Skip to main content

RIS / LIS / PACS Healthcare Platform

A backend for a diagnostic centre that follows a patient from registration through imaging or lab work to a verified report. Built by a team at Rivon AI. I was a sub-lead on it, owning quality: finding bugs, bottlenecks and security gaps, writing them up as tickets for developers, and contributing to R&D.

  • Rivon AI
  • Sub-Lead
  • QA & Defect Reporting
  • R&D

The Problem

Diagnostic centres lose orders between reception and the modality, leave reports unassigned or late, issue lab results with no critical-value escalation, and keep little audit history on who touched patient data. The platform covers the whole path in one system.

The System

  • Reception — Patient registration with generated record numbers, orders and invoices on one screen with contract pricing and supervisor-approved discounts, and a report-status board.
  • Radiology — Technician acknowledgment, case assignment by radiologist workload, a reporting queue, verification, and addenda that create a new report version instead of editing the old one.
  • Pathology — Specimen collection with barcoded labels, section acknowledgment, analyzer or manual results, checks against age- and gender-specific ranges, and critical-value alerts with acknowledgment tracking.
  • Access control — OAuth 2.0 with PKCE, short-lived JWTs with a token blacklist, tracked sessions, and a permission model that goes from role to module, form, button and endpoint, combined with relationship rules, so the frontend can render only what a user may see.
  • Auditability — Soft deletes everywhere, audit logs on critical operations, versioned reports and password history, built for healthcare review.

My Contribution

I led quality on this project as a sub-lead. I tested the system for functional defects, performance bottlenecks and loopholes in the authorization and workflow rules, documented each finding with reproduction steps, and created tickets and assigned them to the developers who owned the affected modules. I also took part in research and design discussions before implementation.

I did not write the core of this backend and I do not present it as mine. The value I added was finding what was wrong with it before users did.

Scale

About 73 database tables, 50+ Alembic migrations, three departments, and a test suite of over 150 files across contract, security, edge-case and integration layers. The data in the repository is mock data only.

Technology Stack

BackendPython 3.11, FastAPI, Pydantic v2, SQLAlchemy 2.0 async, asyncpg, Alembic
DatabasePostgreSQL
SecurityOAuth 2.0 + PKCE, JWT, bcrypt, token blacklist, RBAC + relationship-based rules
DocumentsReportLab PDF reports and invoices, barcode labels, Excel export
Qualitypytest, pytest-asyncio, contract and security test suites, Docker