Booking a doctor's appointment should feel as easy as ordering a taxi — yet the system behind it must guard some of the most sensitive data a person has. Here is how we approach medical booking platforms for clinics, hospitals and pharmacies, from the data model to the reminder that stops a missed appointment.
The core entities
A booking platform revolves around five things: patients, clinicians, services (a 20-minute consultation, a 45-minute scan), availability (recurring schedules and exceptions) and appointments. Model availability as generated slots so that the booking flow becomes a simple query — "free slots for service X with clinician Y this week" — instead of calendar arithmetic at request time.
Never double-book
Two patients tapping the same slot at the same second is not a corner case; it is Monday morning. We rely on the database, not application logic, to make it impossible.
-- Prevent double booking with a unique constraint + optimistic concurrency
CREATE UNIQUE INDEX UX_Appointments_Clinician_Slot
ON Appointments (ClinicianId, SlotStartUtc)
WHERE Status IN ('Booked', 'Confirmed');The second insert fails, the API returns a friendly "that slot has just been taken" and offers the next one. Combined with a short soft-hold while the patient confirms, the experience feels instant and never lies.
Reminders that cut no-shows
Clinics we work with see no-show rates fall by a third when reminders are sent 24 hours and 2 hours before the appointment, with one-tap confirm or reschedule. We schedule them as background jobs the moment the booking is made, and cancel them automatically if it changes.
// Hangfire — SMS reminder 24h before an appointment
BackgroundJob.Schedule<IReminderService>(
s => s.SendAppointmentReminder(appointment.Id),
appointment.StartUtc.AddHours(-24) - DateTime.UtcNow);Twilio (or a local SMS gateway in Iraq) delivers the SMS; WhatsApp and push are used where the patient has opted in. Every message contains only the minimum: time, place, a reschedule link — never a diagnosis or a service name that reveals a condition.
Privacy by design
- Role-based access — receptionists see schedules, clinicians see their patients, administrators see audit logs; nobody sees everything by default.
- Encryption — TLS in transit, transparent data encryption at rest, column-level encryption for identifiers.
- Audit trail — every read of a patient record is logged with who, when and why.
- Data lifecycle — retention policies, right-to-erasure workflows and exports in machine-readable formats, as required by the UK GDPR and EU GDPR.
- Environment separation — no production data in test environments; synthetic patients only.
The patient app
We build the patient app in Flutter for iOS and Android with a focus on three screens: find a slot, my appointments and my documents. Large tap targets, plain language, Arabic RTL support and a font size that respects the phone's accessibility settings matter more than any animation. Clinicians get a tablet-friendly web app in Angular with a day view that loads in under a second.
Integrations
Booking rarely lives alone: we integrate with laboratory systems for results, with pharmacies for e-prescriptions, with Stripe or local providers for deposits, and with video platforms for telehealth. Each integration sits behind an interface so a clinic can switch suppliers without touching the core.
In short
Let the database enforce the hard rules, automate the reminders, encrypt and audit everything, and design the patient app for a nervous person in a hurry. That is what turns a booking system into a service patients trust.