Sources and review notes
These links support workflow-level research and do not establish the regulatory status, clinical safety, diagnostic performance, or suitability of any product.
HL7 FHIR R4 models Schedule, Slot, Appointment and AppointmentResponse as related but distinct scheduling resources. HL7 states that a free Slot does not guarantee that an appointment can be made because eligibility, permissions and other resources may still need evaluation, and that complex clinical scheduling may require workflows beyond Schedule and Slot. Appointment represents a planned booking and its participant and overall statuses, while Encounter represents the actual care interaction; requested, proposed, pending, booked, waitlisted, arrived, fulfilled, canceled and no-show states must not be collapsed. These FHIR R4 resources are Trial Use and do not prescribe local appointment types, clinical urgency, referral, authorization, resource combinations, overbooking, waitlist notification, cancellation or access policy. HHS permits treatment-related scheduling and appointment reminders under specified HIPAA conditions, while requiring reasonable safeguards and attention to confidential communication requests. HHS online-tracking guidance warns that appointment dates and information entered in registration or scheduling workflows can be PHI and that tracking-technology disclosures require fact-specific HIPAA analysis; the page also notes the portion of prior guidance vacated by a federal court. HHS effective-communication resources and DOJ web-accessibility guidance identify disability and language-access considerations, but applicable legal requirements depend on the entity and circumstances. These sources do not validate a scheduling vendor, authorize symptom triage, prove identity, eligibility or appointment appropriateness, or guarantee access, booking success, shorter waits, reduced no-shows, privacy, accessibility or compliance. Buyers should define each bookable service, appointment type, duration, location, modality, practitioner, equipment and room, eligibility and age restrictions, new or established status, referral and authorization prerequisites, visit-preparation requirements, release window, hold and overbooking rules, timezone, lead time, cancellation and rescheduling rules, waitlist priority, clinical and urgent escalation, non-digital channel, source system and final booking authority. Displayed availability, requested time, held slot, proposed appointment, participant acceptance, confirmed booking, reminder delivery, patient acknowledgement, arrival, encounter, cancellation and no-show must remain separate auditable states. Acceptance testing should include normal and peak demand, concurrent requests for the last slot, multiple sites and timezones, daylight-saving changes, group and recurring visits, resource combinations, reserved and overbooked slots, new and returning patients, minors and proxies, similar identities, referrals and authorizations, inaccessible or wrong visit types, appointment changes, waitlist offers and expiration, duplicate bookings, provider leave, clinic closure, wrong contact data, opt-outs, urgent or ambiguous requests, interface latency, stale caches, partial writes, retries, outages, reconciliation and manual fallback. Measure search and booking task success, stale-slot and collision rates, duplicate and wrong-patient events, booking-write acknowledgements and reconciliation failures, time to next available appointment by service and relevant population, waitlist offer and conversion with defined denominators, cancellations and no-shows against eligible booked visits, rescheduling and abandoned requests, wrong-type bookings, referral and authorization exceptions, accessibility defects, clinical escalations, staff touches and queue age, calls by reason, complaints, privacy incidents and actual encounters. Slots displayed, bookings initiated, messages sent, call deflection, average wait or predicted no-show risk can hide unavailable services, selection, distributional differences and shifted workload and are not causal proof of access or efficiency. Systems should preserve the source schedule and slot state, rules and versions, requestor and patient or proxy identity, appointment and participant statuses, reason and restrictions, timestamps and timezones, write acknowledgements, reminders and preferences, staff actions, cancellations, corrections, audit and support access logs. Keep atomic booking or conflict controls, reversible writes, tested downtime and clear clinical and emergency handoff. Automation must not double-book silently, infer clinical urgency or eligibility, expose sensitive appointment context unnecessarily, prioritize patients using unapproved proxies, cancel confirmed care without accountable review, or block access solely because a digital workflow failed.