Patient identity, and chart documents on the EXISTING doc manager

Featurekamo-shared-library
Ya
25 Agosti 2026, 17:59 UTC
Mwandishi
Kamo
Ahadi ya
3b39d18

The EHR gets no second document system and no second signature system. PATIENT_CHART is a new ImageAssocType keyed on the patient's logical id, so a chart is an ordinary document collection the DocManager already renders, and binders already work on it — which is exactly what assembling a records-release packet is. Delete and overwrite are OFF and not org-configurable: a received medical record is evidence, replacing the bytes under a document that a note or a disclosure ledger entry cites rewrites history silently, and removing one destroys the §164.528 accounting the practice must be able to produce. Folders and doc types are required, because a chart of three hundred loose scans is unusable and the doc type is what lets a records request answer "labs from 2024" without a human opening every file. Clinical consents reuse EsignGenericEnvelope — two signature systems means two answers to "prove the patient signed this", and only one survives a subpoena. A §164.508 records-release authorization is its own context type because it is a different instrument: it names a recipient, carries an expiry and can be revoked, and filing it as one more consent is how a practice discloses under an authorization that expired eleven months ago. DICOM, C-CDA, FHIR JSON/XML, HL7 v2 and XDM are storable as themselves. Transcoding a C-CDA to PDF on the way in destroys the structured data that made it worth receiving, and a DICOM study rendered to JPEG is a picture of an image rather than the image. PatientLink makes a merge a LINK and never a delete. The absorbed record stays, tombstoned and pointing at its survivor, because every external system that ever held the old identifier goes on asking about it — a referral, a lab, a payer, an HIE query, a portal bookmark — and answering "that id never existed" turns a merge into data loss on someone else's side. NOT_A_MATCH is as important as the merges: twins share a surname, a birth date and an address, and without a durable record that a pair was reviewed and ruled distinct the matcher resurfaces them forever until a tired clerk merges two different people, which is the most damaging error this module can make and very hard to undo. The merge manifest is stored because an unmerge without one means guessing which of two charts each row came from. PatientIdentifierIndex keeps normalised and phonetic keys OUT of the patient record. Matching runs on normalised values and displaying them is wrong: "O'Brien-Smith" must be findable as "obriensmith" and must still render with its apostrophe. Superseded rows stay searchable on purpose — staff search by the old MRN for years, and the right answer is to land them on the survivor, not to report no such patient. 1789 tests green.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei