MedRex for hospitals, clinicians, patients and investors

Pick who you are — the page introduces itself accordingly.

For hospital leadership

Run the whole hospital on a verifiable ledger.

MedRex is a complete hospital information system — OPD, IPD, labs, pharmacy, billing, fifteen departments and AB-PMJAY claims — where every clinical action is committed as a tamper-evident hash. Protected health information never touches the chain.

ABDM PMJAY NABH DPDP

AES-256-GCM at rest · default-DENY RBAC · per-facility row isolation · fail-closed integrity

15
Departments
3
Portals
23×29
RBAC matrix
12
Hash domains
Rex-hac · L3 anchor log Healthy
▌482921rex.encountersigned
▌482918rex.dischargecommitted
▌482915rex.tms.docPMJAY packet anchored
▌482912rex.credentialverified
▌·····Awaiting next block confirmation…

PHI encrypted off-chain — only the content hash is committed.

Built for ABDM & NABH certification DPDP-ready consent FHIR R4 boundary AB-PMJAY / TMS Postgres + per-facility RLS

Who it's for

One platform, four kinds of trust.

A hospital is many people who need to rely on the same record for different reasons. MedRex gives each of them proof, not just permission.

Hospital leadership

A complete HIS with an audit trail a regulator can resolve to the clinical fact — and per-facility isolation from day one.

  • 15 departments, one build
  • AB-PMJAY claims built in
  • Default-DENY RBAC
For hospitals

Clinicians

OPD to discharge without re-typing. Scanned documents are read, dictation is transcribed, and every note you sign is anchored.

  • Scan & OCR, voice notes
  • Bedside PMJAY pre-auth
  • Ledger explorer
For clinicians

Patients & families

Your timeline, medicines and reports in one bilingual app — with consent you grant and revoke, and an emergency card that works offline.

  • Care timeline & reminders
  • DPDP rights centre
  • Care companion, your record only
For patients

Investors & partners

The clinical layer of a five-chain healthcare stack, with a patent-pending approach to auditable AI and a claims wedge into every empanelled hospital.

  • Working end-to-end stack
  • Native Rust, Substrate PoA
  • Hospital pilot underway
Why now

The shift

From a siloed SQL database to a verifiable state machine.

A tertiary hospital is high-stakes and data-dense — delays or tampering can be fatal. MedRex moves the record off a centralized, mutable database and onto a cryptographically verifiable ledger. A resident cannot quietly alter a lab value in a note without invalidating its hash.

Legacy HIS

  • Centralized SQL — rows can be edited in place
  • Audit logs that live in the same database they audit
  • Trust granted by permission, not by proof
  • PHI copied out to third-party cloud AI

MedRex

  • Every action committed to a tamper-evident hash
  • An audit trail a regulator can resolve to the clinical fact
  • Default-DENY RBAC with segregation-of-duties
  • On-box AI — PHI never leaves the hospital

How it works

Committed to the ledger. Encrypted off it.

The chain carries proof, never the person. Here is the path every clinical document takes.

Encrypt in the enclave

PHI is sealed at rest with AES-256-GCM before it is ever stored. Raw records and biometrics never leave the enclave.

Content-address it

Each encrypted blob is keyed by its rex-hac content hash, and re-hashed on read — so any tampering fails closed.

Commit only the hash

The ledger records a registered rex-hac domain and content hash. Ciphertext and raw PHI stay off-chain, always.

Resolve to truth

Every action chains to a hash a regulator can resolve back to the exact clinical fact. Reproducible, and auditable.

The platform

One platform. Every department.

A shared clinical core carries the whole hospital information system; each specialty compiles in on top of it.

Modular by department

Each specialty is a self-contained module — an on-chain pallet plus an off-chain service. Compile in one department, or all fifteen.

On-box clinical AI

Document OCR, speech-to-text and vision run on the hospital's own GPUs. PHI never leaves for a cloud LLM, and every suggestion is grounded in the person's own record — propose-only, never autonomous.

AB-PMJAY, built in

A deterministic HBP rate engine over the NHA package master, plus the full pre-auth → claims → adjudication workflow, grounded in the real NHA guideline corpus.

Default-DENY RBAC

A 23-role × 29-module permission matrix that denies by default, with segregation-of-duties: whoever enters a result can't be the one who releases it.

Per-facility isolation

Multi-tenancy on Postgres Row-Level Security. A request-scoped tenant guard means one facility can never read another's rows.

Open by standard

A FHIR R4 boundary for export and interoperability, and a DPDP rights centre for consent, access, correction and erasure.

Fifteen departments

Specialty depth, one build.

Clinicians sign in once and pick their department at runtime — a single build serves every specialty on a shared clinical core.

Oncology Cardiology Nephrology Gastroenterology Pulmonology Critical Care Emergency Medicine Paediatrics Obstetrics & Gynaecology Neurology Urology Pathology Microbiology Anatomy Biochemistry
11 clinical specialties 4 diagnostic labs

Portals

Three portals, one secure sign-in.

Patients, clinicians and administrators each get a purpose-built surface — behind a single RBAC-routed login.

Patients
/pts · offline PWA

Care timeline, medicines and adherence, lab reports and discharge summaries, appointments and teleconsult, a care companion grounded in your own record, and an emergency card that works without internet.

Bilingual EN / हिन्दीConsent & data sharingOffline-first
Open patient app
Clinicians
/hpf · all 15 departments

OPD queue and token board, IPD and discharge, labs, pharmacy, OT and radiology, document scanning and OCR, voice transcription, AB-PMJAY, tumor board — and a ledger explorer that makes the chain visible at the bedside.

Scan & OCRVoice transcriptionLedger explorer
Open clinician portal
Facility admins
/hcf · facility console

Facility profile and HFR registry, runtime role-based access control, and empanelment and consent management for the whole hospital.

Runtime RBACEmpanelmentHFR profile
Open facility console
The Rex platform

One layer of a five-chain healthcare stack.

MedRex is L3 — clinical. It sits on a shared native-Rust foundation and composes with four sibling chains. No layer skips: L3 can't write without an L2 attestation, and L2 can't attest without an L1 zero-knowledge proof.

L1 · Identity
RexID
ZK biometric verification — no plaintext biometric ever leaves the device.
L2 · Certification
Trex
Issuer-of-record for credentials, licences and revocation.
L3 · Clinical
MedRex
Departments, records, PMJAY, portals and on-box AI.
You are here
L4 · Monetary
Rexon
Clinician rewards and patient healthcare-credit settlement.
L5 · Public health
Rexus
K-anonymous aggregates and de-identified epidemiology.
Foundation
rex-core
Shared types, the rex-hac content hash, cross-chain contract and ZK verifier.

For investors & partners

Why now, and why this.

India is wiring every hospital to ABDM and paying for care through AB-PMJAY. Both demand records that can be verified and AI that can be audited. MedRex was built for that world from the first commit.

  • A patent-pending approach to auditable AI

    Sovereign clinical data processing with re-derivable cryptographic commitments, so a hospital, insurer or regulator can replay and verify what the system did without seeing what it saw. Details under NDA.

  • A claims wedge into every empanelled hospital

    AB-PMJAY pre-auth and claims are where hospitals lose money and time. A deterministic package engine and an anchored packet trail make MedRex the obvious system of record.

  • Working software across the whole stack

    Six repositories, five Substrate chains and a shared foundation — native Rust, Aura + GRANDPA proof-of-authority — running end to end on synthetic data today.

  • On-box AI is the deployment model, not a feature

    OCR, speech and vision run on the hospital's own GPUs. That is what makes PHI sovereignty credible to a CMO — and what keeps the data moat inside the hospital.

At a glance

Every hospital will need to prove what its software and its AI did. MedRex makes that proof a by-product of care.

Layer
L3clinical
Departments
15live
Portals
3shipped
Anchor domains
12append-only
Patent pending Hospital pilot Bioelectrum Innovations

Public-safe summary. Claim details, figures and the pilot dossier are shared under NDA.

Security & compliance

Trust you can verify, not just take on faith.

Privacy isn't a policy bolted on afterward — it's the architecture. Here is what that buys a hospital.

PHI never on the chain

A hard platform invariant, enforced in code: an on-chain patient registry that could have held demographics was removed rather than trusted to stay empty.

Encrypted, content-addressed at rest

AES-256-GCM on every blob, keyed by its content hash and re-hashed on read — so tampering fails closed instead of passing silently.

Fail-closed credential gate

An action carrying an invalid or revoked credential returns 403 and writes an audit event. The safe answer is always "no".

Least-privilege by default

Default-DENY RBAC across 23 roles and 29 modules, with segregation-of-duties approvals — and a production node that refuses to start without its signing secret.

Zero-knowledge identity

Biometric identity is proven with Groth16/BN254 at L1. On the roadmap: zero-knowledge AB-PMJAY eligibility proving.

Questions

Straight answers.

Is any patient data stored on a blockchain?

No. The chain holds only lifecycle state and content hashes. Records are encrypted with AES-256-GCM and stored off-chain in the hospital's own database, isolated per facility.

Does the AI send our data to a cloud model?

No. OCR, speech-to-text and vision run on the hospital's own GPUs. Suggestions are grounded in the person's own record and are propose-only — a clinician signs, or nothing is committed.

Can we run a single department first?

Yes. Each department is a self-contained module, so a deployment can compile in one specialty — oncology, say — and add others later without changing the shared clinical core.

Is MedRex ABDM and NABH certified?

It is built for certification: an ABDM-aligned identity and consent model, NABH-style segregation-of-duties, and a FHIR R4 boundary. Certification status is shared with prospective sites directly.

What about AB-PMJAY claims?

Pre-auth, claims and adjudication are built in, over a deterministic HBP rate engine and the NHA package master. Every claim packet is anchored, so the trail is verifiable end to end.

What do patients actually get?

A bilingual, offline-first app with their care timeline, medicines, reports, appointments and an emergency card — plus consent controls to grant and revoke who sees what.

Next step

See MedRex on your ward.

A guided walkthrough on synthetic data — a patient's timeline, an AB-PMJAY claim and the anchor log, end to end. Hospitals, clinicians, patients and investors welcome.