How it works

What SunarHealth does, in full.

The detail behind the product page: every feature that is built, the mechanisms that protect a patient record, what is deliberately refused, and the questions clinics ask before signing up. Written to be checked — each claim here is enforced somewhere in the running system.

What it does

Every item below is built and running. Where something is refused rather than approximated, it is in its own section further down.

Appointments and a live queue

A slot is claimed in the database itself, so two people at two desks cannot sell the same seat, and cancelling releases it at once. The waiting-room board and the appointment move together — nobody is ever left on the board with no way to take them off it.

A consultation note that stays put

Signing freezes the note and everything attached to it. A later result goes on the patient plus a dated addendum; the original text never changes, and an older note still verifies years afterwards under the rules it was signed with.

Prescriptions, signed with the note

The prescription is signed in the same moment as the note, so a refusal — a missing registration number, an unanswered allergy warning — stops the whole signature and leaves the note editable, rather than producing a signed note with a draft prescription hanging off it.

The interaction check covers a curated list and says so on every panel, including an empty one. A clean panel is not a clean bill of health, and the software will not imply that it is. Schedule X prescribing is refused outright.

Pharmacy that dispenses the right box

Stock moves off the shelf by earliest expiry first, so the batch about to expire goes before the one that will not. Schedule H1 has a real register behind it — an actual book the software keeps, not a report generated the day an inspector asks.

Lab and imaging, with a gate

A result is not visible to the patient until a clinician has reviewed and released it. The dangerous half of a laboratory result is the one nobody read, so the gate is a database constraint rather than a rule in a service somebody moves.

Built out for eye clinics

Twenty-two pre-consultation tests with left and right recorded as structure rather than as a note, a low-vision assessment in the patient’s own words, and the one rule that fires on something the clinic did — drops given with a raised pressure.

Billing, GST and the books

The charge sheet becomes an ordinary tax invoice, so payments, statements, reminders, credit notes and GSTR-1 need no clinical special case. Tax treatment is worked out per line from the item and the setting — the same tablet is taxable to a walk-in and exempt to an in-patient.

Cost of goods comes off the shelf, not off the bill, so a clinic’s margin is its real one.

An app for the patient

Appointments, bills, prescriptions, released results — and the access log, so a patient can see who opened their record and why. It opens on a public welcome and a clinic search; the phone number is asked for at booking, or at their own records, and nowhere before.

Teleconsultation, recorded honestly

The clinic uses whatever call it already uses. SunarHealth records the mode, the consent, the identity check and the queue entry, and applies a stricter drug gate to a remote consultation. It does not carry the video, and does not pretend to.

ABHA and FHIR R4

An ABHA number can be recorded, and a record projected as FHIR R4 — one document per care context, with coded diagnoses. A number typed at a counter is treated as a claim, never as a proven identity, and is never used as a lookup key. Full gateway participation is not live.

Certificates and numbered registers

Three numbered books, kept the way somebody outside the clinic will read them — whose first question is always what happened to number 412. Certificates carry a seal that a reader with no login can check.

Panels, packages and recalls

Corporate and TPA panels with their own pricing and credit limits, courses of care sold as a package and drawn down visit by visit, and clinical follow-up reminders sent at an hour a person would want to receive them.

How a patient’s record is protected

Mechanisms rather than badges. Each of these is enforced somewhere a reader could go and check, which is the only kind of security claim worth printing.

Separated by the database, not by the app

Postgres row-level security is enabled and forced, and the application connects as a role that cannot bypass it. A query that forgets to name the clinic returns nothing — rather than returning somebody else’s patients.

A key per patient, so erasure is real

Each record is encrypted under its own key. Destroying that key erases the patient from the database, its replicas, its backups and the document store at the same moment. Deleting the rows afterwards is housekeeping.

Every read has a stated purpose

A clinical route must declare why it is reading a patient record, and the response is stripped to an allowlist if it does not. The build fails on a route that skips it, so the access log cannot quietly develop a blind spot.

Sharing needs consent, and it expires by itself

A record crosses between clinics only through a consent the patient gave, recorded in a ledger with a window on it. The window is recomputed on every read, so an expiry can never be widened by a job that failed to run.

Support that cannot read the clinical data

The operator console is a different database role with the read revoked at the Postgres level — not a filter in a response that somebody can forget to apply. A live support view of a clinic needs that clinic to grant a time-boxed window first.

Everything third-party is written down

The register of sub-processors is part of the source code, and the build fails if a new outbound service appears without an entry. Read it at the sub-processor register.

What it refuses to do

A product page that lists only capabilities gives a clinician nothing to calibrate against. These are deliberate, and each one is written down with its reason.

No compliance badge

No certification is claimed — not DPDP, not ISO 27001, not HIPAA. The current position is derived from evidence inside the running system and published at the privacy notice, and it names what has not been verified as plainly as what has. Overstating this to a doctor is treated here as worse than saying nothing.

No complete drug-interaction database

We hold a curated list, not a licensed one, and every safety panel says so — including when it finds nothing. Schedule X prescribing is refused outright rather than approximated, because the register, licence record and retention it requires are not built.

No ratings, no ranking, no sponsored placement

The clinic directory is sorted by name. Every one of those features would either rank clinics using clinical data, or invent a number a clinic then gets judged on.

No marketing campaigns to patients

A recall is a clinical instruction from a clinician to a named patient, not a cohort to send an offer to. A campaign builder was asked for, and refused.

We do not carry the video call

Teleconsultation records the mode, the consent, the identity check and the drug gate around a call the clinic makes on its own tools.

Questions

The answers a clinic asks for before it moves its practice onto something new.

What is SunarHealth?

SunarHealth is clinic software for Indian outpatient practices. One system covers appointments and a live waiting-room queue, the consultation note, prescriptions with a drug-safety check, pharmacy dispensing, laboratory and imaging orders, eye and low-vision workups, GST billing, and a patient app for appointments, bills and prescriptions. It is a product of SunarCode and runs in a web browser.

Who is it for?

Outpatient clinics in India: single-doctor practices, polyclinics, and eye clinics in particular — the eye workup and low-vision assessment are built out to twenty-two tests with laterality recorded as structure rather than as a note.

Can a patient book an appointment without creating an account?

Yes. Anyone can search the public clinic directory, open a clinic, read its doctors and specialities and see when each is next free, with no account at all. A phone number is asked for at the moment the appointment needs an owner, and once — not before.

Can a consultation note be changed after it is signed?

No. A signed note is frozen, and so are the documents attached to it. A correction is a dated addendum that names its author; the original text never changes. This is enforced in three places — the service layer, the database write, and a Postgres grant that revokes UPDATE and DELETE from the application role.

Is one clinic able to see another clinic’s patients?

No. Every clinic’s rows are separated by Postgres row-level security, which is both enabled and forced, and the application connects as a role that cannot bypass it — so a query that forgot to name the clinic returns nothing rather than somebody else’s records. A record can cross between clinics in exactly one way: the patient consents, the consent is written to a ledger with a window on it, and the window is re-checked on every single read.

What happens when a patient asks to be erased?

Each patient’s record is encrypted under a key of its own. Erasing the patient destroys that key, which reaches the database, its replicas, its backups and the attachment store at the same moment — deleting rows afterwards is cleanup, not the erasure. Because a restore would otherwise resurrect an erased patient, the evidence of the erasure is kept outside the database that gets rolled back.

Does SunarHealth support ABDM and ABHA?

An ABHA number can be recorded against a patient, and a clinical record can be projected as FHIR R4 — one document per care context, with coded diagnoses. An ABHA number typed at a counter is treated as a claim rather than as a verified identity, and the software will not use it as a lookup key. Full gateway participation is not live.

Does it check for drug interactions?

It checks a curated list, and it tells the prescriber so on every panel — including when the panel is empty. A clean panel from a partial checker is not evidence that a combination is safe, and the software says that rather than implying the opposite by staying quiet. Schedule X drugs are refused outright, because the register and licence record they legally require are not built.

Does it work when the internet drops?

The console keeps rendering and tells you plainly what it cannot currently reach. It does not pretend a stale screen is a live one — a screen that states something false while it loads is treated here as worse than a slow one.

What does it cost, and is there a free plan?

There is no free plan and no trial. The ladder starts at ₹999 a month and every rung on it is paid. No plan has ever gated a clinical feature, and a lapsed or cancelled subscription cannot refuse a note, a prescription or a dispensed box — the clinic can always practise medicine.

Is SunarHealth certified or compliant with DPDP, ISO 27001 or HIPAA?

No certification is claimed. The current position is derived from evidence inside the running system and published at the privacy notice, and it says what has and has not been verified. Claiming a rung we have not reached is treated as a defect here, not as marketing.

What it costs

Three paid tiers and an enterprise conversation. There is no free plan and no trial.

The ladder starts at ₹999 a month and every rung on it is paid. The current prices, what each tier includes and how a subscription is taken are on the pricing page — which reads them live, because a price is something an operator can change without a deploy and a number written into a marketing page would be right until the first time somebody did.

A subscription can lapse. Medicine cannot.

There is no plan-based guard anywhere on a clinical route. Not one tier withholds signing a note, dispensing a box or seeing a patient, and a lapsed or cancelled subscription changes nothing except the screen that says you have no plan. What follows is a conversation, not a lock-out.