Riverr Flow

Questions about Riverr Flow

Questions about Riverr Flow

Riverr Flow is the automated release layer for health-screening reports. Assemble when the set is complete. A named doctor signs. Employers receive aggregates only.

This page answers the questions clinic owners, medical directors and procurement usually ask first. It does not replace a conversation. Pricing, connection design and security questionnaires stay in that conversation.

Private pilot with a Singapore health-screening provider.

Hosting & DPO

Where is data hosted, and how does Riverr treat PDPA?

Data for the service is hosted in Singapore. Documented exceptions go to the clinic’s DPO. The clinic owns its patient records and clinical content. Riverr processes that data to provide the product. Personal data follows a Singapore PDPA posture agreed with the clinic’s DPO. This page does not name a cloud host or claim a certification.

What does the clinic own versus what Riverr owns?

The clinic owns its patient records and clinical content. Riverr owns the platform, software, and related intellectual property. Using Riverr does not transfer ownership of clinic or patient data to Riverr.

Product

What Riverr Flow is, how release works, and what it refuses to invent.

What is Riverr Flow?

Riverr Flow is the automated release layer for health-screening reports. It is a health-screening report generator: assemble when the result set is complete, hold for a named doctor, then release. Patients receive their copy in My Health. Employers receive aggregates only in Workforce Health. It is not a laboratory and not a practice-management system.

What is Clinic Console?

Clinic Console is the planned clinic admin and onboarding surface above Care Studio. It is design only; not a finished portal. Riverr configures packages and sign-in with the clinic during onboarding — on the clinic’s behalf or alongside the clinic’s own administrators — until that door has a live host. Continue on that door opens Talk to Riverr until a host is published. Clinic Console sits in the Riverr Flow release layer. It does not review or release reports. Riverr Flow is not a medical device: it copies laboratory flags and doctor decisions; it does not diagnose, triage or compute a clinical status.

How does Clinic Console differ from Care Studio?

Care Studio is the surface for doctors and the clinic team: queue, holds, critical protocol, review and release. Screens for Care Studio exist in product source and design. Clinic Console sits above Care Studio as the planned admin and onboarding door — packages and sign-in — not the queue, not review, and not sign-off. Each public portal is a separate application with its own sign-in; there is no switcher between them. Clinic Console does not replace Care Studio and does not release reports. Neither surface computes a clinical status.

Is Clinic Console live?

No. Clinic Console has no live host yet; it is not a finished portal. Continue on that door opens Talk to Riverr until a host is published. No end-customer portal is listed here. Screens for Care Studio, My Health and Workforce Health exist in product source and design; Clinic Console is design-only for now. Riverr Flow is in a private pilot with a Singapore health-screening provider. Until that door has a live host, onboarding is handled with Riverr.

Is Riverr Flow a medical device?

No. It copies laboratory flags and doctor decisions. It does not diagnose, triage, or compute a clinical status.

How does release work?

When the result set is complete, Care Studio assembles the health-screening report in the clinic’s template. A named doctor reads it and signs. Until then every page carries a SPECIMEN watermark. The source is locked before release. Critical results leave the automatic path and follow the clinic’s protocol.

What is the SPECIMEN watermark — unsigned vs signed?

Until a named doctor signs, every rendered page carries a SPECIMEN watermark. An unsigned copy cannot pass as signed. After sign-off, the signature is bound to the document that was reviewed.

What happens if a result changes after the report is generated?

The source is locked before release. If a result changes afterwards, the released document stays as signed. The change is shown for separate review. It is never merged silently into what already left.

When is a report ready for doctor review?

The report assembles when the result set is complete, against a 15-minute design target. That is a design and contract target only — not a measured production result, and there is no live turnaround claim. Held cases are counted in the clock rather than hidden.

Can the report carry our brand?

Reports use the clinic’s own template: cover, wording and ranges follow what the clinic sets. Brand presentation on patient and employer surfaces follows that identity. Delivery uses the clinic’s sender name. Self-service white-labelling and custom domains are not claimed on this page.

How do you stop employer reports exposing individuals?

Employers see aggregates only. Any group smaller than ten is suppressed (k≥10). Membership of an employer group never authorises an individual’s clinical result.

What about our medical director’s veto?

The platform never computes a clinical status. Source is locked before release. Critical results leave the automatic path. Content is signed off before use. Only a named, registered doctor releases — as design intent for the composed release path. We do not claim FDA, CE, SaMD, or “clinically validated.”

Who sets holds and risk tiers?

The clinic. Holds and risk tiers are configured and signed by the clinic. They are not Riverr clinical rules. Critical results leave the automatic path and follow the clinic’s protocol.

Why are there separate portal sign-ins?

Care Studio is for doctors and the clinic team: queue, review, and release. My Health is the patient copy of a released health-screening report. Workforce Health is employer aggregates and statements. Clinic Console is planned admin above Care Studio. It does not review or release reports. Each portal has a separate sign-in.

What does SPECIMEN mean on a report page?

Until a named doctor signs, every rendered page carries a SPECIMEN watermark. An unsigned copy cannot pass as signed. After sign-off, the signature is bound to the document that was reviewed.

Do you offer Chinese-language reports? What about audit evidence of release?

Reports are issued in English. Simplified Chinese output is deliberately refused until a signed Chinese content set is approved by the clinic’s medical director — Chinese is not a toggle.

Release evidence binds the reviewed copy, signature and signed copy together, with an append-only audit posture for privacy-sensitive actions. Treat “complete production audit certification” as something we do not claim on this page; ask for the trust answer sheet for questionnaire detail.

What is Report Studio?

Report Studio lives in Care Studio. It is where the clinic manages report templates, screening packages and coverage, and content sign-off bound to a named responsible doctor — so the released document uses layout and wording the clinic owns.

What is Composer for workforce reports?

Composer builds a corporate client’s workforce report: choose and reorder sections, apply a theme within guardrails, check privacy guarantees, and publish a version. Numbers stay signed from the screening pipeline — they are not edited in the studio. Talk to Riverr about rollout.

What are Clinical AI notes †?

A scribe drafts commentary for the health-screening report. A named doctor accepts, edits, or refuses before release. Laboratory flags and doctor decisions remain the clinical source. No measured time-save percentage is claimed.

Trust / PDPA / Singapore

Residency posture, certifications we do not claim, and portability of what was released.

Where does data live, and who is controller?

Data for the service is hosted in Singapore. Documented exceptions go to the clinic’s DPO. The clinic owns its patient records and clinical content. Riverr processes that data to provide the product. Personal data follows a Singapore PDPA posture agreed with the clinic’s DPO. This page does not name a cloud host or claim a certification.

Do you claim PDPA certification or SOC 2 / HITRUST?

No. We do not say “PDPA certified” or “PDPA compliant”. SOC 2 and HITRUST are not claimed on this page. Security evidence is shared in questionnaires and contracting. Compliance remains the clinic’s determination. Sub-processors are not listed here; they are disclosed on request in security questionnaires.

Can we get data out if we leave — is there a FHIR export?

FHIR R4 export of released reports is part of the product — source export preserves portability, with consent and release checks at download. Portability is scoped to what was released. We do not say “certified FHIR,” and we do not claim integration with any named receiving system. Export acceptance is discussed in a sales conversation.

Getting started

Stage of the product, how clinics begin, and how connections are discussed.

How do clinics start?

Private pilot with a Singapore health-screening provider. Terms are confirmed in conversation.

Which laboratories and clinic systems can connect?

Connections are agreed in the pilot. This page does not list suppliers.

Commercial

Pricing and pilot terms stay in conversation — not on this page.

What does it cost, and what is the pilot?

Pricing is provided in a conversation — not on this page. A private pilot with guided go-live is the path to first use; fee and duration lines are not published here. Riverr Flow is sold by Riverr Pte Ltd via the riverr.net lane.

Still deciding? Talk to Riverr, or read the clinic-owner story.

Start a conversation on the riverr.net lane, open the clinic-owner page, read how it works or trust posture, or use the front door for sign-in and the guided walkthrough.