The modular hospital platform for Indian healthcare.
Patients, appointments, EMR, pharmacy, lab, and billing in one system. Turn on only the modules each hospital needs.
Onboarding is guided by our team. No credit card, no self-serve setup.
Isolated per tenant
PostgreSQL row-level security keeps one hospital's data unreachable from another. Tested on every module, not assumed.
India-resident by design
Built to run on India-resident cloud infrastructure, with health data kept in-region.
Auditable by design
An append-only audit trail records every meaningful action and is retained, tamper-evident, and queryable.
Encryption and least privilege
TLS in transit and AES-256 at rest are the platform's encryption standard, on a least-privilege architecture with PII masked outside production.
- Patient ManagementEnabled
- AppointmentsEnabled
- PharmacyEnabled
- LaboratoryEnabled
- Radiology & PACSOff
- Operation TheaterOff
The model
Buy only what you need. Turn on the rest later.
Each module is installable and billable on its own. A single-doctor clinic can run just patients, appointments, and billing, while a hospital chain runs the full set, all from the same platform.
- Modules are entitlements per hospital, not code forks.
- Entitlement and user access are separate levers.
- Add a module the day the hospital is ready for it.
Modules
Everything a clinic needs on day one.
The seven core modules cover the full outpatient journey, from the front desk to the pharmacy counter. They are what we have built; the wider catalog of twenty-five modules and two add-ons is planned scope from our product plan.
The clinic-core and inpatient (IPD) modules are built and in verification ahead of our first release. Everything marked Planned is scheduled scope from our product plan, not something you can use today.
The outpatient journey, end to end
Register a patient, book the visit, run the consult, dispense, test, and bill, without leaving the platform or re-keying a name.
Patient Management
BuiltOne record per patient, from first visit onward.
Learn moreAppointment Management
BuiltBooking against a doctor's slots, without double-booking.
Learn moreOPD & Check-in
BuiltFront desk to consult, with a live token queue.
Learn moreClinical Workflow (EMR)
BuiltConsultation notes, ICD-10 coding, and prescriptions.
Learn morePharmacy Management
BuiltDispensing against prescriptions, on batch-aware stock.
Learn moreLaboratory Management
BuiltOrder to result, tracked through the worklist.
Learn moreBilling & Payments
BuiltOne invoice across consultation, pharmacy, and lab.
Learn moreSee all 25 modules
Nursing, radiology, IPD, OT, insurance, HR, and more, plus telemedicine and ABDM, each marked with what is built and what is planned.
Explore the catalogOne tenant can never see another's data.
Isolation is enforced at the database layer with PostgreSQL row-level security, and it is tested on every module, not assumed. Every meaningful action lands in an append-only audit trail.
- Row-level isolation per tenant
- Append-only, tamper-evident audit
- AES-256 at rest, TLS 1.2+ in transit
- Hosted in India, kept in-region
| Event | Actor | Time |
|---|---|---|
| appointment.book | reception@brightcare | 12:04:19 |
| patient.view | dr.mehta@brightcare | 12:03:56 |
| permission.grant | admin@brightcare | 11:58:02 |
| auth.login | dr.rao@brightcare | 11:41:30 |

Every role sees exactly its own work.
Permissions are checked on the server for every action. Staff see the modules, screens, and data their role allows, and nothing else.
Included with every plan
The platform core, in every hospital.
These are never a line item. Whatever modules a hospital turns on, they sit on the same secure, multi-tenant foundation.
Tenant & branch isolation
Every hospital's data is isolated at the database layer with PostgreSQL row-level security. Unlimited branches per tenant.
Role-based access control
Fine-grained permissions per role, per-user overrides, and time-bound grants. Explicit deny always wins.
Module entitlements
Turn modules on per hospital as entitlements, not forks. Entitlement and user access are separate levers.
Immutable audit trail
Every security-relevant action is written to an append-only, tamper-evident log that is never physically deleted.
Notifications
One provider abstraction for transactional email and SMS, with idempotency on every send. Email is live; SMS is pending DLT template registration. WhatsApp is a planned channel.
Financial infrastructure
Invoice, payment, tax, and receipt primitives live in one place; every billing module builds on them.
See it running with your own workflows.
Book a walkthrough and we will map your clinic or hospital onto the platform, module by module.