MedRex for hospitals, clinicians, patients and investors
Pick who you are — the page introduces itself accordingly.
Run the whole hospital on a verifiable ledger.
MedRex is a complete hospital information system — OPD, IPD, labs, pharmacy, billing, fifteen departments and AB-PMJAY claims — where every clinical action is committed as a tamper-evident hash. Protected health information never touches the chain.
AES-256-GCM at rest · default-DENY RBAC · per-facility row isolation · fail-closed integrity
PHI encrypted off-chain — only the content hash is committed.
Less typing. More medicine.
One sign-in, your department, your queue. Scan a referral and it is read for you. Dictate a note and it is transcribed on the hospital's own machines. File an AB-PMJAY pre-auth from the bedside. Every order and note you sign is anchored — so the record is yours to stand behind.
On-box AI is propose-only: it drafts, you decide, and your signature is what gets committed.
A ledger explorer at the bedside shows what was committed, and when.
Your health record. In your hands.
See your care timeline, medicines, lab reports and discharge summaries in one place. Decide who can see what, and take it back whenever you like. Carry an emergency card that works with no internet at all — in English or हिन्दी.
Your records are encrypted at rest. Nobody — not even the hospital's AI — sends them to an outside cloud.
- TodayMedicine reminder · 2 taken, 1 dueAdherence 94% this week
- MonLab report ready · HaemogramExplained in plain language
- FriDischarge summary · Ward 3BShared with your family doctor — you can revoke
- AnytimeEmergency cardBlood group, allergies, contacts — works offline
Ask the care companion — it answers only from your own record.
Sovereign clinical data. Auditable AI.
MedRex is the clinical layer of Rex — a five-chain, native-Rust healthcare stack built for India's ABDM and AB-PMJAY era. Identity, consent, records and AI inference each leave a re-derivable cryptographic commitment, so any stakeholder can verify what the system did without seeing what it saw.
Working software, not a whitepaper: the full stack runs on synthetic data today, end to end.
The thesis
Every hospital will need to prove what its software and its AI did. MedRex makes that proof a by-product of care.
Public-safe summary. Claim details, figures and the hospital pilot dossier are shared under NDA.
Who it's for
One platform, four kinds of trust.
A hospital is many people who need to rely on the same record for different reasons. MedRex gives each of them proof, not just permission.
Hospital leadership
A complete HIS with an audit trail a regulator can resolve to the clinical fact — and per-facility isolation from day one.
- 15 departments, one build
- AB-PMJAY claims built in
- Default-DENY RBAC
Clinicians
OPD to discharge without re-typing. Scanned documents are read, dictation is transcribed, and every note you sign is anchored.
- Scan & OCR, voice notes
- Bedside PMJAY pre-auth
- Ledger explorer
Patients & families
Your timeline, medicines and reports in one bilingual app — with consent you grant and revoke, and an emergency card that works offline.
- Care timeline & reminders
- DPDP rights centre
- Care companion, your record only
Investors & partners
The clinical layer of a five-chain healthcare stack, with a patent-pending approach to auditable AI and a claims wedge into every empanelled hospital.
- Working end-to-end stack
- Native Rust, Substrate PoA
- Hospital pilot underway
The shift
From a siloed SQL database to a verifiable state machine.
A tertiary hospital is high-stakes and data-dense — delays or tampering can be fatal. MedRex moves the record off a centralized, mutable database and onto a cryptographically verifiable ledger. A resident cannot quietly alter a lab value in a note without invalidating its hash.
Legacy HIS
- Centralized SQL — rows can be edited in place
- Audit logs that live in the same database they audit
- Trust granted by permission, not by proof
- PHI copied out to third-party cloud AI
MedRex
- Every action committed to a tamper-evident hash
- An audit trail a regulator can resolve to the clinical fact
- Default-DENY RBAC with segregation-of-duties
- On-box AI — PHI never leaves the hospital
How it works
Committed to the ledger. Encrypted off it.
The chain carries proof, never the person. Here is the path every clinical document takes.
Encrypt in the enclave
PHI is sealed at rest with AES-256-GCM before it is ever stored. Raw records and biometrics never leave the enclave.
Content-address it
Each encrypted blob is keyed by its rex-hac content hash, and re-hashed on read — so any tampering fails closed.
Commit only the hash
The ledger records a registered rex-hac domain and content hash. Ciphertext and raw PHI stay off-chain, always.
Resolve to truth
Every action chains to a hash a regulator can resolve back to the exact clinical fact. Reproducible, and auditable.
The platform
One platform. Every department.
A shared clinical core carries the whole hospital information system; each specialty compiles in on top of it.
Modular by department
Each specialty is a self-contained module — an on-chain pallet plus an off-chain service. Compile in one department, or all fifteen.
On-box clinical AI
Document OCR, speech-to-text and vision run on the hospital's own GPUs. PHI never leaves for a cloud LLM, and every suggestion is grounded in the person's own record — propose-only, never autonomous.
AB-PMJAY, built in
A deterministic HBP rate engine over the NHA package master, plus the full pre-auth → claims → adjudication workflow, grounded in the real NHA guideline corpus.
Default-DENY RBAC
A 23-role × 29-module permission matrix that denies by default, with segregation-of-duties: whoever enters a result can't be the one who releases it.
Per-facility isolation
Multi-tenancy on Postgres Row-Level Security. A request-scoped tenant guard means one facility can never read another's rows.
Open by standard
A FHIR R4 boundary for export and interoperability, and a DPDP rights centre for consent, access, correction and erasure.
Fifteen departments
Specialty depth, one build.
Clinicians sign in once and pick their department at runtime — a single build serves every specialty on a shared clinical core.
Portals
Three portals, one secure sign-in.
Patients, clinicians and administrators each get a purpose-built surface — behind a single RBAC-routed login.
Care timeline, medicines and adherence, lab reports and discharge summaries, appointments and teleconsult, a care companion grounded in your own record, and an emergency card that works without internet.
Open patient appOPD queue and token board, IPD and discharge, labs, pharmacy, OT and radiology, document scanning and OCR, voice transcription, AB-PMJAY, tumor board — and a ledger explorer that makes the chain visible at the bedside.
Open clinician portalFacility profile and HFR registry, runtime role-based access control, and empanelment and consent management for the whole hospital.
Open facility consoleOne layer of a five-chain healthcare stack.
MedRex is L3 — clinical. It sits on a shared native-Rust foundation and composes with four sibling chains. No layer skips: L3 can't write without an L2 attestation, and L2 can't attest without an L1 zero-knowledge proof.
For investors & partners
Why now, and why this.
India is wiring every hospital to ABDM and paying for care through AB-PMJAY. Both demand records that can be verified and AI that can be audited. MedRex was built for that world from the first commit.
-
A patent-pending approach to auditable AI
Sovereign clinical data processing with re-derivable cryptographic commitments, so a hospital, insurer or regulator can replay and verify what the system did without seeing what it saw. Details under NDA.
-
A claims wedge into every empanelled hospital
AB-PMJAY pre-auth and claims are where hospitals lose money and time. A deterministic package engine and an anchored packet trail make MedRex the obvious system of record.
-
Working software across the whole stack
Six repositories, five Substrate chains and a shared foundation — native Rust, Aura + GRANDPA proof-of-authority — running end to end on synthetic data today.
-
On-box AI is the deployment model, not a feature
OCR, speech and vision run on the hospital's own GPUs. That is what makes PHI sovereignty credible to a CMO — and what keeps the data moat inside the hospital.
At a glance
Every hospital will need to prove what its software and its AI did. MedRex makes that proof a by-product of care.
Public-safe summary. Claim details, figures and the pilot dossier are shared under NDA.
Security & compliance
Trust you can verify, not just take on faith.
Privacy isn't a policy bolted on afterward — it's the architecture. Here is what that buys a hospital.
PHI never on the chain
A hard platform invariant, enforced in code: an on-chain patient registry that could have held demographics was removed rather than trusted to stay empty.
Encrypted, content-addressed at rest
AES-256-GCM on every blob, keyed by its content hash and re-hashed on read — so tampering fails closed instead of passing silently.
Fail-closed credential gate
An action carrying an invalid or revoked credential returns 403 and writes an audit event. The safe answer is always "no".
Least-privilege by default
Default-DENY RBAC across 23 roles and 29 modules, with segregation-of-duties approvals — and a production node that refuses to start without its signing secret.
Zero-knowledge identity
Biometric identity is proven with Groth16/BN254 at L1. On the roadmap: zero-knowledge AB-PMJAY eligibility proving.
Questions
Straight answers.
Is any patient data stored on a blockchain?
No. The chain holds only lifecycle state and content hashes. Records are encrypted with AES-256-GCM and stored off-chain in the hospital's own database, isolated per facility.
Does the AI send our data to a cloud model?
No. OCR, speech-to-text and vision run on the hospital's own GPUs. Suggestions are grounded in the person's own record and are propose-only — a clinician signs, or nothing is committed.
Can we run a single department first?
Yes. Each department is a self-contained module, so a deployment can compile in one specialty — oncology, say — and add others later without changing the shared clinical core.
Is MedRex ABDM and NABH certified?
It is built for certification: an ABDM-aligned identity and consent model, NABH-style segregation-of-duties, and a FHIR R4 boundary. Certification status is shared with prospective sites directly.
What about AB-PMJAY claims?
Pre-auth, claims and adjudication are built in, over a deterministic HBP rate engine and the NHA package master. Every claim packet is anchored, so the trail is verifiable end to end.
What do patients actually get?
A bilingual, offline-first app with their care timeline, medicines, reports, appointments and an emergency card — plus consent controls to grant and revoke who sees what.
Next step
See MedRex on your ward.
A guided walkthrough on synthetic data — a patient's timeline, an AB-PMJAY claim and the anchor log, end to end. Hospitals, clinicians, patients and investors welcome.