Lifecycle view
Appointment details stay available for requested, booked, checked-in, in-progress, completed, cancelled, no-show, and reschedule-requested visits.
The staff view of one appointment, with lifecycle facts, verified patient and provider context, governed note, medication-request, order/referral and after-visit drafts for an active Encounter, prescriptions and medication history, attached records, preparation messages, requested information, and telemedicine readiness.
Appointment details stay available for requested, booked, checked-in, in-progress, completed, cancelled, no-show, and reschedule-requested visits.
After a booked visit window ends, an active scheduler or the exact assigned doctor can record that the patient did not arrive. The action records a controlled patient/reason/time/actor trail and releases the reservation once. Before the window ends it is hidden and denied. If an Attempt exists, patient or provider absence must use the governed Encounter disposition instead.
Before check-in, patient cancellation, clinic cancellation, and clinic request decline receive distinct server-derived party and reason codes with actor/time/prior-state evidence. Optional narrative is clinical-sensitive detail and is never copied into command or audit logs. After an Attempt exists, use the governed Encounter disposition instead.
The assigned clinician or an active operational care-team member can record a controlled revised start for a linked, policy-bound virtual visit before admission. The exact Appointment, patient, membership, schedule revision, optional waiting Encounter, command, and audit commit together. It does not change the booked slot, and Communication history must be checked for in-app delivery. External channels remain disabled.
Before the session starts, add comments, ask follow-up questions, request missing information, or suggest lab reports.
Review attached patient records. The assigned provider can run their own appointment-bound local check for confirmed telemedicine visits; patient diagnostics remain private and are evaluated only by the server-side entry gate. Permission, device, network, pause, and resume changes invalidate stale local success and require a rerun.
Review the prescription issued for this appointment and earlier prescriptions available for the patient. Each entry preserves the final medication directions and issue date.
During an in-progress, paused, or documentation-pending Encounter, the exact assigned clinician can document history, remote examination provenance, assessment, diagnoses, plan, disposition, precautions, medication and order decisions, education, and follow-up. Draft status changes to Saved only after the server acknowledges an immutable revision.
When an authorized Encounter is loaded, the sticky server-bound banner identifies the patient, clinician, Appointment, Encounter, modality, and current lifecycle state. A changed or unavailable context removes clinical authoring instead of retaining stale controls.
The assigned clinician can review answer provenance, record a governed outcome for open clinical signals, correct submitted answers with a reason, and complete review only when required answers and signals are resolved. Coordinators receive completion and ownership status without answer values.
The assigned clinician reviews patient-entered current location, callback, privacy, capacity, people, support, and emergency planning. A non-allow decision creates owned next actions. Even an allowed review is not Start authority and must be rechecked with current provider eligibility.
The assigned clinician can read the exact booked consent text and current patient decision. The view is read-only and never treats an absent decision as approval. Consent is only one future Start prerequisite and does not authorize recording, AI, pharmacy transmission, or added participants.
An active clinic scheduler can create one expiring patient self-access invitation for an unlinked requested or booked virtual visit. The server uses the current verified Contact email and never returns the destination or link secret to the browser. Provider acceptance is not proof of receipt or use. Proxy/caregiver access and wrong-link correction remain disabled and must never be simulated by linking the proxy as the patient.
Complete required sections, save the current revision, then mark it ready for signature. The server has an immutable signing and reason-coded addendum transaction, but the product keeps both actions disabled until DEC-005 approves a signing-assurance provider. A signed version never releases the note or completes the visit by inference.
Create one versioned MedicationRequest per selected catalog candidate, author dose and indication, and record all seven manual safety dimensions. Ready stays patient-hidden. The server has an exact immutable issue handoff with fresh identity, Encounter, location, credential, catalog, review and assurance checks, but the product keeps Issue locked until an approved assurance provider and medication-safety policy are enabled. Internal issue would not transmit to a pharmacy, notify the patient, resolve the owned task or close the visit.
The assigned clinician can create and revise laboratory, imaging, referral, and other approved ServiceRequest drafts against the current Encounter. Terminology is unverified, and signing, routing, results, and patient release remain unavailable, so a saved draft is not an order sent to a destination.
The assigned clinician can prepare plain-language care instructions from the verified Encounter and reviewed note, save an immutable revision, and mark it reviewed. Review remains private. Publication stays product-disabled while the approved assurance adapter is unavailable; an enabled exact release may create an optional policy-bound in-app summary-ready intent, but it never enables export or Encounter closure.
Create a due-window plan with a current follow-up visit type, accountable care-team owner, modality, provider constraint, and patient action. Assignment, offer, cancellation, closure, and owner reassignment are governed transitions. The recovery worker records distinct Due and Overdue events and may create an optional policy-bound in-app reminder; communication history remains the delivery truth. Completed comes only from the exact provenance-bound linked Appointment. Cancellation, no-show, reschedule, authority, or provenance drift remains a reason-coded owned review state. Review can set a future window and return the plan to Assigned. This tracking does not create an SLA escalation, run post-visit ClinicalTasks, or close the Encounter.
The assigned clinician creates pre-closure ClinicalTasks for unfinished documentation, instructions, medication, orders, follow-up, questions, and safety dispositions. Abnormal and critical internal results create their own configured-due task before receipt reports success. Each task binds verified source and owner evidence. The due time is manual evidence only for ordinary tasks; it is not an approved SLA or automatic escalation trigger. Checkout review fences both the decision manifest and task-set digest. An already-owned task may Start, Block, or Resolve after clinical completion without reopening the Encounter. Result-review tasks may Start or Block here, but only exact Result acknowledgement can Resolve them; generic assignment, source refresh, cancellation and resolution are denied. Team or covering authority, approved SLAs, automatic escalation, care completion, and Encounter closure remain unavailable after that boundary.
The history panel exposes identifier-only, audited intent status for the appointment. It distinguishes queueing, provider acceptance, delivery, suppression, and failed work without displaying patient destinations or message content. Local adapter submission and expiry stay in immutable evidence rather than being shown as delivery states.
The assigned clinician or explicitly assigned active care coordinator or tenant owner can read and send in the virtual-visit care thread. Reassignment, close, and reopen use exact optimistic revisions and controlled reasons. The patient remains exact self only; platform administration and generic chat presence grant no clinical access. Response SLA, on-call routing, automatic ClinicalTask escalation, attachments, proxy access, moderation, and external notifications remain disabled.