Answers
Questions, answered by one page each
Each question below links to the single page that settles it. Use it as a fast route into the documentation when you already know what you want to ask.
Continuity and failure
- What happens to the billing counter when the internet drops?The counter's desktop stops, because no browser reaches the record store directly and the site cannot reach the platform. The hospital's downtime procedure takes over, staff work on printed fallback forms, and the entries are brought back into Pensieve afterwards as late entries carrying their true time. The orophin bridge keeps running on the hospital network throughout, sealing messages from the hospital's own machines into a local encrypted queue and replaying them when the link returns.
- What happens to clinical work when the link to the cloud drops?Care carries on under the hospital's downtime procedure. The ward reads from the downtime pack, a read-only extract of active in-patient summaries and current medication orders held on the hospital's own storage, and paper is the record while the link is down. Every paper entry is brought back into Pensieve afterwards as a late entry carrying its true clinical time, never back-dated to disguise the gap.
- What does a registrar do at two in the morning when the record is out of reach?They follow the hospital's downtime procedure: read the current clinical picture from the downtime pack, record care on the printed fallback forms, and keep the true clinical time against each entry. When the link returns, that paper work is entered into Pensieve as late entries with their true clinical times, and the registrar tells the ward lead if the outage runs long.
- What happens to unsaved work when the next person taps in?Every confirmed entry is already in the record, held with your name and the time, and a change either commits in full or leaves the record as it stood, so there is no half-written state to lose. A form you had not confirmed keeps your place as a draft, which you reopen from the record and carry on from where you paused. If an entry turns out to be absent, enter it once more and watch for the confirmation.
- How fast can we recover, and what have you committed to?The committed recovery time and recovery point are set per deployment and recorded on its order form and in the service level agreement, because they depend on the deployment model and the region. Pensieve commits them where it controls the infrastructure, on DM-1 Dedicated and DM-2 Shared, and on DM-3 Customer cloud subject to the hospital's project and keys staying available; there is no Pensieve commitment for DM-4 on-premise, where restore time depends on the hospital's own hardware, media and staff. The database keeps automated backups with point-in-time recovery, object storage is versioned with a soft-delete window, and a restore is checked for integrity before access reopens.
The record
- What does the patient record hold?Atlas holds one record per patient, and it belongs to the patient rather than to a site, so it follows them across every hospital that runs Pensieve. It keeps diagnoses, completed forms, uploads, imaging studies, triage records, consent records and the access history, alongside the patient's identity, blood group and the two facts it holds about sex. Every entry names the person who made it and the moment they made it, drawn from that person's own sign-in.
- Can a record be altered?No entry is overwritten. A correction lands as a new version that leads the record while the earlier version stays visible and marked superseded, and each correction writes an audit entry in the same transaction as the change it records.
- What is the difference between an amendment and an addendum?Pensieve records two kinds of change to an entry, and they carry different meaning. An amendment says the earlier content was correct and a newer version now leads the record, with the original kept and marked superseded. An entered-in-error mark says the entry was recorded in error, so it leaves the live clinical view while staying in the history.
- Who saw this patient record?Open the record in Atlas, select its access history and set the review period. Each line names the person and the role they held, the site, the moment, the part of the record touched, whether it was a read or a change, and the basis for the access, with emergency reads carrying the clinician's own stated reason. The history is complete because each audit entry is written in the same transaction as the access it describes.
- How long are records kept?There is no single period. Retention is a property of each record class, computed from its jurisdiction, anchor event, period and hold state, so an in-patient record, a statutory register, the books of account and the processing logs each run their own clock, with logs held not less than one year. The hospital sets the values as Data Fiduciary, a nominated hospital role approves each destruction queue, and every destruction event is written to a destruction register.
- How do we release a record to a patient?Establish the lawful basis or the patient's recorded consent, fix the scope per data category rather than releasing the whole record by default, send it to the named recipient, and write the entry to the disclosure register. The register holds the recipient, the scope, the time and the basis, so the hospital can later tell the patient exactly who received their data. A medico-legal record is released only through its own approval chain.
- How do we decline an erasure request lawfully?An erasure request is never answered as a single yes or no. Pensieve decomposes it into a category inventory and the hospital, as Data Fiduciary, assigns each category a state of active, restricted or erased together with the named legal ground, restricting a category where an unexpired statutory floor, a hold or a live legal claim blocks erasure. The patient receives that enumerated residual with the reason for each part rather than a bare refusal.
Access
- How does the system decide what someone can see?It reads two things together: the person's role, which sets what they may do, and their relationship to the patient, which sets which records those actions reach. <Tool>Cirith Manager</Tool> holds that decision for the whole platform, and access holds only where consent, an active admission at the site, role and care team, clearance for any sensitive category, and cross-site sharing all hold at once. Access is refused by default, so the absence of a granting relationship leaves the action closed.
- Who can see this patient right now?Open <Tool>Cirith Manager</Tool>, the access panel inside <Tool>Nexus Manager</Tool>, and search for the patient. It lists every person who currently holds access, each row naming their role and the relationship that grants it, alongside any clinician inside an emergency-access window and any explicit block. The list is live, so a name drops off when the shift ends, the visit completes past its grace period, or the patient withdraws consent.
- What can this person see?<Tool>Cirith Manager</Tool> gives the forward view for one member of staff: the roles they hold at each site, the live duty scope their current shift derives, and the patient records those roles reach now, each with the relationship behind it. A capability reaches a patient only where the person's current scope covers the service and the patient holds an active admission, so the set moves as the shift moves.
- How do I rehearse a permission change before making it?Use the simulator in <Tool>Cirith Manager</Tool>. Describe the change, whether a role grant or removal, a care relationship added or ended, or a change to a patient's consent, and it runs against a pinned snapshot of the live relationships and returns two lists: the people who gain access and the people who lose it, each with the resolution path behind it. The simulation leaves the relationships unchanged, and applying the change is a separate step the platform records.
- How does emergency access work, and what does it record?A clinician with an active admission at the site invokes it with a stated reason, and the read reaches past the patient's cross-site partition and the site's sensitivity markings for a window a new site sets to four hours. An explicit block against that clinician still holds, and the window ends on its own or an administrator revokes it sooner. The entry records the clinician, the time, the site and the justification for the hospital's reviewer, who works it within a review clock set to 72 hours, while the patient's own access log shows the fact of the override with the hospital, the time, the purpose and the outcome.
- How does someone sign in on a machine four people have already used this shift?They select their name, or type their staff identity, then enter their PIN on the keypad, or tap a passkey or hardware key where the workstation takes one. Signing in signs out the person who used the screen before, so the session begins fresh under the new name and every note, order and result carries that person's name and the time.
- What is the idle timeout?Five minutes on a shared ward or clinical workstation and 30 minutes on a single-user office workstation, with a one-minute warning before the lock. A lock closes the screen while the session stands, so the same person signs back in with their PIN and their work is held for them. An administrator adjusts both periods per site in the access settings hosted in <Tool>Nexus Manager</Tool>, within the floor and ceiling the platform holds.
Safety
- Where in this system could a patient be harmed?The hazard log names each identified clinical hazard, its cause and the one mitigation that answers it: an action recorded against the wrong patient, a missed drug interaction, a discontinued medicine given, an unverified result acted on, a check waved through, a superseded dose read at another site, a critical result unseen, an identity error at registration, and a clinical entry lost during a service reduction. Each row reads Controlled where the mitigation stands wholly in the platform, and Monitored where it rests on human behaviour as well as a mechanism. A safety review revisits the log at a set cadence and after each material change.
- How does a medication order become a dose?Forge reviews the order against the patient's record and the catalogue before it is recorded, checking dose range, allergy, interaction and pregnancy, and a dose above the ceiling, a severe allergy match or a contraindicated drug in pregnancy holds placement until the prescriber records a reason that answers the finding. Each ordered dose then becomes a scheduled task in Quest with a due time. At the bedside the drug must be dispensed and received in the ward, the administering nurse verifies the five rights, a controlled drug records a named witness, and a high-alert drug takes a second check by a named member of staff.
- What happens to a withheld dose?You record it as Held and pick the reason from the list, and the record keeps the outcome and the reason together with your name and the time. Held is the entry for a clinical instruction not to give the dose, which is distinct from Refused, where the patient declines, and from Missed, which the record sets itself when a due time passes with no outcome recorded.
- How are critical results handled?A value falling in a critical range carries a critical flag as data on the result, so it stays with the value through verification and any correction. The flag raises an alert that Sentinel holds in its ledger and Raven delivers over the channel the recipient accepts, to the clinician responsible for the patient drawn from the care relationship and the staff on shift. The clinician acknowledges receipt, an unacknowledged alert escalates up a defined chain until a second responsible person answers it, and the record holds who was notified, the channel, the moment of delivery and the acknowledgement.
- Who authors an alert rule, and who can retire it?An administrator at the hospital sets the rules, and Pensieve raises an alert when a rule matches a clinical or operational event. The hospital owns the rules that fire and the people who respond, so authoring a rule and withdrawing one both sit with that named configuration owner rather than with Pensieve, which carries the ledger, the grouping, the acknowledgement and the escalation.
- What does an override record?An override records the check that fired by its own identifier, a reason drawn from the list that check offers, an optional note, the clinician who proceeded, and the moment the action went ahead. It is written in the same transaction as the action it clears, so a proceeded action always carries its reason, and the entry lands in Sentinel's ledger and in the patient record, searchable by patient, by clinician and by the check that fired. Each override clears one named check only, and it holds rather than clears when the actor lacks the override permission for that check.
- Who is responsible for clinical safety?Responsibility is shared, and the line runs between the mechanism and the judgement. Pensieve provides one patient record, a check before a risky action, verification held as two separate capabilities, an attributed entry and a searchable trail. The hospital owns the clinical decision, the content of each entry, the catalogue items, the alert rules, the access model and the people who act, and we recommend a named owner in the hospital for each configurable area.
Money
- Can a posted charge be edited?No. Vault freezes the price onto a charge when it is raised, using the price in force on the service date, and from that point the charge stays fixed. A correction is a new entry beside the original: a credit note that reverses a charge on a finalised invoice and preserves the invoice number, or a cancellation with a reason from a fixed list where the invoice is not yet finalised.
- Can the audit log be switched off?No. Vault writes the audit entry in the same step as the change it records, so every posting, correction, approval, claim movement and configuration change carries its own entry as it commits. Entries are added and then held as written, each carrying its position and a link to the entry before it, so the chain for a finance account reads continuously from the first entry to the last.
- How is a charge created?A charge becomes real the moment a chargeable order is placed. A clinician orders an item in Forge, and Vault reads the item from the charge master and writes a charge against that encounter, priced at the rate in force on the service date and carrying the item, quantity, category and payer split. Integrity checks run as the charge is written: a clean charge lands on the books, and a flagged one is held for review before it can sit on an invoice.
- How does one admission price out end to end in rupees?On the worked three-night admission, seven postings for room, consultations, a blood panel, an X-ray, a minor procedure, medication and consumables sum to a charges subtotal of INR 27,400. Tax of INR 420 falls on the pharmacy and consumable lines, giving an invoice total of INR 27,820, and the INR 10,000 deposit taken at admission is adjusted against it, leaving a balance of INR 17,820 for the patient to settle.
- How are packages and overruns handled?A care package fixes an agreed scope of services at one price before care begins, and Vault holds it as the price authority for the admission. Each charge is measured against that scope: an in-scope charge is absorbed at its line so the account holds at the package price, and a charge outside the scope, such as an extra night or an added investigation, is priced on its own at the rate in force on its service date and recognised as overrun the moment it is raised. The package price and the overrun read as two figures on one account, and overrun splits between payer and patient by the same terms as any charge.
- How do you model a payer?A payer is the party responsible for a charge, and the platform recognises five types: self-pay, insurer, third-party administrator, government scheme and corporate account. Each payer in a site's registry carries the terms that shape a bill, such as a credit limit, per-category sub-limits, a room rent cap, whether balance billing is allowed, and a claim deadline. An admission carries one or more payer allocations with exactly one primary at any moment, and self-pay sits as the residual so every bill settles to someone.
- What happens to a claim, state by state?A cashless claim opens, files a pre-authorisation that the payer approves or declines, then accrues charges in stay against the approved ceiling, with an enhancement filed if that ceiling runs low. The discharge bill is filed for sign-off, the final claim follows, and it ends settled in full, settled in part with documented deductions, declined on adjudication grounds, or repudiated on policy grounds, with disputed, resubmitted, appealed and written off as the routes between; closed is the single resting state. A reimbursement claim runs shorter: intimation, the patient pays in full and the hospital account closes there, documents are issued, the patient files, and the payer reimburses the patient.
- Does a tariff change today re-price last month?No. A charge resolves against the version in force on its service date and freezes that value, so a change made today opens a new version from its own effective date and reaches only charges raised from that date forward. When a ward moves its daily rate from INR 4,000 to INR 4,500 from the first of the month, a night before that date carries INR 4,000 and a night after carries INR 4,500.
- Who can see our financial data?Every read of a financial figure passes one authorisation decision made by Cirith Manager, which reads the person's role and their site together: the role sets which figures they may see, and the site sets the accounts those figures come from. The finance head reads the whole book, including the ledger, period totals and site-wide totals, while a billing clerk, cashier or insurance desk sees a narrower set fitted to their work, and a patient sees only their own account and statement. Every read and write writes an access entry naming who acted, which figures they touched and when, so the finance head can answer for any account who looked at the money.
Integration
- Which protocols does the bridge speak?orophin speaks the protocols the hospital's own machines speak: HL7 v2 messages, laboratory analyser feeds, CSV file drops and DICOM imaging references. It reads only the envelope of a message, its start, its end and its size, and forwards the content as it stands for Pensieve to parse and map. Imaging pixel data keeps its own route straight to the Pensieve imaging store, so the bridge carries only the study reference.
- Which integration protocols sit outside current support?DICOM image bytes on the message channel, HL7 v2 scheduling, document and financial message types, a FHIR release other than R4 at version 4.0.1, FHIR imaging and medication resources, a search Pensieve starts on a timer, a person's FHIR app session and a direct inbound link all sit outside the supported set. Each one names a supported path that does the same work: imaging travels its own route to the imaging store, appointments run in Gate and tasks in Quest, documents attach in Atlas and structured documents run through Glyph, charges and claims run in Vault, inbound runs push-driven, and every connection reaches the platform outward through the bridge's single path.
- What happens when a message is rejected?A delivery that errors, times out or meets a dropped link reverts to waiting, the bridge raises the attempt count and schedules the next try on a backoff. After a set number of attempts the message moves to held for review, where it is set aside rather than discarded, a counter records the depth and an alert draws a member of staff to resolve or re-send it in Westron.
- Can a message be replayed?Yes. On reconnect the bridge re-establishes its authenticated connection and replays every message still waiting or in transit, including one whose confirmation was outstanding when the link dropped. Pensieve de-duplicates by the message's stable identifier, so a replay records each message once and delivery stays exact.
- What does the bridge need on our network?A host on the hospital network for the bridge, reachable by the systems it serves, with outbound HTTPS on port 443 from that host to the Pensieve service and outbound HTTPS on port 443 from the imaging source to the imaging store. Hospital systems reach the bridge across the local network on port 2575 for HL7 v2 messaging and port 2576 for the laboratory analyser feed, plus a watched folder on a local share for any file-drop interface. The firewall opens for outbound traffic only, because the bridge's listeners bind to the hospital network and the platform opens no connection inward.
- What is installed inside the hospital, and what does it hold?One installation of orophin, the bridge, runs as a single binary on one machine on the site network, with one identity and one outbound channel. It holds its own certificate and token in the machine keystore, the narrow scope the platform has granted it, and the messages waiting in its durable local queue, encrypted on disk and cleared once Pensieve confirms the write. It holds no clinical vocabulary, maps no code, takes no access decision and makes no entry in the record, so an attacker who took the machine would reach the queued messages and nothing further.
- Which system is the record for each kind of data during coexistence?Each data type resolves to one authoritative holder, agreed when the connection is configured in Westron: demographics sit with the system that runs registration, encounters with the system that runs admissions, orders with the system where the clinician places them, lab results with the laboratory system that produces them, and charges with the system that runs billing. Imaging is the one shared function that is not negotiated, because Pensieve holds the study bytes in its imaging store. Pensieve is always authoritative for the clinical record in Atlas, consent and directives, access decisions and the access log, the audit trail, and the hospital model in Nexus Manager.
Platform
- How is the system put together?Pensieve is one platform rather than a set of separate products. Every tool resolves against one model of the hospital, its ontology, and shares the same foundations: one patient record, one authorisation decision, one audit entry written inside the committing transaction, one event log, and one path in and out. Only the record tool holds a patient's clinical data, so every other tool asks the record for it rather than keeping a copy.
- Can a tool bypass the permission check?No. Each system resolves access through the one authorisation decision rather than rules of its own, and that boundary holds by construction: an automated check runs across the whole platform on every build and refuses a build that reaches around the shared foundation. A reviewer reads the same boundary on any day, because the platform will not build in a shape that crosses it.
- Where does the data live?In four stores, all in the deployment's own region and country and all encrypted with the deployment's own keys: a PostgreSQL record store for the structured record, an object store for documents and imaging studies, a per-tenant secret store for the hospital's own credentials, and an immutable retention-locked log bucket for audit and access records. Every query is scoped to the tenant at the datastore itself, and Pensieve keeps no central copy, warehouse, analytics extract or training corpus. The patient's clinical record sits outside the tenancy structure and follows the patient to each site that treats them.
- How do you keep three sites configured consistently?One deployment serves the organisation and all of its sites, and the platform holds the layer beneath configuration centrally: the authorisation model, the registry of grantable permissions, and the shipped clinical terminology baseline every site codes against. Each site then authors its own operational configuration, its orderable catalogue, charge item definitions, tariffs, forms, workflows and roles, and adds terminology overrides that resolve ahead of the shipped baseline. Staff, roles, rosters, beds and access decisions stay scoped to the site they were made in.
- Which browsers work?A current mainstream web browser, kept current, on a workstation the hospital manages, with traffic over TLS 1.2 or above. This page pins no version, because the supported set moves as browsers release; the current matrix is published in the Pensieve support centre. There is no client to install: <Tool>Chamber</Tool>, the dock and the <Tool>image study viewer</Tool> all run in the browser.
Leaving
- Can we get our data out?Yes. A hospital's own users export its data at any time during the term, self-service and without asking Pensieve, and the export covers everything the hospital put in and everything the platform generated about it. Export is not gated on a ticket, an approval, an invoice or a notice period, and it proceeds regardless of a commercial dispute, a termination or non-payment.
- In what format does the data come out?Clinical records travel as HL7 FHIR R4 resource bundles with a structured CSV or JSONL extract alongside, images as DICOM with their study and series metadata, billing, inventory, workforce and master data as structured CSV or JSONL, generated documents as PDF with the structured data behind them, and the audit trail as structured JSONL. A data dictionary describing each file, column, code system and identifier, together with per-file checksums, accompanies every delivery so the receiving team can load and verify the export.
- How long does an export take?A self-service export during the term runs whenever the hospital wants it, with no notice period. On termination the sequence is fixed: an exit plan within five business days of notice, a trial export the hospital verifies before the termination date, the full export delivered within ten business days of the termination effective date, and a sixty day retrieval window in which the hospital verifies it and may request further exports.
- Who authorises an export?The hospital does. Its own users run an export from the platform at any time without asking Pensieve, and no ticket, approval, invoice or notice period stands in the way. On exit the hospital names the person who runs the exit on its side, and the deletion instruction that follows the export is the hospital's to issue.
- What happens to the audit chain when we leave?The one audit trail travels with the export as structured JSONL, carrying record access, amendments with their prior values, and disclosures, so the records keep their evidentiary integrity in the hospital's hands. It lands alongside the clinical, financial and imaging data with per-file checksums and the data dictionary, and it is included in the same way for a self-service export during the term.