Healthcare Operations

CareFlow

Confidential healthcare operations platform used by a live medical practice.

What This Does

A confidential internal operating system used by a medical practice to coordinate call-center work, callbacks, referrals, schedules, tasks, training, and management reporting.

  • —Moves high-volume practice operations out of scattered spreadsheets, chats, and manual handoffs into one role-based system
  • —Gives agents, team leads, managers, and administrators different workflows without relying on UI-only permission checks
  • —Supports healthcare-sensitive operations with MFA, audit-oriented controls, RLS-backed data access, and deployment runbooks
  • —Improves follow-through on callbacks, escalations, shift handoffs, training, and internal support requests

CareFlow ops

Synthetic demo view - no PHI

Ops

27

Callback queue

priority follow-ups

Ops

2

Telebroad sync

events ready to replay

Ops

86%

Training

module completion

Ops

12

QA review

call logs scored

Role-scoped surfaces

RLS + MFA

Agents
CallbacksTasksScripts
Team leads
EscalationsQAShift handoff
Managers
TrainingMeetingsAnalytics
Admins
MFARLS rolesAudit trail

Operational Proof

Live healthcare operations, confidential by design.

CareFlow is used inside a medical-practice environment. The public case study keeps patient-adjacent workflows private while still showing the system scale, role model, and controls behind the work.

Live
Use
50+
RLS Tables
45
Route Surfaces
4
Roles
31
Test Files

The Challenge

Medical-practice call-center operations create a hard software problem: many roles, many handoffs, sensitive patient-adjacent data, and constant pressure to keep work moving without exposing more information than each user needs. The practice needed one system for callbacks, referrals, provider schedules, tasks, announcements, training, internal support, and management visibility.

The Solution

CareFlow provides a confidential, role-based operations platform for a live medical practice. The public case study intentionally avoids practice details and raw screenshots; the inspectable engineering story is the system design: Supabase Auth and RLS, MFA, audit-oriented controls, realtime collaboration, operational runbooks, and guarded AI assistance.

Architecture Decisions

01

Role-scoped React/Vite app shell for agent, team lead, manager, and admin workflows, with permissions enforced in both UI affordances and Supabase RLS

02

50+ Postgres tables covering callbacks, referrals, waitlists, provider schedules, training, documents, announcements, tasks, escalations, call logs, and corporate operations

03

Healthcare-sensitive controls: MFA enrollment, admin user management, audit trail surfaces, Turnstile-backed auth hardening, and deployment smoke-test runbooks

04

Realtime collaboration across chat, announcements, task/callback queues, and dashboard updates using Supabase subscriptions and TanStack Query invalidation

05

Telebroad phone-system ingestion path normalizes external call activity into operational queues, with webhook replay, sync history, and failure recovery controls documented

06

AI assistant guardrails reject medical-advice, diagnosis, treatment, and medication guidance prompts before model calls

Tech Stack

React 18
TypeScript
Vite
Supabase
TanStack Query
shadcn/ui
Vercel
AI SDK

Key Features

01

Live medical-practice operations platform with agent, team lead, manager, and admin workflows

02

50+ Supabase tables with row-level security and audit-oriented controls for PHI-sensitive surfaces

03

Operational modules for callbacks, referrals, provider schedules, escalations, chat, tasks, training, QA, meetings, documents, and analytics

04

Telebroad phone-system ingestion with webhook event storage, replay, sync history, and recovery operations

05

MFA enrollment, admin user management, realtime messaging, and deployment/rollback/smoke-test runbooks

06

AI assistant guardrails block medical advice, diagnosis, treatment, and medication guidance requests