Secure Drop
Anonymous · Encrypted · No login required
Your message is sealed and anonymous. We cannot identify you. No account or login is needed.
Your message
Max 3 files, 10 MB each
Secure Channel
Anonymous · Bidirectional · Encrypted
Start an anonymous conversation. You'll receive a thread code to check for replies later.
Your message
Max 3 files, 10 MB each
Thread Code
Enter your thread code above to check for replies.
Healthcare & Clinics

A clearer path from patient intake to follow-up.

City of Hats can give a clinic a branded entry point for intake, documents, appointment requests, and secure communication, paired with a staff workflow for handling the next action. It is a communication layer—not a claim of automatic healthcare compliance.

Best fitClinics improving patient-facing intake and communication
Typical accessBranded browser portal with secure escalation
Important boundaryNot an EHR and not compliant by default
What this solution does

Reduce inbox confusion around patient service

Patients often move between a website, generic forms, phone calls, attachments, and consumer messaging. A configured clinic experience can give them a more coherent route while the practice defines which information may be collected, where it is stored, and when a protected Hat channel is required.

Guided intake

Present the right questions and instructions before a visit without turning every interaction into an email exchange.

A defined document path

Provide an approved route for supported uploads or delivery instead of ad hoc attachments.

Secure follow-up options

Move appropriate patient communication into supported protected workflows with explicit staff ownership.

Core workflows

Patient-facing workflows with clinical boundaries

The clinic must decide which data belongs in City of Hats, which belongs only in the clinical record, and how staff transfer or reference information between systems.

Pre-visit intake

Collect configured administrative or clinical information with clear instructions and privacy notice.

Appointment requests

Capture a request or route to scheduling; final booking may remain in the clinic’s authoritative system.

Document exchange

Support an approved path for records, referrals, results, or certificates when configured for the deployment.

Patient messaging

Use secure communication for appropriate follow-up while keeping emergencies and clinical escalation out of ordinary messaging.

Localized guidance

Offer translated interface content, subject to the clinic’s review of medical terminology and translation quality.

Staff handling

Route requests to the responsible team through Operations, with access and retention defined by the clinic.

How it works

Design around minimum necessary information

A clinic deployment should begin with a documented data map and an explicit emergency-communication policy.

01

Classify the workflow

Separate general information, administrative intake, clinical data, urgent symptoms, documents, and records that must remain in the EHR.

02

Configure access and notice

Define patient instructions, staff roles, retention, integrations, consent, escalation, and the secure-channel boundary.

03

Pilot with governance

Test the patient journey, accessibility, terminology, record transfer, incident response, and staff training before broad use.

Security and privacy

Healthcare security requires more than encryption

Encryption is one control. Healthcare deployments also depend on contracts, lawful processing, minimum-necessary collection, staff authorization, endpoints, auditability, retention, breach procedures, and regional health-privacy law.

Protected Hat communication

Supported Hat-channel content uses City of Hats encryption controls; public portal pages and connected systems have different boundaries.

Minimum-necessary design

Collect only what the configured workflow needs and avoid duplicating the clinical record without a defined purpose.

Authorized staff handling

The clinic must assign and review staff access, administrator privileges, device security, and offboarding.

No badge-based assurance

Do not treat a website badge or encryption claim as HIPAA, PHIPA, PIPEDA, Loi 25, or GDPR compliance. Review the complete deployment and contracts.

Scope clarity

Important boundary

A strong fit when

Your clinic needs a more coherent patient communication layer and can define data boundaries, staff ownership, emergency instructions, and the authoritative medical record.

What it does not replace

It is not an emergency service, diagnosis tool, EHR, e-prescribing platform, clinical decision system, medical-device system, or automatic compliance solution.

Confirm before deployment

Complete privacy, security, clinical-safety, accessibility, retention, breach-response, vendor, and legal review. Confirm contracts and required agreements before processing regulated health information.

Straight answers

Questions teams ask before a demo

Product scope reviewed: 10 August 2026

Is City of Hats HIPAA compliant?

The product should not be described as compliant by default. HIPAA applicability and compliance depend on the organization, contract and business-associate requirements, configured services, subprocessors, administrative safeguards, and actual use. A deployment requires specific review.

Does this replace our EHR?

No. The clinic’s EHR or other approved system should remain the authoritative clinical record unless a separately validated architecture says otherwise.

Can patients use the portal without installing an app?

Public and configured browser-portal steps can be opened from a link, QR code, or NFC touchpoint. A protected Hat workflow may require the participant to create or open a Hat.

Can patients send urgent medical messages?

The clinic must publish clear emergency instructions and should not rely on ordinary portal messaging for urgent or life-threatening care. Escalation and response-time expectations must be configured and communicated.

Can content be translated automatically?

Localized or translated workflows may be configured, but medical terminology and patient instructions require clinical review. Machine translation should not be treated as a substitute for qualified interpretation where accuracy is critical.

Map the patient-data boundary before the portal.

Bring your intake journey, record systems, jurisdictions, security requirements, and staff roles to a focused solution review.