A scalable backend API for HealthStream, an online healthcare consultation platform that connects patients with doctors for appointments, online consultations, digital prescriptions, and secure account management.
π Live Backend: https://health-stream-lac.vercel.app
HealthStream is a healthcare consultation platform designed to make doctor-patient communication easier and more accessible.
Patients can discover available doctors, book consultation slots, complete payments, join scheduled video consultations, and receive digital prescriptions after their appointments.
Doctors can apply to join the platform, manage their schedules, conduct consultations, and provide prescriptions.
Admins and Super Admins manage doctors, patients, administrators, and the overall platform.
- Patient registration with email and password
- Patient Google authentication
- Doctor application system
- Email OTP verification
- Login with email and password
- Forgot password functionality
- Password reset through OTP
- Change password for authenticated users
- Set password for Google-only patients
- Access token authentication
- Refresh token based session management
- Cookie-based token storage
- Role-based authorization
HealthStream supports four different user roles:
| Role | Description |
|---|---|
PATIENT |
Registers directly and books doctor consultations |
DOCTOR |
Applies to become a doctor and waits for approval |
ADMIN |
Manages doctors, patients, and creates admins |
SUPER_ADMIN |
Has full administrative control over the platform |
Patients can:
- Register their account
- Verify email using OTP
- Login using email/password
- Login using Google
- Reset forgotten passwords
- Change password
- Set password for Google accounts
- Browse available doctor schedules
- Select available consultation slots
- Pay for appointments
- View booked appointments
- Cancel appointments
- Join online consultations
- Receive consultation invoices
- Receive digital prescriptions
Doctors can:
- Apply to become a doctor
- Verify email using OTP
- Wait for admin approval
- Login after approval
- Create consultation schedules
- Publish schedules
- Update schedules according to platform rules
- Provide meeting links
- Manage appointments
- Start consultations
- Complete consultations
- Write prescriptions
- Send digital prescriptions to patients
Admins can:
- Approve doctor applications
- Reject doctor applications
- Block doctors
- Unblock doctors
- Block patients
- Unblock patients
- Create new admin accounts
- Manage doctor-related activities
- Manage patient-related activities
Admins cannot:
- Create Super Admin accounts
- Block Admin accounts
- Block Super Admin accounts
Super Admins can perform all administrative operations available to Admins.
Additionally, Super Admins can:
- Create Super Admin accounts
- Block Admin accounts
- Unblock Admin accounts
- Block Super Admin accounts
- Unblock Super Admin accounts
A patient can register using:
Name
Email
Password
After registration:
Registration
β
OTP sent to email
β
Email verification
β
Account activated
β
Login session created
Patients can also register using Google.
Google registration does not require separate OTP verification because Google already verifies the user's email.
Doctors cannot directly become active doctors.
The process is:
Doctor Application
β
Email OTP Verification
β
Pending Application
β
Admin / Super Admin Review
β
Approve / Reject
β
Doctor Account Activated
A doctor cannot log in or use the platform before approval.
After approval, the doctor receives a welcome email.
HealthStream uses OTP-based email verification for self-registration flows.
OTP verification is required for:
- Patient registration
- Doctor application
OTP verification is not required for:
- Admin accounts
- Super Admin accounts
- Google patient registration
HealthStream provides multiple password-related flows.
User submits email
β
OTP sent to email
β
User submits OTP
β
New password
β
Password updated
Authenticated users can change their password by providing:
Current Password
New Password
Patients who initially registered through Google can set a password later.
After setting a password, they can use both:
Google Login
+
Email/Password Login
After a successful authentication, HealthStream issues:
- Access Token
- Refresh Token
Both tokens are handled through cookies.
Typical authentication flow:
Login
β
Access Token
+
Refresh Token
β
Authenticated Requests
β
Access Token Expired
β
Refresh Token
β
New Access Token
This provides secure session management while allowing users to remain authenticated without repeatedly logging in.
Doctors can publish their availability through schedules.
Each schedule belongs to:
One Doctor
+
One Calendar Date
HealthStream applies several schedule restrictions.
A doctor can create a maximum of one schedule for a particular calendar date.
A schedule must be:
Minimum: 3 hours
Maximum: 8 hours
The schedule must start and end on the same calendar date.
Valid:
09:00 AM β 05:00 PM
03:00 PM β 11:00 PM
Invalid:
09:00 PM β 03:00 AM
because it crosses into the next day.
Each schedule contains a video consultation meeting link.
The same meeting link is used by appointments booked under that schedule.
A new schedule starts as:
DRAFT
Patients cannot see draft schedules.
The doctor must publish the schedule before patients can book available slots.
Consultation slots are generated automatically in:
20-minute intervals
Example:
03:00 PM β 09:00 PM
6 Hours
360 Minutes
360 / 20 = 18 Slots
Therefore, the schedule contains:
18 consultation slots
After a schedule is published, different fields follow different update rules.
The date becomes locked after publishing.
The doctor can change the time range only until the first appointment is booked.
Once an appointment exists, the time range becomes locked.
The following can still be updated:
- Schedule status
- Meeting link
- Other editable schedule information
Patients can only see schedules for:
Today
They cannot see:
- Past schedules
- Future schedules
A schedule also becomes unavailable for new bookings once its starting time arrives.
Example:
Schedule:
03:00 PM β 09:00 PM
Before 03:00 PM:
Visible β
Bookable β
From 03:00 PM:
Visible β
New bookings β
A fully booked schedule is also removed from the patient's available schedule list.
The appointment booking flow is:
Patient
β
View Today's Available Schedules
β
Select Doctor
β
Select Available Slot
β
Payment
β
Payment Successful
β
Appointment Created
β
Appointment Status = BOOKED
Patients must pay for the appointment before the booking becomes confirmed.
After successful payment:
- Appointment is created
- Appointment status becomes
BOOKED - A serial number is assigned
- Invoice information is generated
- Invoice PDF is sent through email
Each appointment receives a serial number based on its booking order within the schedule.
Example:
First booking β Serial 1
Second booking β Serial 2
Third booking β Serial 3
Fourth booking β Serial 4
After successful payment, the system sends an invoice PDF to the patient.
The invoice contains important appointment information such as:
- Meeting link
- Consultation date
- Consultation time
- Payment information
Appointments follow this lifecycle:
BOOKED
β
ONGOING
β
COMPLETED
Automatically assigned after successful payment.
The doctor manually changes the appointment to ongoing when the consultation begins.
The doctor manually marks the appointment as completed after finishing the consultation.
Doctors can create prescriptions only after an appointment is completed.
Prescription information can include:
- Key medical findings
- Prescribed medicines
- Other relevant prescription information
Flow:
Appointment
β
COMPLETED
β
Doctor Creates Prescription
β
Prescription Submitted
β
Prescription PDF Generated
β
PDF Emailed to Patient
A prescription cannot be created for an appointment that is still:
BOOKED
or
ONGOING
Patients can cancel appointments based on the schedule start time.
| Cancellation Time | Refund |
|---|---|
| More than 1 hour before schedule starts | β Yes |
| Within 1 hour before schedule starts | β No |
| During the schedule | β No |
| After the schedule ends | β No |
Suppose a schedule starts at:
03:00 PM
Refundable cancellation:
Before 02:00 PM
Non-refundable cancellation:
02:00 PM onward
The appointment can still be cancelled, but the payment will not be refunded.
Admin and Super Admin accounts are not self-registered.
They are created by authorized existing administrators.
When creating a new administrative account, two emails are involved:
This is the email used as the new account's login identity.
This is the person's actual inbox where the welcome credentials are delivered.
Authorized Admin
β
Create Admin / Super Admin
β
System Generates Password
β
Credentials Sent to Personal Email
β
New Admin Logs In
β
Password Changed
The generated password should be changed after the first login.
HealthStream sends emails for important account and healthcare events.
| Event | Recipient |
|---|---|
| Patient registration | Patient |
| Doctor application approval | Doctor |
| Admin creation | New Admin |
| Super Admin creation | New Super Admin |
| OTP verification | Relevant user |
| Password reset OTP | Relevant user |
| Password reset success | Relevant user |
| Appointment invoice | Patient |
| Prescription generated | Patient |
HealthStream follows role-based and authentication-based access control.
Important security concepts include:
- Authentication
- Authorization
- Role-based access control
- Access tokens
- Refresh tokens
- Secure cookie-based sessions
- OTP verification
- Password hashing
- Protected administrative operations
- Protected doctor operations
- Protected patient operations
Sensitive operations are restricted according to the authenticated user's role.
The backend is organized around modular application responsibilities.
Core areas include:
Authentication
Users
Patients
Doctors
Admins
Schedules
Appointments
Payments
Prescriptions
Email
File/PDF Generation
Authorization
Audit / Platform Management
The project follows a service-oriented backend structure so that business logic remains separated from controllers and route handling.
The backend is built using modern TypeScript-based backend technologies.
- Node.js
- TypeScript
- Express.js
- Prisma ORM
- JWT-based authentication
- Access Token
- Refresh Token
- HTTP Cookies
- Google Authentication
- Prisma ORM
- Relational database
- REST API
- Email-based OTP
- Transactional email notifications
- PDF generation for invoices
- PDF generation for prescriptions
- Vercel
git clone <your-repository-url>Move into the project:
cd <your-project-folder>Using npm:
npm installCreate a .env file in the root directory:
DATABASE_URL="your_database_url"
JWT_ACCESS_SECRET="your_access_secret"
JWT_REFRESH_SECRET="your_refresh_secret"
GOOGLE_CLIENT_ID="your_google_client_id"
GOOGLE_CLIENT_SECRET="your_google_client_secret"
SMTP_HOST="your_smtp_host"
SMTP_PORT="your_smtp_port"
SMTP_USER="your_smtp_user"
SMTP_PASSWORD="your_smtp_password"
FRONTEND_URL="your_frontend_url"Add the exact environment variables required by your project configuration before running the application.
Generate Prisma Client:
npx prisma generateRun migrations when required:
npx prisma migrate devFor production deployment:
npx prisma migrate deploynpm run devThe API should then be available on your configured local port.
Example:
http://localhost:5000
HealthStream backend is deployed on Vercel.
https://health-stream-lac.vercel.app
Open:
https://health-stream-lac.vercel.app
Expected response:
{
"success": true,
"message": "Welcome to HealthStream Backend"
}The API follows a modular REST architecture.
Major API domains include:
/auth
/users
/patients
/doctors
/admin
/schedules
/appointments
/payments
/prescriptions
Exact endpoint names and request/response structures depend on the current implementation of the deployed API.
The complete HealthStream workflow can be summarized as:
Patient Registration
β
Email Verification
β
Login
β
Browse Today's Doctor Schedules
β
Select Available Slot
β
Make Payment
β
Appointment Confirmed
β
Receive Invoice
β
Join Consultation
β
Doctor Starts Consultation
β
Appointment Ongoing
β
Doctor Completes Consultation
β
Appointment Completed
β
Doctor Creates Prescription
β
Prescription PDF Generated
β
Patient Receives Prescription
Doctor Application
β
Email OTP Verification
β
Admin Review
β
Approval
β
Doctor Login
β
Create Schedule
β
Publish Schedule
β
Receive Appointments
β
Start Consultation
β
Complete Consultation
β
Create Prescription
Admin Login
β
Dashboard
β
Manage Doctors
β
Approve / Reject Applications
β
Block / Unblock Doctors
β
Manage Patients
β
Block / Unblock Patients
β
Create Administrators
Super Admin Login
β
Full Platform Management
β
Doctor Management
β
Patient Management
β
Admin Management
β
Create Admin
β
Create Super Admin
β
Block / Unblock Admin
β
Block / Unblock Super Admin
For development:
npm run devTo build the project:
npm run buildTo run the production build:
npm startMake sure these scripts match the scripts defined in your project's
package.json.
The backend is deployed using Vercel.
Production deployment flow:
Git Repository
β
Vercel
β
Build
β
Environment Variables
β
Production Deployment
β
HealthStream API
Production API:
https://health-stream-lac.vercel.app
Never commit sensitive credentials to Git.
Do not commit:
.env
.env.local
.env.production
Make sure secrets such as the following remain private:
Database credentials
JWT secrets
Google OAuth credentials
SMTP credentials
Payment credentials
API keys
For Vercel deployment, configure environment variables from the Vercel project settings.
A typical modular structure for HealthStream can be organized as:
src/
βββ app/
β βββ modules/
β β βββ auth/
β β βββ user/
β β βββ patient/
β β βββ doctor/
β β βββ admin/
β β βββ schedule/
β β βββ appointment/
β β βββ payment/
β β βββ prescription/
β β
β βββ middleware/
β βββ routes/
β βββ helpers/
β βββ utils/
β βββ errors/
β
βββ lib/
βββ config/
βββ server.ts
Adjust this structure to match the exact folders and files in your repository.
βββββββββββββββββββββββ
β HealthStream β
β Healthcare API β
ββββββββββββ¬βββββββββββ
β
βββββββββββββββββββββββΌββββββββββββββββββββββ
β β β
βΌ βΌ βΌ
Patients Doctors Admins
β β β
β β β
βΌ βΌ βΌ
Book Slots Create Schedules Manage Platform
β β β
ββββββββββββββββ¬βββββββ΄ββββββββββββββββββββββ
β
βΌ
Appointments
β
ββββββββββββ΄βββββββββββ
βΌ βΌ
Payment Consultation
β β
βΌ βΌ
Invoice Prescription
β
βΌ
Patient Email
HealthStream follows these core business rules:
- Patients can register directly.
- Doctors must apply before becoming active doctors.
- Doctor applications require email verification.
- Admin or Super Admin approval is required for doctors.
- Google authentication is available only for patients.
- Admins and Super Admins cannot self-register.
- Only Super Admins can create Super Admin accounts.
- Admins cannot manage other Admins or Super Admins.
- Doctors can publish one schedule per day.
- Schedule duration must be between 3 and 8 hours.
- Consultation slots are generated in 20-minute intervals.
- Patients can only book today's available schedules.
- Payment is required before appointment confirmation.
- Appointment statuses are
BOOKED,ONGOING, andCOMPLETED. - Prescriptions can only be created after an appointment is completed.
- Appointment cancellation is allowed according to the platform's refund policy.
- Invoice and prescription documents are delivered through email.
HealthStream aims to provide:
- Simple patient-doctor communication
- Secure authentication
- Organized doctor scheduling
- Reliable appointment management
- Online consultation support
- Digital prescription delivery
- Automated email notifications
- Role-based platform management
- Secure and scalable backend infrastructure
Project: HealthStream Backend: HealthStream REST API Deployment: Vercel Status: Production
https://health-stream-lac.vercel.app
This project is for educational and project development purposes.
Add your preferred license here, for example:
MIT License
Connecting Patients with Doctors β Smarter, Simpler, Better.