All BlueprintsHealth

Therapy intake and consent

Intake for a small therapy practice: new clients fill in one form over as many evenings as they need, consent is recorded against the wording they actually read and the date they read it, and a practitioner sees the clients who are theirs and nobody else's.

L2–L4Level range
8Sprints
35Tasks
Backend and frontendBuilt as

What you’ll build.

By the last sprint

An intake and consent system for a therapy practice. Clients fill in a long form over as many sittings as they need, agree to terms they can still read a year later, withdraw that agreement and watch it take effect, and see everybody who has opened their record. Their own therapist reads it; the one at the next desk is refused.

What you’ll learn.

Each sprint is built around one skill. You show you have it in a pull request your team reviews, then explain it in a walkthrough.

Authentication

You can register and sign in a user, keep a request authenticated without asking for the password again, and explain where the credential lives in the browser and why there rather than somewhere else.

Patient records

You can record and retrieve a patient record, and demonstrate that a clinician outside the care relationship is refused — by the server, not the interface.

Consent, and taking it back

You can capture consent against a specific version of what was agreed, show it at a point in time, and stop the processing it permitted when it is withdrawn.

Who read this record

You can show, for one patient, everyone who accessed their record and when — and explain why that log cannot be edited by the application.

Email verification

You can issue a verification link, activate the account when it is followed, and explain what the link contains and why it cannot simply be a user id.

Going live

Somebody who has never met you can open a URL and use the product — and you can say what is different about the copy running there, where its secrets come from, and what you do when a release turns out to be wrong.

The roadmap. 8 sprints, 35 tasks.

Every sprint has a goal and a set of tasks. Open a sprint to see the tasks you will pick up.

Sprint 01

Who you are here

Three kinds of account exist, and only one of them can be made by filling in a form.

4 tasks
  1. A client can register and land signed in
  2. Signing back in survives a refresh
  3. Signing out leaves nothing on a shared machine
  4. Practitioner and practice accounts cannot be self-issued
Sprint 02

The form nobody finishes in one sitting

A client works through the intake form across days, submits it once, and can still read what they sent.

4 tasks
  1. A client can work through the intake form
  2. A half-finished form is still there on Thursday
  3. Submitting ends the drafting, and can be read back
  4. A correction after submitting does not erase what was sent
Sprint 03

Agreeing to something specific

Consent is a dated agreement to a particular version of the wording, and both sides can still read that wording later.

4 tasks
  1. The practice publishes its terms, and a change makes a new version
  2. A client agrees, and the agreement records what they read
  3. A client can read back exactly what they agreed to
  4. New terms ask again rather than assuming
Sprint 04

The desk next to yours

Being the client's practitioner is what grants access to their intake. Being a practitioner is not.

5 tasks
  1. The practice takes a client on and assigns them a practitioner
  2. A practitioner reads their own client's intake in full
  3. A practitioner outside the care relationship is refused, whatever route they use
  4. The administrator sees the paperwork, not the contents
  5. Moving a client to another practitioner ends the old access
Sprint 05

Taking it back

Withdrawing consent stops something the client can watch stop, and does not erase the fact that consent was given.

4 tasks
  1. A client can withdraw, and knows what that does before they do it
  2. The practitioner's access stops at the moment of withdrawal
  3. Withdrawing does not erase the agreement that was made
  4. Agreeing again is a new agreement, not an undo
Sprint 06

Who opened my record

The client can see every time their intake was opened, and every time somebody was turned away from it.

4 tasks
  1. Every time an intake is opened, it is recorded
  2. A client can see who has opened their record
  3. A refused attempt is recorded, and shown too
  4. Nothing in the product can change the trail
Sprint 07

An address that is theirs

Nobody consents on behalf of an address they have not proved they can read.

4 tasks
  1. Registering sends something only the owner can act on
  2. Consent waits on a proved address, and says so
  3. The link cannot be guessed, reused or used next year
  4. Asking again, and correcting an address that was wrong
Sprint 08

Somewhere a client can reach

The practice is on the internet at an address it can print, and the person who built it is not part of keeping it there.

6 tasks
  1. A stranger can reach it without you
  2. No credential has ever been in the repository
  3. The messages actually arrive
  4. An address worth printing on a letter
  5. The records survive the machine, and nobody else can reach them
  6. A bad release can be undone in minutes

Read before you build. The best engineers do.

Senior engineers read the docs before they touch the code. Every Blueprint comes with short documents on the product and its world, the kind a team hands a new hire. Read them well and you ask sharper questions and walk into every review prepared.

What you are building

The product, who it is for, and what finished means.

Why this data is different

Domain you will not have: what an intake form is, who is in a therapy practice, and what a mistake with this data costs somebody.

Build therapy intake and consent.

Start your free week. Adaeze runs your kickoff, and Lars reviews every pull request.