Features · the complete map

Everything Northstar does.

The honest, exhaustive list — every capability shipping today, every one in motion, and every one explicitly on the way. Grouped by what a pediatrician does in a day.

Built shipping in main · tested · in production rails In progress partially shipped · usable but evolving Coming on the roadmap · prioritized AI AI-grounded surface · audited
Capability areas
01

Charting

The chart is FHIR-native end to end. Compositions, Conditions, AllergyIntolerances, MedicationRequests, Observations — every field is FHIR R4, every write is auditable, every read knows whose chart it's on.

Patient chart shell core
Briefing · Timeline · Notes · Problems · Meds · Allergies · Immunizations · Vitals · Growth · Screenings · CarePlans · Family · Inbox — all surfaces in one navigation, keyboard-first.
Built
Briefing surface core
Per-patient single-screen briefing: identity, active problems, meds, allergies, recent vitals, upcoming visit, vaccine status, sibling badges, Spruce thread, AI bili card for newborns.
Built
Timeline core
Visit notes, imported outside notes, immunizations, labs, and Spruce threads as one chronological feed. Each event clickable. Paragraph boundaries preserved in clinical notes.
Built
Problem list A7
Free-text problem entry with active/resolved state, reactivation via read-then-merge PUT. SNOMED + ICD-10 picker with peds-tuned top-by-age coming.
In progress
Medications core
MedicationRequest with status / dose / route / frequency / duration / refills / pharmacy / authored-on. Edit and Discontinue actions. RxNorm-aware refill dedupe.
Built
Allergies & intolerances core
AllergyIntolerance with substance, severity, reaction. Subject-preserving updates. Allergy contraindication check on prescribe.
Built
Chart density gate A10
Hides adult-only metrics (lipid, BP routine, glucose, alcohol screen, sexual hx, HEADSSS, depression routine, pap, mammogram, dexa, colon screen) until peds-appropriate age — 11 metrics, AAP / USPSTF / NHLBI cited.
Built
"Show all" override A10
Per-user toggle to surface every metric. Persists across sessions via FHIR Basic user settings.
Built
Composition note rendering core / K1
Tiptap-styled note bodies preserve paragraph structure. HTML allowlist sanitization (K13). Sign-flow uses status-only patches that read-then-merge body.
Built
02

Scribe & encounters

The visit itself. Tiptap-grounded editor with AI ghost-text, AssemblyAI ambient scribe, peds-tuned SOAP drafting, and a sibling-shift detector that catches "let's talk about Mia now."

Encounter editor core
Tiptap-based, keyboard-first. Inline templates, ghost-text suggestions, AI Cmd-K. Paragraph rendering preserved on save and sign.
Built
AI ghost-text completion scribe
AI · scribe surface Source-grounded SOAP drafting. Pediatric prompts. Parser rejects fabricated history not in transcript.
Built
Ambient scribe (AssemblyAI) scribe
Ambient or push-to-talk transcription. Patient-controlled hold + pause. Transcript becomes source for SOAP draft.
Built
Multi-patient sibling routing A3 · multi-patient-routing
AI · refuses silent routing Detects "switching to ", "let's talk about ", "moving on to " mid-utterance. Banner asks clinician to confirm before splitting the note.
Built
Template picker G1
Practice templates + per-clinician favorites + cross-practice imports. Favorites sorted first. Star toggle on Templates page.
Built
Encounter ↔ template wiring core
"From template ▾" dropdown loads scaffolded SOAP into the editor on encounter open.
Built
Cmd-K plan insertion A9
From any Cmd-K result (e.g. dose card), drop the structured text into the Plan section via window event — no copy-paste.
Built
Sign + finalize C1 · K1
One-button sign. Read-then-merge body preservation on POST. Triggers AVS draft flow downstream.
Built
MA / nurse rooming workflow A1
Appointment status transitions (booked → checked-in → roomed → ready-for-provider → in-progress → done), status pill on calendar + briefing, "who did what" stamp, MA-scoped quick actions.
Coming
03

Vitals

Keyboard-first quick entry. Live preview of derived metrics as you type. Batched as a single FHIR transaction.

Quick-entry form A2
Height / length, weight, BP, HR, RR, temp, SpO2 — keyboard tabs straight through.
Built
Head circumference (under 36mo) A2
Age-gated field; only renders for patients under 36 months.
Built
Live BMI / WFL / trajectory preview A2
As you enter weight + height, BMI percentile / WHO weight-for-length / growth trajectory band crossing are computed and previewed before save.
Built
Batch Observation write A2
One FHIR transaction — all vitals or none. Encounter-linked when one is active.
Built
Recent vitals panel A2
Last few measurements on the same page for instant comparison.
Built
04

Growth charts

Standard percentile curves done right, plus the interpretation layer that turns the chart from a record into clinical guidance. CDC, WHO, Fenton 2013, Olsen 2010 — each cited.

CDC + WHO LMS percentile engine core
Weight, length/height, BMI, head circumference. Age- and sex-stratified L/M/S tables.
Built
BMI percentile + obesity classification D2
CDC 2022 categories: underweight / healthy / overweight / obesity / severe obesity. Latest-BMI category chip on chart.
Built
Weight-for-length under 2 D3
WHO WFL chart tab + same-day infant weight/length derivation.
Built
Trajectory anomaly detection D6
Flags ≥ 2 major percentile-band crossings across consecutive measurements. Surfaced as growth-tab alert + briefing badge.
Built
Predicted adult height D5
Mid-parental method with 95% confidence bracket. Badge on growth tab.
Built
Preterm growth curves D10
Fenton 2013 (PMID 23601190) + Olsen 2010 (PMID 20100760) anchor-point LMS tables. pickPretermCurve() auto-routes Fenton / Olsen / WHO / WHO-corrected / CDC based on GA, PMA, chronological age.
Built
AI growth narrative D1 · growth-narrative
AI · refuses unsupported facts Deterministic readout always renders; clinician-triggered AI draft synthesizes percentile + trajectory + recent-visit context into a paragraph. Parser rejects diagnostic / workup / referral / treatment recommendations.
In progress
Head circumference (over 36mo) D4
Plot + auto-flag macrocephaly / microcephaly when ≥ 2 SD from mean.
Coming
Endocrine red-flag pack D8
AI · planned Short stature, tall stature, dropping percentiles, accelerated growth, weight-for-height divergence — inline "consider workup" hints.
Coming
Sibling overlay D7
Plot index patient + siblings on the same chart.
Coming
Per-patient preterm correction window D9
Adjust age across all peds tooling, not just growth.
Coming
Growth chart PDF artifact
Printable chart for parents and schools.
Built
05

Vaccines & immunizations

Pediatric immunization is half the job. The vaccine engine is encoded data — schedule, intervals, catch-up — with a Cmd-K-fast search, lot tracking, and atomic FHIR transactions.

CDC + AAP 2026 schedule engine core
evaluateSchedule(birthDate, immunizations, today) returns per-dose status: due / coming-due / overdue / complete / not-yet. Influenza handled as annual recurrence. Catch-up windows respected.
Built
Per-patient immunization tab core
Schedule with status badges, source labels for imported records, and one-click administer.
Built
Vaccine inventory + lot tracking core
Per-lot FHIR Basic resources with NDC, expiration, on-hand count. Inventory management page.
Built
Atomic vaccine administration K5
FHIR transaction with If-Match version check. Decrements lot + writes Immunization + no half-finished state.
Built
VFC eligibility tracking core
Per-patient VFC status; per-dose VFC eligibility recorded on Immunization.
Built
Today's vaccine diff C1
Helper used by AVS: administered today vs prior, currently due, upcoming within 12 months. Source for the AVS prompt.
Built
Immunization record PDF artifact
Letterhead PDF for camp / school / sports submission.
Built
Overdue alerts on practice home core
Today's appointments scanned; rows with overdue vaccines surface in the Needs You panel.
Built
06

Pediatric tools

Bili and dosing — the two safety-critical calculators every peds practice runs daily. Both source-cited, both clinician-triggered, both audit-captured.

Newborn bili calculator A8
AAP 2022 Supplemental Tables 1–4 encoded through 336 hours. evaluateBili() returns phototherapy + exchange + escalation thresholds. Risk-curve selection per neurotoxicity risk factors. Anchor-tested at every published point.
Built
TSB / TcB selector A8
TcB vs TSB input toggle. Explicit "do not subtract direct bilirubin" guardrail.
Built
Newborn briefing bili card A8
Patients under 14 days surface latest TSB/TcB with age in hours; one-click into the calculator with prefilled fields.
Built
AI bili plan A8 · bili-decision
AI · refuses unsafe escalation Two-sentence chart-grounded plan synthesized from feeding history, weight loss percent, exam. Parser rejects direct-bilirubin subtraction and unsupported exchange escalation.
Built
Bili FHIR decision persistence A8
Persist accepted bili decisions as FHIR resources tied to Patient + Encounter.
Coming
Pediatric dosing calculator A9
13 medications with DailyMed-cited source snapshots: amoxicillin, amox-clav ES, cephalexin, cefdinir, azithromycin, oseltamivir, prednisolone, ibuprofen, acetaminophen, ondansetron, doxycycline, clindamycin. Indication-specific dose ranges, max/dose, max mg/kg/day, adult cap, default duration.
Built
Suspension volume by concentration A9
Per-drug concentration table; switch when supply varies (amox 400/5 vs 250/5, ibuprofen 100/5, acetaminophen 160/5).
Built
Cmd-K dose card A9
AI · NL query parser Compact queries like amox 11 kg AOM return a deterministic dose card with mg/kg/day math, suspension volume, source citation. One-click insert into Plan.
Built
PrescribeForm chart-weight suggestion A9
When you pick a drug and the chart has a recent weight, dose/frequency/duration auto-fill with provider-confirmable suggestions.
Built
Hard-stops + override audit A9 · dosing-suggestion
Exceeds mg/kg/day or adult cap → hard block; override requires a typed reason that's captured to the audit trail.
Built
Soft renal / hepatic adjustment context A9
9 medications flag "verify CrCl / LFTs" when relevant. DoseSpot integration tightens this further.
Built
Source-backed catalog infrastructure A9
Schema validation, fixture-parsed DailyMed / RxNorm snapshots, live no-write fetch mode, normalized diffing, coverage reporting. Versioned, reviewer-tracked.
Built
Catalog expansion to ~30 meds A9
Albuterol nebs, diphenhydramine, epinephrine IM, clonidine, methylphenidate, vitamin D, iron, racemic epi, fluticasone HFA, budesonide neb, and more.
In progress
07

Screening & tracking

Developmental and behavioral screening done as a first-class longitudinal tracker — not a checklist that resets per visit.

13 screeners as FHIR Questionnaires A11
M-CHAT-R, ASQ-3, ASQ-SE-2, PHQ-A, PSC-17, Vanderbilt Parent + Teacher, SCARED, AUDIT, CRAFFT, SWYC, PEDS, EPDS. Each with scoring rubric, license metadata, citation, URL.
Built
License-metadata audit A11
Automated check asserts honest publicDomain flag + citation + Questionnaire + scoring per screener. Caught and fixed an incorrect PEDS flag.
Built
Cross-practice export / import A11
Portable JSON via /api/templates/export + /api/templates/import. Preserves slug + license metadata. Foundation for a public template registry.
Built
Longitudinal screening tracker A12
screensDueAt(ageMonths, completed, riskFactors) mirrors the vaccine-engine API. 11 screens with cited source (Bright Futures, USPSTF, Red Book).
Built
/patient/[id]/screenings tab A12
Due / overdue / upcoming cards. Quick-launch into the screener Questionnaire from any row.
Built
Briefing-card "due today" badges A12
Surfaces overdue / due screens on the patient briefing for the active visit.
Built
Inbox-side screener delivery B1
Pre-visit: cron picks tomorrow's appointments and sends Spruce link to parent. Result lands on briefing.
Coming
08

Care plans

Chronic conditions tracked across visits, not relived per encounter. FHIR CarePlan with starter templates and source-grounded AI delta suggestions.

CarePlan data model C4
FHIR CarePlan per chronic condition. Goals + categorized activities (medication, behavioral, monitoring, education, emergency).
Built
5 starter templates C4
Asthma · ADHD · anxiety · food allergy · eczema. One-click instantiate from /patient/[id]/care-plans.
Built
AI care-plan-update suggest C4 · care-plan-update
AI · refuses unsupported changes Source-grounded suggestions from recent visits. Parser rejects new meds, specialist referrals, or diagnoses not in source. Clinician confirms via PUT — no auto-write.
Built
CarePlan subject-preserving merge K2
PUT /api/care-plan preserves subject reference via read-then-merge; a malformed body can't reassign the chart.
Built
09

Patient-facing artifacts

After-visit summaries, forms, action plans, anticipatory guidance — all generated source-grounded, rendered on letterhead, persisted as DocumentReference, sent via Spruce or downloaded.

After-visit summary (AVS) C1 · avs-draft
AI · refuses fabricated vaccines One-button sign drafts AVS from your note + today's vaccine diff + active meds + allergies. Editable text, Spruce send or PDF download. Parser rejects vaccines not given today, meds not on chart, specialist referrals not in note.
Built
School excuse form A4 · forms-factory
AI · source-grounded Date range + reason category. Parser rejects unsupported diagnoses + medications.
Built
Sports physical form A4
AI · refuses substituted diagnoses Latest height/weight/BP/HR + immunization compliance via vaccine engine. Clearance vocabulary (cleared / cleared-with-restrictions / not-cleared-pending-eval). Rejects substituted cardiomyopathy / syncope diagnoses.
Built
Camp medical form A4
AI · source-grounded Emergency contact + chart facts + care instructions + emergency plan.
Built
Daycare medication authorization A4
AI · authorization-medication check Clinician-supplied medication + dosage + dates. Parser rejects authorization text that doesn't reference the supplied medication.
Built
Jury duty excuse A4
PHI-minimal. Reason category + relationship.
Built
State-specific form templates A4.d
Per-state variants of school / sports / immunization forms.
Coming
Asthma action plan A5 · action-plan
AI · refuses red zone without 911 Green / yellow / red zones with mandatory 911 in red. KNOWN_MED_NAMES guard rejects substituted inhalers.
Built
Anaphylaxis action plan A5
AI · refuses missing epinephrine Epi dose by weight + secondary meds + mandatory 911 + epinephrine required in "what to do."
Built
Seizure action plan A5
AI · refuses missing escalation Rescue (Diastat) + maintenance + triggers + 911 for status epilepticus tied to > 5 min duration.
Built
Eczema action plan A5
AI · refuses substituted steroid Emollient + topical-steroid step-up. KNOWN_TOPICAL_STEROIDS guard.
Built
Anticipatory guidance handout A6 · anticipatory-guidance
AI · topic-only filter Bright Futures topic catalog (21 topics × age bands). One-page handout PDF. Rejects sections whose titles aren't in supplied topics.
Built
Growth chart PDF artifact
Printable percentile curves for parents/schools.
Built
Immunization record PDF artifact
Letterhead immunization record for camp/school/sports.
Built
Generic letter generator artifact
Lakes-letterhead letters drafted from chart context (school accommodation, court letter, allergy plan).
Built
Specialist referral letter C3
AI · planned AI-drafted referral with chart context, outbound fax via Spruce.
Coming
10

Family & sibling model

First-class siblings, custody-share guarantors, half-sibling taxonomy. The data model knows pediatrics is a household business.

Peds RelatedPerson code system F2
biological-parent · legal-guardian · foster-parent · grandparent-caregiver · donor-parent · step-parent · adoptive-parent · half-sibling · step-sibling · sibling · other-relative.
Built
Account.guarantor role tags F2
primary · secondary · custody-share. First-class custody share so 50/50 households model cleanly.
Built
/patient/[id]/family tab F2
RelatedPersons + sibling cards + guarantor list in one chart surface.
Built
findSiblingsForPatient() F2
Shared back-search via RelatedPerson last-name. Used across every sibling-aware surface.
Built
Sibling briefing badges F3
On /patient/[id]/briefing: each sibling's name + age + vaccine status + current concerns. Privacy gate via the F1 viewer policy — adolescent siblings hidden from any non-clinician viewer.
Built
Cross-sibling keyboard nav F4
⌘→ / ⌘← flips between siblings preserving the current tab path (Vitals stays on Vitals).
Built
Family Day card on practice home F4
Today's appointments grouped by shared family name. Same parent, same room, shared concerns surfaced as one unit.
Built
Family encounter scaffolding F4
buildPerChildComposition() with K2 patient-scope precondition. The substrate is in place.
Built
Clinician-facing family encounter flip F4
Mid-Encounter per-child Composition switching tied to A3 detection.
Coming
RelatedPerson editing UI F2
Add/edit guardians and siblings from the chart, with custody-share role assignment.
Coming
Adolescent confidentiality (default fail-closed) F1
Per 2025 AAP policy: clinical content for 12+ NOT visible to parent proxies unless explicitly shared. viewerPolicy() decision tree + HL7 v3 Confidentiality tagging (R/N) auto-applied on PHI-write routes for sensitive-default categories (mental health, sexual health, reproductive, substance use, gender-affirming care). Per-resource clinician toggle (R / N / clear). Briefing summary panel + adolescent transition badge + Consent chart tab. Age-transition alerts on practice home for patients hitting 12 or 18. AuditEvent subtype on every flip.
Built
11

Inbox & messaging

One workspace for Spruce, Gmail, faxes, staged documents, forms, and labs. AI-triaged on every ingest path. Same-page focus selection. Refill resolution in one click.

Unified /inbox workspace H2
Top recent queue across Spruce + Gmail + staged docs + faxes + forms + labs. Each row: task type, estimated handling time, confidence, AI summary.
Built
Source panels H2
Spruce and Gmail thread panels in the same workspace. Currently-focused thread hidden from sources to avoid duplicate echo.
Built
Same-page focus selection H2
Clicking a queue row renders the selected thread inside /inbox instead of navigating to chart.
Built
Spruce reply composer inline H1
Reply directly from the inbox; persisted as outbound FHIR Communication with thread auto-resolution.
Built
Gmail thread routing H2
Read-only Gmail threads route into the shared patient thread page. Send remains pending OAuth send setup.
Built
Ambiguous sender staging H2
Gmail senders that don't uniquely match a patient stage as unassigned work; /inbox/assign/[commId] confirms before any chart subject is written.
Built
AI triage classifier H2 · inbox-triage
AI · refuses red-flag downgrade Categories include informational, schedule, refill, results, sick-now, sick-later. Source-grounded prompt + parser.
Built
Triage on every ingest path H2
Runs automatically on Spruce webhook, Gmail sync (cron + manual), patient-scoped Spruce sync, post-assignment of unassigned Gmail. Triage metadata persisted as Communication extensions.
Built
Refill one-click sign + send C2 · refill-decision
AI · refuses substituted medication AI classifies as refill → "Sign + notify patient" → findActiveRefillMatch() dedupes against active MedicationRequest by RxNorm or normalized name → updates existing instead of creating duplicate → Spruce reply sent → audit captured.
Built
Suggested-next-step + draft action hrefs H2
Triage output surfaces persisted suggested-next-step and direct refill-draft action hrefs on inbox rows.
Built
Spruce webhook ingest H1
Secret-gated payload validation. Patient matching by id, reference, or unique Patient.telecom. Dedupes by Spruce message id.
Built
Patient-scoped Spruce sync H1
/api/patient/[id]/spruce-sync with contact-search + contacts-list fallback. Chart-side collapsible Spruce thread panel.
Built
Additional triage categories H2
School-form, prior-auth, and other categories beyond the v1 seven.
Coming
Day-of SMS reminders B2
Cron at T-24h posts reminder via Spruce. Practice-configurable copy. Confirm/cancel reply round-trip.
Coming
12

Scheduling & practice ops

The everyday surfaces: today's home screen, the patients list, the schedule grid, and the operational rails underneath.

Practice home core
Dense Grid B layout. Today's schedule + Day brief + Needs You + Spruce inbox panel + Family Day card + Drafts aside + Team panel.
Built
Day brief core
Today's complexity at a glance: vaccine overdues, sibling families, briefing flags.
Built
Provider huddle / morning panel B3
Today's complexity above the schedule as a single huddle card.
Coming
Patient list core
/patients top-level search/filter. Side-rail accessible.
Built
Schedule grid core
Week/day grid. Click-to-add appointments with patient type-ahead + new-patient modal.
Built
Block-time on calendar G2
Lunch / admin blocks persist as FHIR Slot with status=busy-unavailable. Block-time mode beside appointment booking.
Built
Templates admin core
Practice templates with item editor before save. Practice-vs-my ownership.
Built
Per-clinician favorites G1
Star toggle on Templates page; Favorites filter; encounter picker sorts favorites first. Persisted per authenticated user.
Built
Cmd-K command palette core
Patient search, CDS cards, dosing card NL queries, bili shortcut, Tools registry.
Built
Provider directory + bios G3
Per-provider profile page; surfaced on signup + AVS.
Coming
Multi-provider scheduling G4
Provider picker on appointment booking. Provider filter on schedule view.
Coming
13

Integrations

Northstar plays well with the tools your practice already runs. Patient messaging, email, drive, calendar, ambient transcription — all wired in.

Spruce Health (patient messaging) H1
Webhook ingest + patient-scoped sync + outbound send. Contact-search + contacts-list fallback. Patient-chart thread panel.
Built
Gmail H2
Cron sweep + manual "Sync Gmail now." Plain-text extraction into chart-linked threads for exact sender matches. Ambiguous senders staged for clinician assignment.
Built
Google Drive inbox watch H2
Folder watch with manual "Scan Drive now." Watermark only advances on zero-error sweeps.
Built
Google Calendar core
Event create + lookup wired; calendar UI surfacing matures as schedule linkage deepens.
Built
AssemblyAI (ambient transcription) core
Ambient + push-to-talk transcription for the scribe.
Built
EHR overlay via FHIR H3
Reads + writes against any FHIR-capable EHR. Patient shadows, day dashboard, chart import (vitals as LOINC Observations, immunizations, visit notes). Imported notes become linkable timeline events with source labels.
In progress
Immunization registry submission core
HL7v2 VXU builder + state-registry submit pipeline (single + bulk).
Coming
14

AI features

Seventeen AI surfaces, each doing something only AI can do — and each refusing to do what's unsafe. This is the complete map of what the model actually writes on your behalf.

Scribe scribe
AI · source-grounded SOAP Drafts source-grounded SOAP from ambient transcript or pasted text. Pediatric prompts. Parser rejects history not in the transcript.
Built
Inbox triage inbox-triage
AI · multi-category classifier informational · schedule · refill · results · sick-now · sick-later. Runs on every ingest path. Refuses to downgrade red-flag symptoms.
Built
Pediatric CDS cards cds
AI · guideline-aware Decision support cards inline on chart: vaccine catch-up, dose reasonableness, screening gaps, growth flags.
Built
Cmd-K answers command-palette
AI · NL→structured Natural-language queries return product actions: amox 11 kg AOM, newborn bili, patient lookup, tool launch.
Built
Patient briefing briefing-summary
AI · pre-visit summary Synthesizes the chart into a single pre-visit briefing — identity, active problems, vitals trend, vaccine status, sibling context.
Built
Document import extraction document-import
AI · records pipeline Outside records uploaded as PDF / images get auto-extracted into structured FHIR. Low-confidence outputs escalate to manual review.
Built
Template generation template-generation
AI · authors templates Describe a visit type; AI drafts a note template with sections, prompts, and structured questions.
Built
Growth narrative growth-narrative
AI · refuses unsupported facts Chart-aware percentile + trajectory interpretation. Parser rejects diagnoses, workups, referrals, treatment recommendations.
In progress
Bili decision plan bili-decision
AI · refuses unsafe escalation Two-sentence chart-grounded newborn jaundice plan from feeding history, weight loss, exam. Parser rejects direct-bilirubin subtraction and unsupported exchange escalation.
Built
Dose suggestion dosing-suggestion
AI · weight-aware Suggests dose / frequency / duration from chart weight + drug + indication. Hard-stops on max mg/kg/day; clinician override is captured.
Built
AVS draft avs-draft
AI · refuses fabricated vaccines Plain-language after-visit summary from your note + today's vaccine diff + active meds + allergies. Rejects vaccines not given today, meds not on chart, referrals not in note.
Built
Refill decision refill-decision
AI · refuses substitution AI classifies a refill request → dedupes against active medication by RxNorm → signs + notifies in one click. Refuses to substitute a different inhaler / different drug.
Built
Forms factory forms-factory
AI · suspect-vocabulary check Drafts 5 patient-facing forms (school excuse, sports physical, camp medical, daycare med auth, jury duty) source-grounded against chart + note.
Built
Action plans action-plan
AI · refuses to drop 911 4 conditions (asthma, anaphylaxis, seizure, eczema) with mandatory escalation language and substituted-medication guards.
Built
Anticipatory guidance anticipatory-guidance
AI · topic-only filter Bright Futures topics expanded into a parent handout for the age band. Parser rejects sections whose titles aren't in supplied topics.
Built
Care plan update care-plan-update
AI · refuses unsupported changes Source-grounded delta suggestions from recent visits. Parser rejects new meds, specialist referrals, or diagnoses not in source. Clinician confirms — no auto-write.
Built
Multi-patient routing multi-patient-routing
AI · sibling-shift detector Scribe detects "switching to Mia now" / "let's talk about Mia" mid-utterance. Banner asks clinician to confirm before splitting the note.
Built
15

AI safety

Every AI surface ships with a strict prompt + a parser that refuses unsafe output + a judge that scores it + graded reference scenarios. Nothing gets shipped that we can't grade.

17 audited AI surfaces audit
Every AI feature above is registered as an audit surface with its own judge, scenarios, and report card.
Built
Source-grounded prompts audit
Untrusted input (note snippets, transcripts, documents) is boxed inside explicit untrusted-region boundaries. JSON-only output contracts. Bounded length.
Built
Parser-side safety refusals audit
Suspect-vocabulary checks (no fabricated diagnoses), substituted-medication checks (known-name allowlists), required-phrase checks (red zone must include 911), bullet-budget caps, topic-only filters.
Built
Judges audit
Per-surface judge prompt scoring hallucination · omission · format-drift (0.0 catastrophic → 1.0 perfect). Surface-specific rubrics (e.g. AVS: no fabricated vaccine; bili: no direct-bili subtraction).
Built
Graded reference scenarios audit
Gold-standard input + expected output + must-include / must-not-include facts. Run any time to grade a surface.
Built
Audit dashboard audit
/audit surfaces accepted, refused, and scored entries per AI feature, with daily report cards.
Built
Audit capture on every accept audit
Accepted model output writes an audit entry with surface, input source, model id, version, and output. Refusals captured too.
Built
Prompt injection hardening K15
Uploaded documents bounded with explicit untrusted-document boundaries. Manual-review escalation when confidence is low or schema fails.
Built
Multi-provider AI core
Routes between Anthropic Claude, Google Gemini, and OpenAI per task. Falls back to whichever provider is healthy.
Built
Central prompt registry J2
One source of truth for every prompt with version + edit UI. Audit harness already keys on version.
Coming
16

Security & compliance

HIPAA-grade audit. Auth boundary on every PHI route. Token envelope encryption. Sanitized HTML on note writes. Production-readiness gates.

HIPAA AuditEvent capture I1
Every chart read, write, search, and transaction emits an AuditEvent. Serious-failure events on errors. Auth-success / failure / logout captured with app-user actor.
Built
Generated PHI route inventory I1 / K2
Test scans every API route and asserts it's manifested as auditable. Rejects routes that bypass the audit hooks.
Built
Auth boundary on PHI routes K2
Every PHI route requires a concrete app user before any chart access. Patient/encounter scope checks on every write surface.
In progress
Note HTML sanitization K13
Allowlist sanitizer on every note write. Tested against XSS / script-tag / event-handler injection.
Built
Note sign-flow body preservation K1
Status-only sign patches read-then-merge the body — a malformed sign request can't blank the note.
Built
Atomic clinical transactions K5
High-risk multi-resource writes (e.g. vaccine administration with inventory decrement) execute as one transaction with version-check guards — never half-finished.
Built
Cron secret fail-closed K6
Production cron endpoints require a shared token; missing or wrong token fails closed.
Built
OAuth state verification K7
HttpOnly cookie verifies OAuth state across the round trip.
Built
Read-then-merge update flow K9
Encounter / Condition / Allergy / Appointment updates merge into current state — a malformed body can't strip subject or other fields.
Built
Stable token refresh K10 · K11
Integration token refresh preserves saved config (folders, accounts). Drive watermark only advances on zero-error sweeps.
Built
SOAP draft → audit trail K14
Every accepted scribe draft captured to the scribe audit surface.
Built
Prompt injection hardening K15
Untrusted-document boundaries on uploaded records. Manual-review escalation on low confidence.
Built
Upload size + MIME allowlist K4
75-page PDF cap. Allowed MIME types enforced before write.
Built
Envelope-encrypted integration tokens K3
Third-party access/refresh tokens sealed with secret-box. External secret-store client with backfill planner. Production fails closed without the key.
In progress
Production-readiness API I1
Exposes outstanding readiness issues to authenticated operators before go-live.
Built
BAA discipline + tracker I2
Every PHI-handling third party filed in a tracker doc, status verified.
In progress
Breach response runbook I3
30-day OCR notification, patient + practice templates, AuditEvent forensics workflow.
Coming
Annual pen test I4
Annual cadence with budget + remediation tracking.
Coming
17

How it's built

A modern, opinionated layer. Built to drop in, evolve fast, and never trap your data.

Modern app stack core
Next.js 15 App Router · TypeScript 5 · Tailwind 4 · Tiptap · Vercel AI SDK · pnpm workspaces.
Built
FHIR-fluent core
Speaks FHIR R4 natively. Reads and writes against whatever standards-compliant chart you already have. No proprietary schema, no second source of truth.
Built
Multi-provider AI core
Routes between Anthropic, Google, and OpenAI per task. No single-vendor lock-in on the AI side either.
Built
Per-user settings core
Theme, density, default template, template favorites, scribe-model override, provider profile, chart density preferences — all persisted per authenticated user.
Built
Google SSO production auth core
Allowlist-gated. Login / logout / rejection all captured as audit events.
Built
Cron infrastructure J1
One landing place for pre-visit screener delivery, day-of reminders, audit runner.
Coming
786 passing tests · 163 files core
Type-check clean on every commit. TDD checkpoint cadence per slice.
Built

That's the whole map.

Pediatric depth. AI you can actually grade. Sitting on top of your EHR. If you want to see it in motion — get in touch.

Talk to us