Korvix Health
Clinical records that can answer who read them
Everything a clinic or a hospital does in a day, from the front desk and the till to the ward and the payroll, encrypted value by value and auditable down to the reads that were refused.
Who this is for
Clinics, practice groups and digital health teams holding patient records in a market where the privacy rules are real and recent (POPIA in South Africa, the NDPR in Nigeria, Kenya's Data Protection Act) and the software on offer was mostly built for somewhere else. The specific person this is for is the one who has to answer "who opened this record?" because a patient asked, not because an auditor might.
Best fit
Clinics, practice groups and hospital departments that want a system built for their privacy law rather than adapted to it, and that want a partner in setting it up. Other systems read it as FHIR and analysers send results to it as HL7 v2, so it joins what a clinic already runs. Korvix is not a certified electronic health record; it is the record a clinic can answer for.
What it does
Inside Korvix Health
Encrypted one value at a time
Names, dates of birth and clinical notes are each encrypted separately, with keys held in a managed key service and tied to what the value is and whose it is. The database refuses to store a protected field as readable text, so a code path that forgets cannot quietly succeed.
Consent records what was agreed to
Not a checkbox but a version: the wording a patient agreed to is recorded alongside the agreement, so you can say what they were told rather than only that they said yes.
Withdrawal closes the record at once, and deletes nothing
Consent can be withdrawn immediately and the chart closes immediately, with one exception held open on purpose, described next: what would kill the patient stays visible. No record is removed. The tables do not permit deletion at all, because destroying a clinical record is a decision with retention law behind it and must not be reachable from an ordinary request.
A locked record still shows what would kill someone
A patient who has not consented, or who has withdrawn, does not thereby become invisible. Allergies, current medicines and the last recorded blood group stay on screen for whoever is treating them, with no reason to type and no step to complete, because putting a form between a collapsing patient and their penicillin allergy is the harm. The rest of the record takes a declared emergency: granted at once, since the patient is in front of you, and controlled afterwards instead. It names the clinician, carries their own words, expires within the hour, logs every read it allows, and goes on a register a colleague reviews. The chart says on its face that it was opened that way.
The clinic's name is on the notice, not ours
A consent notice that cannot say who holds the record, how to reach them and how long it is kept is not a notice. Each clinic sets its own controller details, its lawful basis for each purpose it processes for, and how long it keeps each class of record, with legal holds that stop a record ever being counted as due for disposal. Taking consent refuses until those details exist, because Korvix filling them in on a clinic's behalf would be taking a legal position it is not entitled to take.
Refused reads are recorded too
Someone trying to open a record they have no consent for is the event a clinical audit trail exists to catch. It is also the one most systems lose, because the refusal undoes the record of itself on the way out. Here it survives.
You can ask who opened a record
Every access to a patient's record (who, when, from where, and whether it worked) in one report, and downloadable as a file for an investigation or a regulator. It keeps answering after consent is withdrawn, because that is usually when someone asks.
Reading the access log is itself logged
It takes its own permission, separate from the one that opens charts: reading a record and reading who else read it are different acts, and an investigator should not need patient data to do their job. Opening the report appears in the report.
Korvix staff cannot read patient data
Our internal support connection is granted nothing at all on the clinical tables, not even read access. They are the only tables in the database where that is true, and it is the database enforcing it rather than our policy promising it.
A result nobody has read is on somebody's list
Ordering a test and recording what came back are two halves of one thing, and the second half is the dangerous one: a result that arrives and is never looked at is the most common way an outpatient clinic is sued. So a result raises work the moment it lands, and only a clinician signing it off clears it. The database refuses a signature on an order that has no result, so the queue cannot be tidied away. Critically abnormal results are due immediately.
The abnormal flag comes from your laboratory, not from us
Reference ranges vary by instrument, by age and by sex. We record the range and the high/low flag exactly as the lab reported them and calculate neither, because applying our own would be a clinical claim we are in no position to make. A blank flag reads as “the lab did not say” rather than as normal.
Patients who were told to come back and did not
A recall is one date. It appears on the recall list the day it falls due and leaves the moment the patient is next seen, with nobody having to close anything. The list carries a record number and a date and no clinical detail, so the person making the calls is not reading charts.
A diary, and a record of what a visit cost
Appointments are booked against a clinician and open into the consultation. Charges record what a patient owes and how it was settled, and Korvix never holds the money: the clinic takes cash or card at the desk exactly as it does today, and this records that it happened.
An emergency queue that orders by urgency, not arrival
Patients who walk in are triaged and the queue sorts by how urgent someone is and then by how long they have waited, never by who came first. The board names nobody at the level every role can see; opening an attendance is its own permission. Recording a death is its own permission, held by clinicians and never by the desk.
Wards, beds and admissions
Admit a patient to a bed, move them between beds and wards, discharge them. The bed board shows which beds are free and since when, and never who is in them. A board on a corridor wall that named patients would be a chart everyone walking past could read. Two people cannot be admitted to one bed and one person cannot be in two, because the database says so, not a check somebody remembered to write.
A patient can see what a clinician released, and nothing else
A patient asks for a code, sent once to the phone number already on their record; it opens a session of thirty minutes on their own record and no other. They see their appointments, and a laboratory result only after a clinician has signed it off and then chosen to release it, shown with the laboratory's own range and flag and none of our interpretation. They can ask for an appointment, which reaches the front desk as a task and the chart as a message; they cannot book one. Every read they make is written to their own access log, as theirs. The clinic switches the portal on; until it does, the portal answers nothing.
Installs on the clinic's computers as an app
Korvix Health installs from Edge or Chrome onto Windows, Mac and Chromebook computers as an app of its own, with an icon on the taskbar and shortcuts straight to Patients, the Diary and the Laboratory. It updates itself every time we release, so there is nothing for the clinic to reinstall. Nothing from a patient's record is kept on the computer by the app itself; only the entries waiting to be sent when a connection returns.
A ward that loses its signal does not lose its records
A consultation, a reading, a diagnosis, an allergy, a laboratory result or a signature on the drug chart made while the connection is down is kept on that device, with the time that was entered, and sent when the connection returns. The screen says so in plain words and asks the person not to enter it again, because the failure to avoid is not a lost record but a doubled one. Each of these writes carries a key the server remembers, so a record that reached us and lost its reply on the way back is not written twice. Records held on a device are sent under the person who made them and nobody else, which is why a colleague signing in on the same computer cannot send them. This is not an offline system: reading a chart needs a connection, and nothing is stored on a device except the writes waiting to go.
A drug chart that is signed, and never edited
On the ward, a nurse signs each dose as given (how much, when, by whom) or as withheld or refused, with the reason. A controlled medicine takes a second signature from a different person, and the database will not accept the same person twice. Nothing on the chart can be edited afterwards, because the drug is already in the patient: a wrong entry is struck through by a second entry that names it and says why, and both stay on the page. There is deliberately no grid of due times. The dose instruction is the prescriber's own words, and a schedule computed from words the software does not understand would be a chart with wrong cells; the chart shows what happened and when, and the next dose is the nurse's reading of the instruction, as it is on paper.
A theatre list, and a room that cannot be double booked
Cases are booked into a theatre against a surgeon, a start and an end, and the database refuses two cases in one room at once, because two coordinators on two screens will find the same gap. The board shows times, rooms and surgeons and names no patient; the case opens through the record. Recording the operation note is what marks a case done. A cancelled case keeps its slot and its reason is counted, so a directorate can see how much theatre time was lost and why, without any reason being written against a person on a screen the whole suite can read.
Imaging, from the request to the signature
A clinician requests a scan from the chart. The radiographer works a list of scans to take, records the study and the pointer to your PACS (Korvix keeps no images). The radiologist works a list of studies to report. The report then waits on the requesting clinician's signature, exactly as a laboratory result does, and an amended report goes back for a fresh one with both versions kept. A critical finding is flagged by the radiologist, never inferred from the wording.
A blood bank that will not crossmatch the wrong group
Units are registered with a donation number, a component, a group and an expiry, and shown expiring soonest first. A scientist crossmatching a unit to a patient is only offered units the patient can receive, and the database refuses any other pairing whatever the screen did. A reserved bag comes off the shelf; issuing, returning unused and releasing are three separate acts, so a bag that travelled is never recorded as one that sat in the fridge. What is reserved for whom is one list.
Purchasing that ends in a batch on the shelf
A ward asks for stock, and someone who did not ask approves or rejects it; the database refuses the same person doing both. An order goes to a supplier with a reference and a price per line, and each delivery is received against it line by line, becoming a stock batch with its own batch number and expiry the moment it arrives. What is still outstanding is worked out on the server, not typed in. Closing an order is a decision about the lines that never came.
A safety register that does not need the patient's permission
Anything that went wrong or nearly did is reported by whoever saw it, named or anonymously, with a category, a harm level and whether it reached a patient. The register shows those facts and nothing else; opening a report shows what happened, and that read is logged. An investigation closes with an outcome and a finding. Consent does not gate this, on purpose: an incident is a record about the clinic, and the argument is written in the code. Infections are counted separately, split on whether they started here or arrived.
Equipment and vehicles that cannot be in two places
A register of what the clinic owns, where each thing is, and when it is next due a service, with the overdue ones first. An asset can be booked out for maintenance or, if it is a vehicle, sent on a run, and the database refuses a second commitment that overlaps the first. The board shows a vehicle and a window; where it went and for whom is shown only when a job is opened, and that is logged.
A laboratory worklist, and specimens that are labelled
Ordered tests land on the laboratory's own list, sorted urgent first. Collecting a specimen gives it a label and a time, so a result can be traced to the tube it came from. Recording a result is the laboratory's permission, not reception's, because a haemoglobin is more consequential than a registration.
Pharmacy stock in batches, with expiry dates
Medicines are received in batches with a number and an expiry, dispensed from the batch that expires first, and adjusted with a reason when the count is wrong. A batch can be quarantined but never deleted. What is expiring soon appears on the front door for whoever holds the stock permission, and the ledger is the record a pharmacy inspector asks for.
Insurance claims, and what each insurer still owes
A visit that an HMO or insurer will pay for becomes a claim against that insurer, with its own reference, submitted and then paid, rejected or resubmitted. A rejection needs a reason and a payment needs an amount before either can be recorded. A summary by insurer and status says what is outstanding without opening any of them. Korvix does not settle claims and does not talk to any insurer's portal; it keeps the clinic's side of the record straight.
Messages to patients, and one place to see them all
A recall, a reminder or a note that a result is ready goes to a patient by SMS or email from inside their chart, with the wording and the destination recorded: where we did send, not where we would now. An inbox for the whole clinic shows everything that went out, whether it was sent, and the provider's reason when it was not. Sent is what we know; delivered is a claim the provider does not let us make. A patient's appointment request from the portal arrives in the same inbox; replies by SMS and email are next.
A till that takes nothing but the record number
Every charge still owed, oldest first, as a record number, what kind of thing it was for and how much. The cashier asks the patient for their number, finds their charges and records what they paid with. No name and no description reach the till, because the clinic's own words about a charge are chart content and the person taking the money is handed the charge rather than the record. Korvix never holds the money; this is the record that it was paid.
Everybody on the payroll, including the people who never touch a chart
The staff list is the people the clinic employs, not the people who can sign in: a cleaner, a driver or a security guard with no email address is on it, is paid from it and clocks in against it. Each person is paid by the month, the day or the hour, and a daily or hourly figure is multiplied by what the clock-in record actually holds for the period rather than typed in again. Draft a run and every member of staff with a figure is on it, with their pay and the basis it was worked out from copied at that moment, so a raise next month does not rewrite last month. Allowances and deductions are named lines — housing, PAYE, pension, a staff loan — rather than two lump figures, and the totals are maintained by the database so a payslip cannot show lines that add up to something other than what it pays. The person who drafts a run cannot approve it, and once approved nothing on it changes. Korvix computes no tax and moves no money: every deduction is the accountant's figure, and the transfer is the clinic's.
The pay run leaves as a spreadsheet, and the bank list with it
An approved run exports the transfer schedule the clinic hands its bank: each person, their bank, their account number and what they are owed. If anybody on the run has no account on file it says so with a count and no names, rather than quietly paying everyone else and leaving one person short. The payslips export separately with the working shown, so an accountant has the basic, the allowances, the deductions, the net and the hours attended for every person on one sheet. Setting pay for a whole clinic is a spreadsheet too: download the staff list with the figure each person is on now, change the amounts, and send it back. A blank amount is left alone rather than read as zero, and any row it cannot use is reported by its number while the rest are saved. Every figure set that way is recorded exactly as a typed one is.
A staff record that holds what an employer has to hold
Name, department, job title, when they started, and — kept encrypted value by value — date of birth, bank account and next of kin. The list of who works here is open to the practice; the encrypted half takes its own permission, and opening somebody's record is itself recorded, so anybody who reads a colleague's bank details can be asked why. Nobody is ever deleted: a payslip names the record, so leaving is a date rather than a removal.
Patients message the clinic on WhatsApp, and the assistant drafts the reply
A patient writes to the clinic on WhatsApp and it arrives on a screen, matched to their record by their own number. The assistant drafts a reply in the clinic's own words — its name, its hours, the number to ring in an emergency, the languages it answers in — and a member of staff reads it and decides whether to send it. **Nothing is ever sent automatically**, and there is no setting that makes it: a reply to a patient about their own care is a clinical message, and one nobody read before it left is not one a clinic can answer for. The assistant is never given the chart. It sees the clinic's instructions and the one message it is answering, so it cannot say anything about results, medicines or history because it does not have them. A fixed set of rules sits above whatever the clinic writes and cannot be overridden by it: never diagnose, never change a dose, never reassure somebody describing chest pain. Sending is refused more than 24 hours after the patient's own message, because WhatsApp does not carry a written reply after that and a platform that pretended otherwise would report a message as sent that nobody received.
Telemarketing to your own patients, about their own care
A campaign says what the clinic is ringing about and what to say: the hypertensives due a review, the mothers due a second dose, the patients a new service is for. Its list is built by record number and shows a record number and how the last call went, nothing more. Opening a call is what shows the name and the number, one patient at a time, behind the same consent that lets a reminder be sent, and that read is logged against the patient. Each call ends as reached, no answer, call back at a time, declined, or do not call again, and a patient who says the last of these is never listed by any campaign afterwards. There is no way to put anybody on a list who is not a patient with active consent, and no purpose outside their care.
A rota, and who actually turned up
Shift patterns, a week's rota published so people can rely on it, leave recorded so a shift cannot be rostered over it, and clocking in and out. Anybody on the staff list clocks themselves in under their own login and needs no permission to do it, because their own arrival is their own record; reception can clock in somebody whose hands are full, and the entry says which of the two pressed the button. Who is meant to be here and who is are kept as two lists, because the gap between them is what a manager opens the page to see. Leave shows colleagues that someone is away and nothing more; why is health information about a member of staff, and stays behind the management permission.
Roles that match how a clinic actually works
A clinician prescribes and orders tests but cannot dispense. A nurse gives medicines on the ward and signs for them, but cannot prescribe them or discharge anyone. A pharmacist works the dispensing queue, keeps the formulary and the stock ledger, and cannot open charts at all. The queue carries a medicine, a quantity, a prescriber and a record number, because someone filling a prescription is handed it rather than reading a chart. Reception registers patients, works the diary and makes the calls. A cashier works the till and sees a record number, a kind of charge and an amount, and nothing clinical. An accountant keeps the staff records, sets pay, runs payroll and reconciles the till against the stock ledger, and opens no chart at all. Every person signs in to a screen that shows their own job and nothing else, under their own name and role. Prescribing and dispensing must be separable in most jurisdictions, and a system that cannot tell them apart cannot produce a dispensing audit.
Other systems can read it as FHIR
Patients, encounters, conditions, allergies, observations, prescriptions, test orders, their reports and operations are available as FHIR R4, for reading only, under the same consent gate and the same audit trail as the chart, so an integration is not a way around either. It reads and never writes, by design: a clinical record is written by the people accountable for it, and an integration reads what they wrote. Every resource type is exercised end to end on every build.
Analysers and laboratory systems can send results as HL7 v2
A laboratory analyser, or the middleware in front of it, posts an ORU result message over HTTPS with an interface credential, and gets the standard acknowledgement back. Each result is filed against the open order whose specimen label the message quotes, through the same checks the laboratory screen applies: the order must be open, the patient's consent active, a number must have a unit. Anything that does not match, or is not final, is parked for the laboratory to review with the reason stated, and the acknowledgement says so. A resent message is answered the same way and files nothing twice. This is not a write API for clinical records; it is a second keyboard for one form.
Bring your records with you
A clinic moving from another system exports its patient list, its formulary and its staff as spreadsheets, and Korvix Health reads them in. The columns are matched for you, dates in the local order are understood, and the file is checked row by row before anything is written, with each problem named by row number. A patient row can carry the consent the clinic already holds, and it is recorded as consent, not as an import. Rows already present are left alone rather than duplicated, so the same file can be sent again after a correction. Each run leaves a receipt with counts and no patient details, and the person running it needs the record permission, because bringing a record in is writing one.
The assistant never reads your clinical notes
There is an assistant, and what it is not allowed to see is the point. It answers about one named patient at a time and has no way to search across your list. It is sent coded conditions, allergies and test results, never the free text a clinician wrote, which is the densest and least predictable information in a chart. It cannot diagnose or advise on treatment, and it is stored encrypted, so nobody at Korvix can read what it said about your patient.
The desktop app
Install Korvix Health on the clinic's computers
Korvix Health runs as an app of its own on Windows, Mac, Linux and Chromebook computers, and on tablets and phones, with an icon on the taskbar and shortcuts straight to Patients, the Diary and the Laboratory. It installs from the browser in one step and updates itself every time we release, so there is nothing to download and nothing to reinstall.
On every operating system
- Windows
- Open Korvix Health in Chrome or Edge and use the install icon at the right end of the address bar, or the Install button under Sign in.
- Mac
- Chrome or Edge as on Windows. In Safari, use File, then Add to Dock.
- Linux
- Chrome or Chromium: the install icon in the address bar, or the Install button under Sign in.
- Chromebook
- Chrome offers the install icon in the address bar; the app then appears in the launcher.
- iPad and iPhone
- In Safari, tap Share, then Add to Home Screen.
- Android
- In Chrome, tap the menu, then Install app, or accept the banner the page shows.
The app keeps nothing from a patient's record on the computer. Reading a chart needs a connection; entries made while the connection is down wait on that device and are sent once when it returns. That is the same behaviour as the browser version, in a window of its own.
What it costs
One price per clinic, and the first month free
No charge per seat and no charge per patient. A clinic pays once a month for the whole workflow, and every member of staff it needs is included, from clinicians to pharmacists to reception to the people who never touch a chart. The trial is a real month of the real product, not a demo with the useful parts removed.
Clinic
₦250,000per month
Billed monthly. The first month is free, and nothing is charged until it ends.
Clinic, annual
₦2,500,000per year
Ten months for twelve. The same free first month.
Nothing is taken automatically. Each month raises an invoice you pay through a link. There is no card kept on file and no silent renewal.
Cancelling is not a refund, and nothing is switched off. You keep the period you have paid for; the subscription ends when it ends.
An unpaid bill never withholds your records. A clinic is obliged to keep and produce patient records, and locking you out of them over an invoice would turn a commercial dispute into a clinical one. We do not do it.
The price you start on is the price you keep. It is stamped onto your subscription when you subscribe, so a later change to our list price does not change your bill.
Straight answers
How a clinic goes live, and what comes next
Korvix Health is built, reviewed by counsel and deployed. Going live is an onboarding with each clinic, and the parts that make up that onboarding are listed here by name.
Reviewed by Nigerian data protection counsel
A Nigerian data protection lawyer went through the product in September 2026, and every change they asked for in the software is built: a consent notice that names the clinic holding the record, and emergency access that keeps a patient's allergies and medicines visible rather than hiding a chart. Three documents complete the picture and are prepared with each clinic during onboarding: a data protection impact assessment, the documented mechanism for data leaving Nigeria, and the controller and processor agreements between the clinic and Korvix.
Hold your own encryption key
By default Korvix manages the keys. A clinic that needs a key it can revoke registers its own in AWS KMS and its data is encrypted under it from that moment, with records written before the switch still opening. It is set up together during onboarding, so the two halves, our permission to call the key and your policy allowing it, are proven before the first patient is registered.
Hosted in South Africa, with residency documented
Everything runs in Cape Town, on infrastructure built for exactly this data. For a Nigerian clinic the record leaves Nigeria, which the NDPA treats as something to document rather than assume; the transfer mechanism is one of the onboarding documents above, prepared for the clinic rather than left to it.
A patient portal each clinic switches on
Patients see their appointments and the results a clinician chose to release, and can ask for an appointment. They see no notes, diagnoses or prescriptions, and a phone number shared by two records gets no code at all, because the portal never guesses whose phone it is. It is off for every clinic until that clinic turns it on from its compliance page, as part of onboarding.
Replies from patients
Recalls, reminders and result notices go out by SMS and email today, and a patient's appointment request reaches the clinic through the portal. Replies by SMS and email into the same inbox are the next piece of the messaging work.
Built on the same platform you would be
Korvix Health uses the accounts, permissions, ledger and audit trail described on the main page: the same APIs, with no private access and no shortcuts. That is the clearest evidence we can offer that the platform underneath is real.
The other products
Tell us what you're building
If Korvix Health is close to what you need, the useful conversation starts with where it is not.