CareFlow
Confidential healthcare operations platform used by a live medical practice.
What This Does
A confidential internal operating system used by a medical practice to coordinate call-center work, callbacks, referrals, schedules, tasks, training, and management reporting.
- —Moves high-volume practice operations out of scattered spreadsheets, chats, and manual handoffs into one role-based system
- —Gives agents, team leads, managers, and administrators different workflows without relying on UI-only permission checks
- —Supports healthcare-sensitive operations with MFA, audit-oriented controls, RLS-backed data access, and deployment runbooks
- —Improves follow-through on callbacks, escalations, shift handoffs, training, and internal support requests
CareFlow ops
Synthetic demo view - no PHI
27
Callback queue
priority follow-ups
2
Telebroad sync
events ready to replay
86%
Training
module completion
12
QA review
call logs scored
Role-scoped surfaces
RLS + MFA
Operational Proof
Live healthcare operations, confidential by design.
CareFlow is used inside a medical-practice environment. The public case study keeps patient-adjacent workflows private while still showing the system scale, role model, and controls behind the work.
The Challenge
Medical-practice call-center operations create a hard software problem: many roles, many handoffs, sensitive patient-adjacent data, and constant pressure to keep work moving without exposing more information than each user needs. The practice needed one system for callbacks, referrals, provider schedules, tasks, announcements, training, internal support, and management visibility.
The Solution
CareFlow provides a confidential, role-based operations platform for a live medical practice. The public case study intentionally avoids practice details and raw screenshots; the inspectable engineering story is the system design: Supabase Auth and RLS, MFA, audit-oriented controls, realtime collaboration, operational runbooks, and guarded AI assistance.
Architecture Decisions
Role-scoped React/Vite app shell for agent, team lead, manager, and admin workflows, with permissions enforced in both UI affordances and Supabase RLS
50+ Postgres tables covering callbacks, referrals, waitlists, provider schedules, training, documents, announcements, tasks, escalations, call logs, and corporate operations
Healthcare-sensitive controls: MFA enrollment, admin user management, audit trail surfaces, Turnstile-backed auth hardening, and deployment smoke-test runbooks
Realtime collaboration across chat, announcements, task/callback queues, and dashboard updates using Supabase subscriptions and TanStack Query invalidation
Telebroad phone-system ingestion path normalizes external call activity into operational queues, with webhook replay, sync history, and failure recovery controls documented
AI assistant guardrails reject medical-advice, diagnosis, treatment, and medication guidance prompts before model calls
Tech Stack
Key Features
Live medical-practice operations platform with agent, team lead, manager, and admin workflows
50+ Supabase tables with row-level security and audit-oriented controls for PHI-sensitive surfaces
Operational modules for callbacks, referrals, provider schedules, escalations, chat, tasks, training, QA, meetings, documents, and analytics
Telebroad phone-system ingestion with webhook event storage, replay, sync history, and recovery operations
MFA enrollment, admin user management, realtime messaging, and deployment/rollback/smoke-test runbooks
AI assistant guardrails block medical advice, diagnosis, treatment, and medication guidance requests