Healthcare & Beauty
How Techparser Built a Multi-Location Clinic Management System for Cosmetic Clinics
Techparser built a multi-location clinic management system for cosmetic clinic chains: bookings, consents and batch-tracked stock, live in production.
- Client
- Beauty and cosmetic clinic chains (Australia)
- Industry
- Healthcare & Beauty
- Timeline
- Live in production
- Team
- 1 senior full-stack engineer
Results
- 4 states
- Stock: in stock, out, expired or recalled
- Per batch
- Medicine tracked by batch, location and expiry
- SOAP
- Signed healthcare-identifier integration per practitioner
The problem
Beauty and cosmetic clinic chains run several locations under one brand. Each location books treatments, keeps patient records and holds its own stock, while the chain sets the treatments, paperwork and products every location uses. The system includes a staff app and a public online-booking site over one API. Many cosmetic treatments use prescription-only injectables, so each treatment has to be tied to a prescribing practitioner's authority and the patient's consent under Australian healthcare-identifier rules. The stock is regulated medicine that expires, can be recalled, and moves between locations.
The system is live in clinics treating real patients. A missing or expired consent, or medicine used past its expiry, is a clinical and regulatory failure, and patient records are sensitive health data. Techparser built the controls so that treatment can only follow a valid authority and expired items stop being offered automatically.
What Techparser built
- Treatments, consent and medical-history templates, products and payment types are set once for the chain, while each location keeps its own hours, address and stock. A new location starts with the chain's paperwork.
- A patient can belong to several locations, with a credit balance and payment log, and every view of their record is logged with who opened it and when.
- Stock is tracked per batch and location, with received and expiry dates and a status of in stock, out, expired or recalled, and every use, reversal, status change and transfer is logged against the user, patient and booking.
- Scheduled jobs mark expired batches, consents and medical histories, so expired items stop being offered without anyone remembering to check.
- Each practitioner consent links the patient, location, prescribing practitioner, treatment protocol and script, with its own expiry and signature, so treatment can only follow a valid authority.
- Consent forms and medical histories are generated as signed PDFs from the chain's templates and expire on schedule.
- Practitioners' national healthcare identifiers are verified through a signed SOAP integration with the Australian healthcare-identifier service.
- Booking reminders and treatment follow-ups go out by SMS and email on schedule, with marketing opt-outs respected, and only one server instance sends them so nobody is messaged twice.
- Reports export to CSV and practitioner payouts export as bank direct-entry files, guarded so the same day's file is never generated twice. Nurses, dermal therapists and doctors each have their own roles, with administrator variants.
Decisions that mattered
Chain templates, location operations
A chain sets the treatments, consent and medical-history templates, products and payment types every location uses, while each location keeps its own hours, address and stock. Techparser built the data model around that split so a new location opens with the chain's paperwork already in place, and a patient can belong to several locations with one credit balance and payment log. The trade-off is that chain-level changes ripple to every location, so templates carry versions and expiry rather than being edited in place. The gain is consistency: every location treats patients under the same approved protocols.
Consent as a gate on treatment
Many cosmetic treatments use prescription-only injectables, so a treatment cannot be a free action. Techparser made each practitioner consent link the patient, location, prescribing practitioner, treatment protocol and script, with its own expiry date and signature. Treatment can only follow a valid authority, and consent forms and medical histories are generated as signed PDFs from the chain's templates. Practitioners' national healthcare identifiers are verified through a signed SOAP integration with the Australian service. The decision was to encode the regulatory rule in the data rather than trust staff to check it, so a missing or expired consent blocks treatment by default.
Expiry and recalls handled by the system
Stock here is regulated medicine that expires, can be recalled, and moves between locations, so Techparser tracked it per batch and location with received and expiry dates and a status of in stock, out, expired or recalled. Every use, reversal, status change and transfer is logged against the user, patient and booking, so any dose can be traced. Scheduled jobs mark expired batches, consents and medical histories automatically. The trade-off is the overhead of a full audit trail on every unit; the payoff is that expired items stop being offered without anyone remembering to check.
Outcome
The system is live in production at instanttouch.com.au, running beauty and cosmetic clinics across several locations: bookings, patient records, practitioner consents, stock and reports, with a staff app and a public booking site over one API.
Because the chain sets treatments, consent templates and products once, a new location opens with the chain's paperwork already in place. Because stock is tracked per batch to its expiry and consents carry their own expiry, the system can refuse a treatment without a valid authority and retire expired medicine automatically, so clinical and regulatory rules hold without depending on anyone remembering them.
Questions about this project
- What technology stack does the clinic management system use?
- The system is a React front end over Node.js APIs, with MongoDB for data, hosted on AWS, and Twilio for SMS. One API serves both the staff app and the public online-booking site. The stack supports multi-location data, signed PDF consent forms and medical histories, scheduled jobs for expiry and reminders, and a signed SOAP integration with the Australian healthcare-identifier service.
- How does the system make sure a treatment can only follow a valid authority?
- Each practitioner consent links the patient, location, prescribing practitioner, treatment protocol and script, with its own expiry date and signature. Treatment can only proceed where a valid consent exists, and the paperwork is generated as signed PDFs from the chain's templates. Scheduled jobs mark consents, medical histories and stock batches expired on schedule, so expired authorities and medicine stop being offered automatically rather than relying on staff to notice.
- Can Techparser build a multi-location clinic management system like this for us?
- Yes. Techparser built this system end to end: the multi-location model, stock tracked per batch to expiry with a full audit trail, practitioner consents tied to prescribing authority, signed patient paperwork, SMS and email reminders, reports and practitioner payouts, and the healthcare-identifier integration, live in production. We can build the same for your clinics and your regulatory rules. Book a call to discuss it.









