For hospitals and clinics in India

The modular hospital platform for Indian healthcare.

Patients, appointments, EMR, pharmacy, lab, and billing in one system. Turn on only the modules each hospital needs.

Onboarding is guided by our team. No credit card, no self-serve setup.

Isolated per tenant

PostgreSQL row-level security keeps one hospital's data unreachable from another. Tested on every module, not assumed.

India-resident by design

Built to run on India-resident cloud infrastructure, with health data kept in-region.

Auditable by design

An append-only audit trail records every meaningful action and is retained, tamper-evident, and queryable.

Encryption and least privilege

TLS in transit and AES-256 at rest are the platform's encryption standard, on a least-privilege architecture with PII masked outside production.

portal.hms · admin · modules
Modules · Bright Care Clinic
  • Patient ManagementEnabled
  • AppointmentsEnabled
  • PharmacyEnabled
  • LaboratoryEnabled
  • Radiology & PACSOff
  • Operation TheaterOff

The model

Buy only what you need. Turn on the rest later.

Each module is installable and billable on its own. A single-doctor clinic can run just patients, appointments, and billing, while a hospital chain runs the full set, all from the same platform.

  • Modules are entitlements per hospital, not code forks.
  • Entitlement and user access are separate levers.
  • Add a module the day the hospital is ready for it.

Modules

Everything a clinic needs on day one.

The seven core modules cover the full outpatient journey, from the front desk to the pharmacy counter. They are what we have built; the wider catalog of twenty-five modules and two add-ons is planned scope from our product plan.

The clinic-core and inpatient (IPD) modules are built and in verification ahead of our first release. Everything marked Planned is scheduled scope from our product plan, not something you can use today.

One tenant can never see another's data.

Isolation is enforced at the database layer with PostgreSQL row-level security, and it is tested on every module, not assumed. Every meaningful action lands in an append-only audit trail.

  • Row-level isolation per tenant
  • Append-only, tamper-evident audit
  • AES-256 at rest, TLS 1.2+ in transit
  • Hosted in India, kept in-region
portal.hms · admin · audit log
EventActorTime
appointment.bookreception@brightcare12:04:19
patient.viewdr.mehta@brightcare12:03:56
permission.grantadmin@brightcare11:58:02
auth.logindr.rao@brightcare11:41:30
Reception, nursing and pharmacy staff at work in different parts of a hospital.

Every role sees exactly its own work.

Permissions are checked on the server for every action. Staff see the modules, screens, and data their role allows, and nothing else.

Receptionist

Register patients, book and check in appointments, manage the front-desk queue.

Doctor

Open an encounter, record vitals and SOAP notes with ICD-10 coding, and issue prescriptions and lab orders.

Pharmacist

Dispense against prescriptions and manage stock by batch and expiry, first-expiry-first-out.

Lab Technician

Work the order-to-result worklist, record collection, and enter results against reference ranges.

Accountant

Raise the visit invoice, record part payments, and see the day's collections in the reports.

Organization Admin

Manage users, roles, branches, and branding across the organization, with full visibility inside the tenant.

Branch Admin

Run a single branch, its users and day-to-day operations, within the organization's rules.

Included with every plan

The platform core, in every hospital.

These are never a line item. Whatever modules a hospital turns on, they sit on the same secure, multi-tenant foundation.

Tenant & branch isolation

Every hospital's data is isolated at the database layer with PostgreSQL row-level security. Unlimited branches per tenant.

Role-based access control

Fine-grained permissions per role, per-user overrides, and time-bound grants. Explicit deny always wins.

Module entitlements

Turn modules on per hospital as entitlements, not forks. Entitlement and user access are separate levers.

Immutable audit trail

Every security-relevant action is written to an append-only, tamper-evident log that is never physically deleted.

Notifications

One provider abstraction for transactional email and SMS, with idempotency on every send. Email is live; SMS is pending DLT template registration. WhatsApp is a planned channel.

Financial infrastructure

Invoice, payment, tax, and receipt primitives live in one place; every billing module builds on them.

See it running with your own workflows.

Book a walkthrough and we will map your clinic or hospital onto the platform, module by module.