No scattered email attachments
A specialist in a new city gets one organised bundle instead of a handful of separate email attachments the family hopes adds up to everything relevant needed.
Available now
In build
The whole team
Nineteen specialists, each with a defined job and an honest status label.
See all nineteenThe person can hand a new doctor, specialist, or hospital a specific, time-bounded set of records without emailing loose attachments or carrying printouts.
Works with
What it does
The user selects a date range, specific documents, or a whole profile, and generates a share link or a downloadable PDF/ZIP bundle. Shared links expire after a set time or number of views, and every share event is logged with what was shared, with whom, and when.
A family switching from a local doctor to a specialist in another city faces the same tedious choice every time: email a scattered set of attachments and hope nothing important is missing, or carry a heavy stack of printouts on the train instead. Neither option feels like a reliable way to hand over years of a father's diabetes history to someone new.
Record sharing and export lets the family choose a date range, specific documents, or a whole profile, and generate either a shareable link or a downloadable PDF or ZIP bundle. Shared links expire after a set time or number of views, and every access to that share is logged with what was shared, with whom, and exactly when — because handing records to a new clinician should be deliberate and traceable, not permanent and left completely untracked.
Doctor runs this directly on the platforms your customers already use — no separate app for them to install.
How it works
Choose a date range, specific documents, or an entire family member's whole profile, deciding exactly what a new clinician or hospital actually needs to see for this particular visit or referral being made right now.
Create either a shareable link or a downloadable PDF or ZIP file, whichever suits how the recipient prefers to receive records — a link for a specialist's email, a bundle for a hospital's intake form.
Every share expires after a set time period or a maximum number of views, so a link sent for one appointment doesn't remain quietly accessible to anyone who happens to come across it much later.
Every access to a shared bundle is logged carefully, so the family can see exactly when a link was opened and, if needed, revoke it early before its normal expiry date arrives on its own.
Why it matters
A specialist in a new city gets one organised bundle instead of a handful of separate email attachments the family hopes adds up to everything relevant needed.
A share expires after its set time or view count, so a document sent for one appointment doesn't remain quietly accessible to anyone months or years later on.
The family can see exactly what was shared, with whom, and when, rather than losing track of which clinician has which version of a father's history over time.
The detail
This capability only ever packages and transmits documents the family has already organised elsewhere in the app — it adds a cover index listing what's included in the bundle, not a written clinical summary of what any of it actually means. A specialist receiving a shared bundle sees exactly the same reports and prescriptions the family has on file, laid out with an index for convenience, never accompanied by a synthesised account Doctor has no clinical basis to write.
An expiring, single-purpose share link is materially safer than a permanent one, but that safety depends entirely on the expiry and revocation logic being enforced on every access check at the server level, not simply hidden from view on the recipient's screen alone. A family sharing a father's records with a new specialist should be able to trust the link genuinely stops working once it expires or is revoked.
What stays outside Doctor's control entirely is what a recipient does with a link once they already have it — a specialist forwarding a 'private' link to a colleague is a use the sharing mechanism cannot prevent after the fact. Because of that, the share-creation flow makes the time-limited, single-recipient nature of the link explicit before it's sent. Access logs themselves are treated with care, with identifying details like IP addresses stored in hashed or truncated form rather than kept raw.
Industry use cases
2 industries where Doctor applies this directly.
A freelance graphic designer uploads a lab report after a routine checkup, and Doctor files it under their profile and lets them draft three questions to ask at the follow-up appointment about a result they didn't understand, without the designer needing to interpret the report themselves or rely on Doctor to explain it.
See the freelancers and consultants playbookA person managing a parent's post-hospitalization care uploads the discharge summary, several follow-up lab reports, and the current medication list into one family profile, sets reminders for each medication's timing, and generates a visit brief ahead of the follow-up appointment so the family doesn't have to recall everything from memory in the waiting room.
See the health and wellness playbookMore from Doctor
The person sees every report, prescription, and visit they've uploaded laid out in date order instead of as a loose pile of files.
Learn moreThe person adds a paper prescription or report to their record in seconds by taking a photo, instead of typing it in by hand.
Learn moreOne person — often a caregiver — can organize records for their parents, children, or in-laws separately, without mixing up whose test is whose.
Learn moreA person managing an elderly parent's records can invite a sibling to view or help, and can cut off that access instantly if circumstances change.
Learn moreThe person can see a lab report's parameter names, values, units, and reference ranges as clean text instead of squinting at a scanned PDF.
Learn moreThe person can see how one specific lab value has moved across multiple visits without manually flipping between old reports.
Learn moreQuestions
No — the bundle includes an index listing which documents are included, but Doctor never writes a clinical summary describing his condition to accompany that index for the recipient reading it later. Everything the specialist receives is exactly what's already in the family's own organised records, with the index simply making the contents easier to navigate quickly and clearly for anyone opening it.
You set the expiry when creating the share — either a time period or a maximum number of views, whichever suits the particular situation — so a link made for one appointment can be set to stop working shortly after that appointment would reasonably be expected to happen. You can also revoke a share early at any point before its set expiry if circumstances happen to change.
That's outside what the sharing mechanism can actually control once a link has already been sent out — Doctor makes the time-limited, single-recipient nature of the link explicit before you send it, but it can't physically prevent a recipient from forwarding it further afterwards. This is worth keeping in mind when deciding how sensitive a particular share should be, and whether a shorter expiry or fewer allowed views suits it better.
Yes — every access to a shared bundle is logged, showing when it was opened, and you can revoke the link early if you want to end access before its normal expiry arrives naturally on its own. This gives you a clear record of exactly what's been shared and accessed, rather than losing track of who has which version of your family's records over time.
The rest of your stack
No rip-and-replace — share or export records with a clinician works alongside the systems already running your business.
Coming soon