient portal
03
Native Android and iOS
04
EHR integrations
05
Clinical AI after review
— FAQ
Procurement-grade answers.
Current-state answers separated from launch, legal, and roadmap claims.
MediFlow is in active development. The app already contains core clinical workspace features, but production clinical use depends on deployment verification, compliance review, pilot rollout readiness, and operational readiness.
The application is designed toward healthcare compliance controls, including organization isolation, role-based access, server-side PHI mutation paths, and audit logging foundations. Do not treat this landing page as a compliance certification. HIPAA, GDPR, and BAA readiness require separate legal, vendor, operational, and evidence reviews.
Teams can manage patient demographics, medical documents, vitals, appointments, medical history entries, and quick notes from one organization-scoped workspace.
MediFlow includes an early workflow-focused Operations Copilot. It is server-side, feature-flagged, role-gated, and designed for operational questions rather than direct clinical decision-making. Clinical summaries and grounded research should remain roadmap language unless production endpoints are verified.
Yes. MediFlow is free during open beta while early clinical teams evaluate the workspace and share feedback. No payment is required for beta access.
Multiple-language support is planned, but completed locale content needs product and clinical review before it is marketed as live.
MediFlow is a web application. The architecture keeps future mobile clients possible, but native iOS and Android apps should be described as roadmap items.
Appwrite is part of the current hosting path. Do not treat this page as a claim of a specific production hosting region, residency policy, or backup residency guarantee unless deployment settings and contracts confirm it.
Open beta access
Start with one workflow your clinic already runs every day.
Free during open beta. Open MediFlow to try patient records, vitals, documents, quick notes, and scheduling yourself. For a guided pilot, send the workflow, roles, volume, and review needs your team wants to validate first.