Unified patient record
One page per patient: overview, visits, notes, medications and allergies, results, care plans, flags, documents and portal. Each is a tab away, and none of it is a separate system.
Lyme & complex chronic illness
Years of scattered records, from outside labs to old prescriptions to symptoms that only make sense across time, assembled into one clear picture. Practice tools and an invite-only patient portal.
Accounts are created by invitation only. Practice staff are added by an administrator; patients receive a portal invitation from their clinician.
Illustrative only. Symptom scores, lab markers and treatment periods on one shared axis. No patient data is shown.
The problem
Patients arrive after years of specialists, carrying a history that exists but isn't legible. The software they meet was built for something else entirely.
A decade of outside labs, imaging reports and half-remembered prescriptions, in paper and PDFs from a dozen systems that never spoke to each other.
Conventional records are organised around one encounter at a time. They document a visit well and show an illness poorly, because the shape of it lives between the visits.
Every outside result and intake sheet gets re-keyed by hand. That time is taken directly out of the appointment, and the transcription is where errors enter.
What we stand for
Five commitments that decide what this software does, and what it refuses to do.
Symptoms, labs, medications, supplements and visits plotted on a single shared time axis. Patterns, relapses and treatment responses become visible instead of inferred.
Lab PDFs, outside records, scans and handwritten intake forms are read and turned into structured data. Nobody should be retyping a blood count.
Every extraction and every flag is surfaced for human review before it reaches the chart. The software never quietly changes a patient's record, and it does not practise medicine.
The portal gives patients their labs, their medications, their care plan, their education materials, and a direct, secure line to the people treating them.
Not a policy page. Files live in private storage that is never publicly addressable, the database is never exposed to the internet, and access is by invitation only.
How it works
Four steps, and a clinician stands in the middle of them.
Lab PDFs, outside records, photographs and completed paper forms, uploaded at the visit they belong to or in a batch during onboarding.
Analytes with their values and reference ranges, medications, symptoms and findings are read out of the document and proposed as structured data.
Each proposal is shown beside the source document. Accept it, correct it, or reject it. Nothing is written to the chart unread.
Everything lands on one shared time axis, and the parts the patient needs are published to their portal.
Step 03, up close
The extraction is proposed, not applied. A clinician sees each field beside the page it came from and accepts, corrects or rejects it. That review is the point of the whole pipeline: the software does the transcription, the clinician keeps the judgement.
Illustrative only. No patient data is shown.
Features
One record per patient, with everything that matters to a long case kept in view.
One page per patient: overview, visits, notes, medications and allergies, results, care plans, flags, documents and portal. Each is a tab away, and none of it is a separate system.
Symptom scores and lab analytes overlaid on one normalised axis so different units compare. A longitudinal grid of analyte by date, a calendar of every event, and a Gantt view of which medications were running when.
Upload a lab PDF, an outside record, a photo or a scanned form. Structured data is proposed, reviewed side by side with the original, and only then committed.
A configurable rule engine plus per-visit analysis raises interactions, out-of-range results, worsening trajectories and missed follow-up into one practice-wide inbox that is assignable, resolvable, and quieter over time as dismissals teach it.
Build the practice's own intake and follow-up questionnaires, including a per-day grid for week-long symptom tracking. Print them, hand them over, scan them back, and the handwriting becomes data on the chart.
Doctor-authored, sectioned treatment plans that print cleanly for the patient to take home and publish straight to their portal.
Threaded messaging between patient and practice, with internal notes staff can attach out of view and triage to route a thread to the right person.
Day, week and month calendars with appointment status, configurable practice hours and slot lengths, and today's list surfaced on the dashboard.
Admin, doctor, staff and patient roles in a strict hierarchy, admin-only user management, an audit log of record access, forced password change on first login and lockout after repeated failures.
Illustrations above are abstract representations of the interface. They are not screenshots, and no patient data is shown.
For patients
If you are a patient of the practice, the portal is yours. It holds the same record your clinician is working from, not a summary of it.
Lab results as they come in, kept in order, with the values that moved shown against the ones that didn't.
What you are taking now and what you have taken before, with the dates, so you never have to reconstruct it from memory in an appointment.
The plan your doctor wrote for you, in full, available to read at home and to print.
Articles, documents and videos your clinician has chosen specifically for your case, not a generic library.
Secure messages to your care team, kept with the rest of your record instead of scattered across email and voicemail.
Your clinician sends the invitation. There is nothing to sign up for here. If you are a patient of the practice and don't have portal access yet, ask at your next visit or call the office.
Security & privacy
This platform holds real medical records. These are the specific technical measures in place, not a badge and not a promise.
Patient documents live in private object storage and are served only through an authenticated route. No public buckets, and no shareable pre-signed links that outlive a session.
Postgres is not reachable from the internet. It accepts connections from the application only, on a private network.
HTTPS end to end for every request, and encryption at rest for the database and stored documents.
Admin, doctor, staff and patient roles in a strict hierarchy. Patients reach their own record and nothing else; user management is admin-only.
Record access is written to an audit log, so who opened which chart and when is a question with an answer.
There is no public sign-up to attack. Accounts are created deliberately, with a forced password change on first login and lockout after repeated failed attempts.
Spiro Health is built with HIPAA-conscious controls. We describe the measures above rather than display certification badges we don't hold.
The practice's tools and the patient portal live behind one sign-in.
Accounts are created by invitation only. Practice staff are added by an administrator; patients receive a portal invitation from their clinician.