
🏥 Healthcare · Data Flow
How protected health information (PHI) moves through a health app while staying encrypted, access-controlled and audited.
Drawing diagram…
Data flow for a HIPAA-compliant health app: patients and clinicians send PHI over TLS to an API gateway with authentication, the application service stores it in an encrypted database with keys in a KMS, every read and write is recorded in an audit log, a de-identification service strips identifiers before data goes to the analytics warehouse, and records are shared with partner providers only under a business associate agreement.
flowchart LR P[Patient App] -->|PHI over TLS| GW[API Gateway - auth, MFA] C[Clinician Portal] -->|PHI over TLS| GW GW --> APP[Application Service] APP -->|Encrypted writes| DB[(PHI Database - encrypted at rest)] KMS[(Key Management)] -->|Keys| DB APP -->|Every access| AUD[(Audit Log)] DB -->|Records| DEID[De-identification Service] DEID -->|De-identified data| DW[(Analytics Warehouse)] APP -->|Under BAA| PART[Partner Providers]
A container-level view of a hospital management system: patient and staff apps, the core services behind them, and the external systems a hospital depends on, such as insurers and labs.
How a patient books a doctor's appointment online: checking free slots, holding one, paying the consultation fee and getting a confirmation.
How a hospital's EHR exchanges data with labs, radiology and insurers through an integration engine, translating between HL7 v2 and FHIR.
An online doctor consultation from booking to e-prescription: payment, a secure video room, consultation notes and the prescription sent to the patient.
How a cashless health insurance claim works at a hospital: pre-authorisation with the TPA, treatment, and final bill settlement directly with the insurer.
A core relational schema for a hospital: patients, doctors, departments, appointments, admissions, beds, prescriptions and bills.