A regional clinic network wants patients to book, reschedule and join telehealth visits from their phones instead of calling the front desk. This blueprint shows how we design a cross-platform app and a HIPAA-ready backend that read and write appointments directly in the clinic's EHR.
Most bookings still happen by phone, so front-desk staff spend much of the day on scheduling calls.
Appointment data lives in the EHR, and any app that keeps its own copy quickly drifts out of sync.
No-shows are common because reminders are manual or missing, especially for telehealth visits.
Any new system that touches patient data must be ready for a HIPAA security review before launch.
What the Solution Delivers
Patients book, reschedule and cancel visits in the app, with slots read live from the EHR
Reminders by push, SMS and email that include telehealth join links and pre-visit forms
Upcoming appointments and visit details available on the device even without a connection
Encryption, audit logging and BAA-covered services in place for the client's HIPAA review
Architecture
Appointment app architecture
The Flutter app talks only to the scheduling API, which checks identity, writes an audit record and syncs appointments with the EHR over FHIR. Reminders and telehealth links are sent through BAA-covered messaging services.
The situation
Clinic networks often have a patient portal that came with the EHR, but it is hard to use on a phone and patients rarely log in. Most people still call to book, which ties up front-desk staff and makes it hard to fill last-minute cancellations. Telehealth adds another layer: patients need the right link, a working device and a reminder at the right time. A separate booking tool that keeps its own calendar quickly drifts out of sync with the EHR, which leads to double bookings and a lot of manual cleanup.
Our approach
1. Design around the patient’s real journey
We start with short interviews and usability sessions with patients and front-desk staff. We map the paths that matter most: finding a provider, picking a slot, choosing in-person or telehealth, completing intake forms and joining the visit. Our designers prototype these flows in Figma and test them with older patients and with screen readers before any code is written. Large tap targets, clear language and dynamic type support are defaults, not extras.
2. Keep the EHR as the source of truth
The app never owns the schedule. A FHIR adapter reads Slot and Schedule resources and creates or updates Appointment resources directly in the EHR, using the vendor’s certified FHIR R4 API and SMART on FHIR authorization where available. Clinic-specific booking rules, such as visit types, buffer times and new-patient restrictions, are stored as configuration that staff can change from a console. When the EHR is slow or down, the API returns a clear message instead of confirming a booking it cannot guarantee.
3. Build a HIPAA-ready backend
Every request passes through identity checks with multi-factor sign-in for patients and role-based access for staff. Data is encrypted in transit with TLS and at rest with AWS KMS-managed keys. Each read or write of patient information produces an audit record showing who, what and when, stored in a tamper-evident log. We only use cloud, messaging and video services that offer a Business Associate Agreement, and we keep push notification text free of clinical details. We document these controls so the client’s compliance team can complete its HIPAA risk assessment.
4. Make reminders do real work
The reminder service sends messages at configurable intervals before each visit, through push, SMS or email based on patient preference. Reminders carry one-tap actions: confirm, reschedule or open pre-visit forms. For telehealth, the message includes a device check and the join link shortly before the appointment. Cancellations release the slot back to the EHR right away so another patient can take it.
5. Work offline, safely
Patients open the app in parking lots and waiting rooms with weak signal. We store upcoming appointments, clinic addresses and visit instructions in an encrypted local database built with Drift and SQLCipher. Changes made offline are queued and synced when the connection returns, and conflicts are resolved against the EHR rather than overwriting it. Signing out or remote deactivation wipes the local cache.
How we deliver it
We ship in phases. The first release covers booking, reminders and cancellations at a pilot clinic, with telehealth scheduling and intake forms following once the integration is proven. Automated tests run against an EHR sandbox, and each build goes through TestFlight and Google Play internal testing before release. Infrastructure is defined in Terraform on AWS; see our cloud services for how we run regulated workloads.
Is this relevant to you?
If your patients still book by phone, or your current app keeps its own calendar that fights with the EHR, this architecture is a good fit. Explore our web and mobile app development service or talk to us about your clinics and EHR.
Building something similar?
We'll walk through your requirements and share how we'd approach architecture, timeline and team for your project.
We use essential technologies to run this site. With your OK, we also use cookieless analytics and Google Maps, which may set cookies. No ads, and we never sell your data. Cookie Policy
Privacy preferences
Choose which optional technologies we may use. Strictly necessary ones are always on because the site can’t work securely without them. Details are in our Cookie Policy.
Your browser sends a Global Privacy Control signal, so optional technologies are off by default.
Strictly necessary
Security and spam protection (Cloudflare, Google reCAPTCHA), form delivery, and remembering these choices.
Always on
Cloudflare Web Analytics counts page views without cookies or cross-site tracking.
Shows our office on Google Maps. Google may set cookies and receive your IP address.