The problem this solves
For many clinics and hospitals, the front desk telephone is still the main booking channel. Lines are busy at peak hours, schedules are kept in a mix of software and registers, no-shows leave gaps that could have gone to waiting patients, and follow-up depends on whether the patient remembers to call. Patients, meanwhile, juggle paper reports and prescriptions across providers.
This blueprint shows how Twara Technologies would design a patient appointment and engagement platform that gives patients self-service access, gives staff a calmer and more predictable day, and treats health information with the care it requires. It is a reference design. A typical implementation is shaped by the facility’s size, specialities, existing hospital information system (HIS) and the regulatory position confirmed by its own advisers.
Architecture
[Patient web] [Patient app] [Messaging channels]
\ | /
[API gateway + patient identity / OTP / auth]
|
[Booking service] [Patient profile] [Teleconsult service] [Notification service]
| | | |
[Schedules + slot rules] | [Video provider] [SMS / email / push]
|
[Consent & privacy service] <--- enforced on every read / share
|
[Integration layer: FHIR APIs, HL7 interfaces, adapters]
/ | \ \
[HIS / EMR] [Lab] [Pharmacy] [Payment gateway]
|
[Audit log] [Analytics store (de-identified where possible)]
- Patients authenticate with a mobile number OTP or stronger methods, and can manage dependants’ profiles.
- The booking service owns availability rules and reservations; the HIS remains the clinical system of record.
- Teleconsultation runs through a secure video service embedded in the platform, with the consultation note and prescription saved back to the record.
- The consent service sits between data and every consumer of it, so permissions are checked consistently rather than module by module.
Key design decisions
System of record. Duplicating the hospital’s patient master and schedules creates reconciliation problems. The blueprint keeps the HIS as the master for clinical data and, where the HIS can expose schedules reliably, for availability too. Where it cannot, the platform manages schedules and pushes confirmed appointments into the HIS.
Interoperability standard. HL7 FHIR is a standard for exchanging health-care data, with Release 5 (v5.0.0) shown as the current published version on HL7’s site. Resources such as Patient, Practitioner, Schedule, Slot and Appointment map naturally onto this platform. Many deployed systems still use older FHIR releases or HL7 v2 messages, so the integration layer supports adapters rather than assuming one version everywhere.
ABDM readiness. The Government of India launched the Ayushman Bharat Digital Mission in September 2021. As PIB’s July 2026 backgrounder describes, it includes the Ayushman Bharat Health Account (ABHA) identifier, a Healthcare Professionals Registry and a Health Facility Registry, with health records exchanged through the patient’s revocable, time-bound consent. The blueprint keeps patient identity and consent models compatible with ABHA linking so a facility can integrate with the ABDM ecosystem when it chooses to.
Video provider. Managed video APIs (for example Twilio, Vonage or Agora) speed up delivery; self-hosted WebRTC stacks such as Jitsi give more control over data flows but require operations effort. The choice is weighed against expected volumes, data-location requirements and support capacity.
Native apps or progressive web app. A progressive web app avoids app-store installs for occasional patients; native apps suit facilities with frequent repeat patients and richer features such as reliable push notifications. Many implementations start with the web experience and add apps later.
Security and compliance
Health information is among the most sensitive personal data a platform can hold. India’s Digital Personal Data Protection Act, 2023 requires reasonable security safeguards (section 8(5)), notice of breaches to the Data Protection Board and affected individuals (section 8(6)), and verifiable consent of a parent or lawful guardian before processing a child’s data (section 9(1)). Under the DPDP Rules, 2025, rule 6 sets minimum safeguards such as encryption, access control, access logging and backups, and rule 7 requires a detailed report to the Board within seventy-two hours of becoming aware of a breach. The platform’s family-profile, consent and audit features are designed around these obligations.
For teleconsultation, the Telemedicine Practice Guidelines dated 25 March 2020, prepared with NITI Aayog and issued as Appendix 5 to the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002, describe how practitioners should identify patients, record explicit consent when required, and maintain records of consultations. The teleconsultation module captures identity checks, consent and consultation records to support practitioners in following them. Facilities should confirm the current regulatory position with their advisers and the National Medical Commission.
Technical controls include encryption in transit and at rest, role-based access for clinicians and staff, break-glass access with review, de-identified analytics, and complete audit trails of who viewed or shared which records.
Phased rollout
- Discovery. Map patient journeys, clinic workflows, scheduling rules, HIS interfaces, communication channels and compliance requirements.
- Booking and reminders. Launch online booking, rescheduling, payments and reminders for a pilot department or clinic, integrated with the HIS.
- Front desk and doctor tools. Add queue management, check-in and clinician schedule views, refined with staff feedback.
- Teleconsultation and records. Introduce video consultations, digital prescriptions and report access, with consent flows reviewed by the facility’s clinical and legal teams.
- Engagement and interoperability. Follow-up programmes, multilingual content, ABDM integration and analytics, under ongoing support and maintenance.
Risks and how the design handles them
| Risk | How the design responds |
|---|---|
| Double bookings from out-of-sync schedules | Single owner for availability, slot reservation with expiry and reconciliation with the HIS |
| Unauthorised access to health information | Role-based access, consent checks on every read, audit trails and anomaly alerts |
| Poor video quality in low-bandwidth areas | Adaptive video, audio-only fallback and chat-based consultations where clinically appropriate |
| Low adoption among older patients | Simple flows, multiple languages, family profiles and continued phone booking via front-desk console |
| Message fatigue or unwanted contact | Preference centre, consent-based messaging and frequency limits |
| Changing health-data regulations | Consent and retention held as configuration, with documented review points |