A patient platform designed for clarity and trust
A patient-facing platform for appointment booking, records access, and care communication, built with clarity, accessibility, and privacy in mind.
What the engagement involved
- Industry
- Healthcare & Dental Practices
- Duration
- 20 weeks
- Cooperation model
- Time & materials
Client name withheld under NDA. Engagement details are shown to the extent our agreement permits.
Every surface, in order
Step four of four: the earlier answers kept with an Edit beside each, the week of times still there as large targets with Thursday 09:40 chosen and held, and a Back that loses nothing.
A thread with the care team about a home blood pressure average of 138/87, who else can read it listed, the reply from Dr. Whitlock, and the after-hours note stated plainly.
Twelve months of blood pressure over the eight results behind it, each marked against its own range: below 140/90 in clinic, below 135/85 at home.
Prescription refills: seven items, three due on October 1 and checked to order together, and the levothyroxine already ordered and waiting at the pharmacy.
Text size, contrast, motion and plain language, with a preview of the next appointment in the chosen settings, audited to WCAG 2.1 AA before launch.
Seven statements across the year with what insurance paid and what the patient paid, footing to $184.00 of $671.00 charged.
The rollout across eleven clinics: eight live with last week's own booking and scheduling-call counts, Kestrel Park in training at seven of ten staff, and two scheduled.
Ashcombe's Tuesday at 14:10 as reception and the exam rooms both see it: 42 booked as 26 seen, 4 waiting, 2 no-shows and 10 still to come, with the longest wait named.
One decision queue instead of four inboxes: 41 waiting as 14 results, 12 messages, 9 refills and 6 referrals, with the three urgent at the top.
Two weeks of slots by type, offered minus booked equaling open on every row: same-day urgent fully taken both weeks while 63 nurse slots sit open.
The week's 158 results outside range, each with the range it broke: 152 looked at inside a working day and 6 later, 141 commented and released, 17 still with a clinician, none released without a comment.
Five roles against six kinds of record, the patient holding their own and nobody else holding all six, and 18,402 staff openings in thirty days with six challenged and each explained.
The brief
Booking an appointment or finding records meant navigating dated, confusing screens. We redesigned the patient experience around guided, accessible flows.
A group of eleven clinics whose patient portal had been bought in 2014 and never replaced, and whose front desk was fielding around four hundred calls a day, most of them to book, rebook, or ask for a result. The engagement was commissioned after an accessibility complaint the group couldn't answer, which is why the audit came before the redesign.
Product Design
What people were running into
- 01
Patients had no simple way to book, view records, or reach their care team between visits, driving avoidable phone volume to the front desk.
The booking form was one page with nineteen fields, no keyboard order, and error messages that appeared above the fold while the invalid field stayed below it. Records lived behind a separate login patients were never given. Every one of those was a phone call, and the front desk was taking them while patients stood at the counter waiting.
We redesigned scheduling around a guided booking flow, gave patients a clear records view, and added secure messaging so care teams could follow up without a phone call.
Design decisions
- 01
Ran accessibility audits and designed to WCAG AA from the start
The audit ran before any design work and set the constraints, so accessibility shaped the flow from the start, with nothing retrofitted.
- 02
Prototyped a guided booking flow with real patients
The booking flow was prototyped with real patients including screen-reader users, which is where the four-step order and the ten-minute slot hold came from.
- 03
Built secure, role-aware messaging between patients and teams
Clinic staff scoped this, and their first requirement was that it couldn't become a second inbox, so it routes into the triage queue they already work.
- 04
Rolled out clinic by clinic with staff training
Each clinic went live with its front-desk staff trained beforehand, so the people absorbing the change had seen it before their patients did.
Phase by phase
Phase 1: Accessibility & UX Audit
Patient Journey & Compliance Audit
Audited existing booking & records access for WCAG 2.1 AA compliance and usability friction across various patient demographics.
- Accessibility Audit Report
- Patient Journey Map
- Healthcare Usability Matrix
Phase 2: Product Design & Prototyping
Guided Booking & Messaging UX
Designed a progressive multi-step booking flow and HIPAA-encrypted patient-provider messaging interface.
- Figma Design System
- Interactive Prototype
- Accessibility Test Sign-off
Phase 3: HIPAA Architecture & Build
EHR Integration & Encrypted Vault
Built the secure web application connecting directly to the EHR system with end-to-end encryption for patient data.
- Next.js Care Engine
- EHR Connector API
- HIPAA Compliance Audit
Phase 4: Clinic Rollout & Training
Multi-Clinic Launch & Staff Onboarding
Deployed clinic by clinic across 11 locations, training front-desk staff and monitoring patient adoption metrics.
- Multi-Clinic Launch Plan
- Staff Training Guide
- Patient Onboarding Assets
The twenty-week plan at week 19: the audit first, a keyboard and screen-reader gate on every increment, and eleven clinic cutovers one at a time, eight live, one in training and two scheduled.
Guided Appointment Scheduler
Accessible multi-step clinic booking engine with automated SMS and email reminders.
Booking is four steps (reason, clinician, slot, confirm), each announced to screen readers and reachable by keyboard, because the previous single-page form failed the clinic's own accessibility audit. Slots are held for ten minutes while the patient completes and released automatically after, so two people can't claim the same appointment. Reminders go out at forty-eight hours and two hours by both SMS and email.
- Four steps, keyboard-reachable and screen-reader announced
- Ten-minute slot holds prevent double booking
- SMS and email reminders at 48 and 2 hours
The booking engine: the four steps as a screen reader announces them, the keyboard and screen-reader gate each increment passed before merging, live ten-minute slot holds, and one booking's text and email reminders at 48 and 2 hours.
A cholesterol result held from the patient until Dr. Reyne writes a comment and releases it, the vault holding the value while the app keeps a pointer, and every read of the record with its actor and stated reason.
Secure Patient Records Portal
HIPAA-compliant records view allowing patients to access lab results and medical history securely.
Records are read through a HIPAA vault and never copied into the application database, so the app holds pointers and permissions and never the protected health information itself. Every read is logged with actor, record and stated reason. Lab results sit behind a clinician release step, so a patient doesn't meet a serious result alone on a Saturday, and sessions expire hard with no silent refresh.
- PHI stays in the vault; the app holds pointers only
- Every read logged with actor, record and reason
- Clinician release gate ahead of result visibility
Direct Care Team Messaging
A message addressed to the care team, not to one physician, sitting in the decision queue the practice already works, carrying the appointment it refers to, and escalated by a triage rule to a call from the on-call physician.
Encrypted direct messaging between patients and clinic staff for follow-up care.
Messages are encrypted end to end and addressed to a care team instead of an individual, so cover works when a clinician is away. Threads route into the practice's existing triage queue, not a new inbox nobody watches, and each one carries the appointment or result it refers to. Anything the triage rules mark urgent escalates straight to a phone call.
- Threads addressed to a care team, so cover works
- Routed into the existing triage queue
- Urgent flags escalate straight to a call
What moved after the redesign
−38%
Front-desk call volume
+52%
Online bookings
WCAG AA
Accessibility
Call volume is the switchboard's own count for scheduling calls specifically, comparing the three months after full rollout with the three before. Online bookings are measured as a share of all bookings, not in absolute terms, so growth in patient numbers can't flatter the figure. The accessibility result is a third-party audit, not a self-assessment.
Client name withheld under NDA. Figures are approximate, drawn from the engagement’s own reporting.
Principles that held
Designing to WCAG 2.1 AA from day one reduced front-desk scheduling calls by 38%.
Accessible and simple turned out to be the same work: the constraints that make a flow usable by a screen reader are the ones that make it obvious to everyone.
Secure direct messaging resolved patient follow-ups without requiring unnecessary in-clinic visits.
The follow-ups that stopped becoming visits were the ones needing a yes or a dose confirmation. A message answers those; an appointment slot was the wrong unit for them.
Guided step-by-step booking increased online appointment scheduling by 52%.
Booking rose because each step asked one thing and showed what was left. Patients had never really rejected the nineteen-field form; they abandoned it midway.
How design and engineering worked together
A cross-functional team of 5 worked on a time & materials basis over 20 weeks, covering Accessibility-first design, Secure messaging, Records UX. We ran daily standups with an in-house lead in the room, and a demo at the end of every sprint. Scope changed twice during the engagement, and both times the change was priced and agreed before work started.
Accessibility was a gate on every increment, not a review at the end: nothing merged without keyboard and screen-reader passes, which is the only arrangement under which a WCAG claim survives contact with a deadline. Rollout went clinic by clinic with the front-desk staff trained before each cutover, so the people absorbing the change had seen it first.
Four settings, one card
Accessible and simple turned out to be the same work
The settings patients use in the app, applied live to the card on their home screen. Make the text larger, raise the contrast, turn motion down or switch to plain language, and the same appointment and result stay readable. Switch tabs, or use the arrow keys once one is focused.
Everything is sized relative to the text, so a larger setting reflows the card instead of cutting words off or hiding the button.
Now: text default, contrast standard, motion full, plain language off. Timings are illustrative.
Thu, Sep 24, 09:40
Blood pressure review · Dr. Tobias Reyne · Ashcombe Clinic, Room 4
Measured against below 5.0 mmol/L. A little above target. We will talk about it at your review on Sep 24.
Press the card’s button to see how a confirmation arrives: sliding in with motion on Full, simply appearing with Reduced.
From a patient’s tap to the clinic, and back
Bookings, messages and results pass through the same five stages. The patient-facing app stays simple because the hard rules (holds, release and routing) live behind it, where no screen can skip them.
- 1 · Source
Patient app
- Four-step booking: reason, clinician, slot, confirm
- Messages to the care team
- Records and results views
Nothing merged without keyboard and screen-reader passes
- 2 · Queue
Holds and triage
- A chosen slot is held while the patient finishes
- Threads routed into the practice's existing triage queue
A slot held ten minutes cannot be claimed twice
- 3 · Engine
Care engine
- Role-aware permissions on every request
- Triage rules mark urgent threads
- Clinician release step on results
No result reaches a patient before a clinician releases it
- 4 · State
Records vault
- Protected health information stays in the vault
- PostgreSQL holds pointers and permissions
- Every read logged: actor, record, reason
The app database never holds the record itself
- 5 · Delivery
Reminders and calls
- Text and email reminders at 48 and 2 hours
- Urgent threads become a call task
- Sessions expire hard, no silent refresh
An urgent message is escalated to a call, never left in a queue
Privacy, release and access
Safe to open to every patient
The right role, and a reason on file
Messaging and records are role-aware: a patient holds their own record, staff see what their role needs, and nobody else holds everything. Every read is logged with actor, record and stated reason, and sessions expire hard with no silent refresh.
No result without a clinician first
Lab results sit behind a clinician release step, so a patient doesn't meet a serious result alone on a Saturday. The results themselves stay in the vault; the application holds pointers and permissions, never the protected information.
A booking flow nobody is shut out of
The audit ran before any design. Booking is four steps, each keyboard-reachable and announced to screen readers, and no increment merged without both passes. A third-party audit, not a self-assessment, put the result at WCAG 2.1 AA.
Patients phoning the front desk to book, rebook or chase a result? Scope your build in 3 minutes.
Scope your buildNearby engagements
Web PlatformsThe ransomware attack that became a four-hour non-event
A ransomware attack encrypted the primary patient records server. Drilled offsite backups and a written runbook turned what could have been a scramble into a full restore inside the recovery time objective.
Healthcare & Dental Practices · Ongoing retainer
E-commerceA cart that won't check out until the prescription is real
An online pharmacy where a prescription is a first-class record with its own lifecycle, and prescription-only items simply can't leave the cart without one.
Healthcare & Dental Practices · 20 weeks
Web PlatformsThe right blood type isn't enough: it has to be someone who can get there
A donor register that matches each request on blood-group compatibility and on whether the donor can actually reach the hospital. One platform serves a web admin and a mobile client from the same records.
Healthcare & Dental Practices · 16 weeks
Let's talk
Running a large platform, shaping a first MVP, or getting a product ready for a funding round? Tell us where you are. We'll shape the process around it, and stay with you after launch.














