PCS Cross Check logo PCS Cross Check
Audit, Admin & Reporting

Oversight for supervisors — and numbers for the budget meeting.

A dedicated portal, separate from the medic's tablet: review the legal document for any chart, keep the sign-off queue moving, turn finalized calls into KPIs, exports and a call-density map — and let the breach watch read the audit log so a human doesn't have to.

Every screen below is the live product on demonstration data — no real patient or staff information.
Audit & Admin Portal

Oversight built for supervisors Admin

A dedicated portal gives supervisors and administrators full visibility — find any chart, keep the sign-off queue moving, triage shift logs and incidents, securely release records, and see every access — all separate from the medic's tablet, with the server enforcing every role boundary.

Audit & search
Admin portal audit tab — recent ACRs with statuses and the awaiting sign-off badge counted on the tab
Every chart, searchable by patient, address, health card, call number or paramedic — with the sign-off queue counted right on the tab, and every search itself logged.
Awaiting sign-off
Awaiting sign-off queue naming who still owes a signature on each chart
The queue names exactly who still owes a signature — and the 18-hour backstop keeps it honest.
Disclosures — the PHIPA record, built in
Disclosures tab with one-time secure sends, expiry times, download counters and a new secure send button
Secure release with one-time links and separately-texted codes — and the send log doubles as the service's PHIPA accounting of disclosures.
A client’s document file — from the desk
The portal’s Community Paramedicine client record with the Document file card: nine documents — date, type pill, title, size and filed date — each with Open, Edit and Remove buttons, an Add documents button and a drag-and-drop zone above, and a Show removed documents control beneath
The coordinator’s side of the same file: drag the scanned fax or the PDF from the desk straight onto the client — no visit needed. Every document with its type, date and size; Open (and it’s logged), Edit the details, or Remove with a PIN — a removed document stays recoverable for 30 days before the file is crypto-shredded. Documents get their own retention dial, 12 to 60 months, and purging them never deletes the client.
Shift logs — triaged daily checks
Shift Logs tab with daily vehicle checks and red flag pills for defects
The crews' vehicle checks, triaged — red pills where something needs a supervisor.
Activity log
Activity log audit trail in the admin portal — reads, searches and system events with actors, resources and timestamps
Every access, search and change — recorded, filterable, and itself audited.
What supervisors can do11 features
  • Audit & search — find any chart by patient, address, health card, call number or paramedic, and review the official document in full; every search is logged.
  • Awaiting sign-off & return-for-amendment — the queue names exactly who still owes a signature; return a chart to a crew member with a reason and a clear amendment banner on the tablet, and amendments come back as stacked, immutable versions.
  • A priority audit queue — a med-error override or a stale escalation rides straight to the top of the list, so the charts that need a supervisor first get one first.
  • Reporting & exports — call volume, response and on-scene times, CTAS mix, transport destinations and crew workload, all computed on the server from the live records. Export any view in five formats for your own analysis, or schedule a report to arrive on its own.
  • Call-density heat map — see where the calls actually are across your coverage area, built from the location already captured on each call. Useful for posting, staffing and the conversations you have to justify both.
  • Supervisor-authorised overrides — when a medic is blocked by a required-field rule on a real call, a supervisor can read them a one-time code instead of the crew self-attesting. The call goes to the top of the review queue carrying the supervisor's name and their stated reason.
  • A review queue that empties — escalations can be marked reviewed once dealt with, so the list reflects what still needs attention rather than growing forever. The escalation stays in the record's history either way.
  • Shift logs & incident reports — triaged daily vehicle checks with red flag pills (major defect, failed check, low fuel), plus PIN-signed incident reports viewable and downloadable as PDFs.
  • Two-factor secure disclosure — package a patient's record, encounters and linked 911 reports into a one-time pickup link, then text a separate access code; the recipient needs both, the link carries no PHI, and wrong codes lock them out.
  • The client’s document file, from the desk — drag PDFs or photos onto a Community Paramedicine client’s record, edit a document’s details, open any document (each open is logged) and remove one with a PIN — a removal stays recoverable for 30 days before the file is crypto-shredded. Documents get their own retention dial in Service settings, 12 to 60 months, and purging them never deletes the client.
  • Role-limited account administration — create, reset and deactivate accounts with guardrails: supervisors can't grant themselves admin or delete the last administrator, and accounts tied to records are deactivated rather than deleted, so the audit trail stays intact.
Reporting & Analytics

The numbers, without the patient records Reporting

Every finalized chart already holds the times, codes and outcomes your service reports on — the reporting layer turns them into KPIs, charts and exports without a single patient record leaving the server. Records decrypt server-side, reduce to counts and medians, and only the aggregates reach the browser. Every view, export and scheduled run writes the audit log. And every median comes with its completeness percentage, because a number without its denominator is a guess.

Service performance — the KPI dashboard
Reporting tab: date-range and filter controls with five-format export, KPI tiles for total calls, transport rate, CTAS 1–2 share, median response, on-scene and offload times, offload hours and medications per call, and call-volume charts by hour, day of week and trend
The KPIs a service actually reports — call volume, transport rate, CTAS mix, response, on-scene and offload medians, offload hours — over any range, with filters and five-format export, and the volume trends charted right below.
Operational intervals — with their denominators
The Operational intervals card: chute, response, on-scene, transport, offload-delay and total-task rows each with eligible calls, completeness percentage, median, mean and 90th percentile — plus median response by CTAS, average task time by hour, and response-by-priority tables
Chute to offload delay, each interval with its eligible count, completeness, median, mean and 90th percentile — response by CTAS and by dispatch priority beside it. Honest numbers, ready for the annual report.
Per-paramedic activity
Per-paramedic activity table listing OASIS number, calls, transports, transport rate, medications, procedures, median on-scene time, incident reports, amendments and returns for each attending paramedic
Activity per attending paramedic over any range — calls, transports, medications, procedures, median on-scene, incident reports, amendments and returns — built from charts that are already signed, so nobody re-keys anything.
Community Paramedicine — the funding numbers
The Community Paramedicine reporting card: program KPIs including 47 distinct clients seen across 211 visits, referral counts, visit durations, the current caseload, encounters-by-month with 911-sourced notes on their own line, how-often-clients-were-seen frequency bands, and a by-clinician workload table with a reconciliation note
The CP program's funding case, computed: distinct clients seen reported separately from visit volume, frequency bands showing how often clients are really seen, by-clinician workload — and a reconciliation note that says exactly which basis each number rests on, so a submission never overstates the program's reach.
Reporting — call density
The call-density card: a heat map over the coverage area with the location-completeness figure — 1,133 of 1,254 calls mapped — and a calls-by-postal-area bar chart beneath it
Where the calls actually are. Counts are bucketed into ~550 m cells on the server, so no patient record and no raw coordinate ever reaches this screen — and the same picture comes out as numbers, by postal area, underneath.
Inside the reporting layer8 features
  • Server-side aggregation, by design — records decrypt in the application, reduce to counts and medians, and only de-identified aggregates reach the browser. Charts are inline SVG — no CDNs, no third-party analytics.
  • The KPIs a service actually reports — call volume, response / on-scene / transport intervals with a completeness percentage on each, CTAS mix, dispositions, destinations, medications, procedures, age and sex distributions, calls by hour.
  • Call-density heat map — de-identified ~550 m grid-cell counts drawn locally over base tiles that load only when a supervisor clicks Load; the density data itself never leaves the service.
  • Five-format export — the dashboard, per-medic and custom reports export as CSV, XML, XLSX, DOCX or PDF, generated entirely on the server — and CSV cells are neutralized against spreadsheet formula injection.
  • Reports that arrive on their own — schedule the service-performance report daily, weekly or monthly; recent runs stay downloadable in the portal, and email delivery is optional.
  • A custom report builder — pick the range, filters, group-by and metric, and export the answer like any other view.
  • Per-medic activity — a view for supervisors and administrators of workload by attending paramedic, attributed the way the chart was signed.
  • Research-grade raw export, guarded — administrators can export record-level data, de-identified by default: names, birthdates, health cards, addresses and call numbers stripped, ages banded, and free-text never exported in any mode. Every export is audited.
Privacy that patrols itself

Breach watch — someone actually reads the audit log PHIPA

Every access is logged — but a log nobody reads protects nobody. So an automated sweep reads it for you — comparing record access against each account's own history and the patterns snooping takes: a volume outlier, an enrolled client sharing a staff member's surname, a long-quiet account suddenly reading, small-hours access. A signal is a suspicion, not a breach — most are a busy shift. A supervisor looks at each one, dismisses it in a tap, or escalates it into the breach register: the service's permanent PHIPA s.12(2) record of what happened, how it was contained, and when the required notices went out.

Breach watch — signals above, the s.12(2) register below
The Breach watch tab: six open access signals across five detectors — own-surname record access, volume outliers, a dormant-account burst, coworker-surname access and small-hours access — each with severity, a plain-language summary and a lapse countdown; below, the breach register with an open entry whose individual-notified column reads 'not yet' in red, a contained lost-phone entry and a closed misdirected-fax entry with both notification dates recorded
The whole discipline on one screen: machine suspicions with plain-language summaries and severities — each one Dismiss, Dismiss-with-note or Escalate — lapsing on their own if nobody bites; and beneath them the permanent register, where the red "not yet" pill nags until the person is actually notified, and the closed entry carries both notification dates for the annual IPC return.
How the breach watch works6 features
  • Five detectors — access-volume outliers measured against the account's own baseline (multiples of that user's own daily median), own-surname and coworker-surname access to enrolled-client records, a dormant account suddenly reading, and small-hours access. What's a normal volume for a duty supervisor isn't what's normal for a part-timer — so the volume baseline is personal.
  • A signal is a suspicion, not an accusation — the UI says so on every screen. One tap dismisses with or without a note; escalation opens a register entry with the signal attached as evidence.
  • Signals lapse; the register never does — untouched signals age out on a service-set window so the list stays honest, while register entries are kept permanently. Suspicions expire — the s.12(2) record doesn't.
  • The notices, tracked — each register entry carries when the affected person was notified and when the IPC was told, with a red "not yet" until it's done. PHIPA's first-reasonable-opportunity duty, on a screen instead of a sticky note.
  • Breaches people report get a door too — a misdirected fax or a lost phone that no detector saw is recorded directly into the register, so the record is complete either way.
  • The annual statistics, already kept — the register is the source for the yearly statistical return to the Information and Privacy Commissioner; the count is a query, not an archaeology project.
Security & PHIPA

Built to pass your security review

Every safeguard below is in the product today — not on a roadmap. Data stays in Canada, encrypted and isolated per service, with every access logged.

Encrypted at rest (AES-256-GCM)on every route that touches health information — the database only ever holds ciphertext, hosted in Canada.
Two-factor sign-insupervisors and admins add an authenticator app in about a minute — scan a code, done. A service can make it mandatory for everyone, and anyone who turns it on is walked through setup at their next sign-in.
Locked out? Still coveredprintable single-use backup codes that work with no signal, and any duty supervisor can read a one-time code down the phone to a medic whose phone died mid-shift. Both are single-use, time-limited and recorded against the supervisor who issued them.
Encrypted off-site backupsthe database is backed up nightly, encrypted so that the server itself cannot read its own backups — only the key held off-site can. Restores are rehearsed, not assumed.
Searchable without exposing PHIblind-index (keyed-HMAC) matching over encrypted fields, so a name lookup never decrypts the database.
Per-service isolationone service can never see another service's records.
PHI never travels in a URLrecords and health-card lookups move only in encrypted POST bodies over HTTPS.
Brute-force lockoutfive failed PIN attempts locks the signer for 15 minutes; signing PINs are never stored in the clear.
Clean hand-off between medicsevery open patient panel is force-closed at sign-in, so the next crew never sees the last patient.
Clinical roles only, enforced server-sidescheduling and office staff are hard-blocked from every patient-data route — a scheduler can never open a chart.
Every access auditedreads, searches, signatures, overrides and disclosures are all logged — and viewing the audit log is itself audited.
A tamper-evident audit logevery entry is hash-chained to the one before it, and the log is append-only at the database level — rows cannot be edited or deleted, not even by the application. Periodic head hashes are written outside the database, so the chain can be checked against a witness the server does not control.
Backups that are restore-tested, not just takenthe nightly encrypted backup is restored end to end and the result written down — tables compared, the audit chain re-verified inside the restored copy, and the encrypted patient data decrypted to prove it is still readable. A backup nobody has restored is a hypothesis.
Nightly integrity checksan automated sweep re-verifies the chart hashes and looks for anything that should be encrypted and is not — a write path that skipped encryption would otherwise be invisible, because unreadable and readable data look identical on screen.
Session controlan administrator resetting a password ends that person's live sessions everywhere, immediately — not at the next expiry. Sessions are capped and re-checked on every request.
Retention and disposal, per recordretention is set by the service and enforced by the database, with legal holds that survive it. Disposal is deliberate and recorded — nothing is quietly deleted on a timer.
Disclosure by designsingle-use, expiring, revocable pickup links with the access code texted separately; the disclosure log doubles as your PHIPA accounting of disclosures.
Proven at scale

A million charts, and the bedside answer still lands in milliseconds

When a medic arrives at a patient, the platform checks whether that person has been seen before — previous 911 calls, and whether they are an active Community Paramedicine client. That lookup is worthless if it is slow, and dangerous if it is wrong. So it was measured against a million charts, seeded with the platform's own encryption, on the ordinary two-core server the platform runs on — with the live application running beside it.

LookupMedian99th percentileWorst seen
By health card, against a 700,000-chart service0.72 ms2.52 ms6.72 ms
By name + date of birth0.62 ms1.83 ms3.94 ms
Full panel — CP check, match and prior-chart summary1.43 ms4.30 ms8.36 ms
…with the access-audit rows written before the answer is released1.80 ms4.71 ms8.42 ms

Under load it holds. With twenty concurrent workers sustaining 1,835 lookups per second against the million-chart service, a second service's worst full-panel answer was still 24.7 ms — three orders of magnitude more pressure than a real fleet applies, and the bedside answer stays instant.

Fast is only half of it. The same run put 23 adversarial cases through the matcher and all 23 held: McDonald never returned a MacDonald chart, twins sharing a birthday stayed ambiguous rather than being merged, one service could never see another's records, unfinished drafts stayed invisible, and an allergy added by a later correction still surfaced. A recognition system that guesses is worse than none — so it is built to return nothing rather than the wrong patient.

Keep exploring

The rest of the platform

The portal oversees the same records the crews chart on the tablet — and the scheduling system runs the roster those crews work.

ePCR → Community Paramedicine → Scheduling → Book a live demo