Hospital management system · Kenya

Hospital management system for clinics, hospitals and labs in Kenya

Patient records, billing, M-Pesa, insurance claims, pharmacy, lab and payroll in one system your whole team shares.

Everything a clinician orders lands on the patient’s bill by itself. Insurance claims leave complete, and payments reconcile the moment they arrive. You see today’s takings, queues and stock as they happen, across every branch.

Free trial from 7 days. Nothing to pay until it ends.

  • M-Pesa and insurance claims built in
  • Every branch on one system
  • PAYE, NSSF, SHIF and housing levy payroll
One visit, one record Example
  1. ReceptionPatient registered, KES 500 deposit taken
  2. DoctorConsultation notes, full blood count ordered
  3. LabSample run, result back to the doctor
  4. PharmacyPrescription dispensed, stock updated
  5. BillingEvery item above already on the invoice
  6. PaidM-Pesa confirmed, receipt sent

Built for

Every kind of facility, one system.

From a single chemist to a multi-branch hospital, SmartCare runs on the same shared record, set up around the way your facility actually works.

  • Hospitals

    Wards, theatres, labs, pharmacy and the ledger on one record, from admission to discharge.

  • Clinics

    Queue, consult, prescribe and bill in minutes, with M-Pesa and insurance on every visit.

  • Medical centres

    Several departments or branches under one roof, each site’s stock and takings kept apart.

  • Laboratories

    Orders arrive from the chart, results go straight back to it, and every test is billed.

  • Diagnostic centres

    Imaging and procedure orders, reports and referrals, each charged to the right visit.

  • Pharmacies & chemists

    Dispensing, reorder levels and stock-out forecasts, well before the shelf is empty.

The difference

One system, so your numbers finally agree with each other.

A purchase order and a journal entry match because they were never two separate products stitched together after the fact. One record, one set of books, one login — nothing to reconcile at month end.

Counted in the demonstration database

1,500
Patientsacross 4,966 visits, 755 admissions and 3,865 triage assessments
20,338
Ledger entriesfrom 5,914 double-entry transactions, posted by billing and procurement
67,317
Logged writesevery create, update and delete, with actor, IP and before/after values
7,596
Diagnostic orders2,546 lab, 1,685 imaging and 3,365 procedure orders, all on the same visits
Clinical Pharmacy Lab Imaging Supply Ledger Roster Messages ONE RECORD
Every module writes to the same record — and is logged doing it.

Modules

Thirteen modules, grouped the way the software is.

These are the four areas of the application’s own navigation, and every module inside them.

Clinical

Dashboard & Patients

The whole of a person’s care on one timeline, and the state of the building on one screen.

  • Dashboard — occupancy, waiting times, staff on duty and revenue, live
  • Patients — demographics, identifiers and medical history
  • Visits, admissions and discharge on the patient record
  • Triage assessments with ESI acuity scoring
  • Clinical notes, diagnoses, allergies and vitals
  • Lab, imaging and procedure results filed back to the patient
  • Insurance providers and claims against a visit

Operations

Wards, Visits, Pharmacy & Procurement

The day-to-day: who is in which bed, what was given to them, and what it consumed.

  • Wards — facilities, departments, rooms, beds and bed categories
  • Visits — triage, physician queue, procedure orders and visit charges
  • Pharmacy — medications, prescriptions and dispensing
  • Inventory with batches, expiry and stock-take sessions
  • Procurement — suppliers, purchase orders and goods receipt
  • Vendor bills and their payments, posted to the ledger
  • Equipment and medical device registers per facility

Finance

Accounting, Payroll & Pricing

Double-entry underneath, so the statements come out of the same books the wards write to.

  • Accounting — chart of accounts, journals and financial statements
  • Invoices, payments, receipts and expenditure
  • Payroll — runs, payslips, PAYE bands and locum rates
  • Pricing — the price list behind procedures, labs and imaging

Administration

Staff, Shifts, Catalogues & Settings

Who works where, when — and every list the rest of the system chooses from.

  • Staff — directory, facility postings and secondments
  • Shifts — station templates, rosters, swap requests and leave
  • Data catalogues — lab tests, imaging, procedures, devices, templates
  • Settings — users, permissions, tax, currency, time zone, messaging

Across every module

Communication, audit and access

Not a module of its own — these run underneath all thirteen.

  • Email, SMS and WhatsApp from any patient or staff record
  • Automatic receipt and invoice delivery on payment and issuance
  • Reusable message templates with attachments
  • Activity trail on every write: actor, IP, before and after
  • Role-based access with per-account permission overrides
  • Six interface languages, and per-facility regional settings

Integrations

Meet the systems you already run.

Native where it matters, and the same authenticated API the interface itself uses for everything else.

Analysers & lab systems

An HL7 gateway takes orders out to your analysers and middleware and brings results back in, with the chain of custody recorded at every hop.

Pharmacy & stock

Dispensing and administration deduct from inventory as they happen, so stock levels are a consequence of the clinical record rather than a separate count.

Payments

M-Pesa, PayPal and Stripe alongside cash, card and bank transfer — recorded as payments against an invoice, with receipts issued automatically.

Email, SMS & WhatsApp

Your own SMTP relay, Twilio or Africa’s Talking for SMS, and WhatsApp — invoice delivery, receipts and reminders go out on whichever you configure.

Accounting

The ledger is built in rather than synced to: procurement and billing post their own double-entry journals, and the statements come out of the same books. Export to CSV for your auditor.

REST API & webhooks

Every module is reachable over the same authenticated API the interface uses, with webhooks for pushing events out to systems of your own.

Working with something not listed here? Tell us what it is — the API is the same one the product is built on, so most things are reachable.

Security

So no one can quietly change a record on you.

Not a wall of badges — the specific protections built in, and what each one means for your liability if something ever goes wrong.

Every write is logged

Not per-screen, and not opt-in: the audit trail is written at the database layer, so every create, update and delete is captured with the actor, their IP address, and the before and after values.

Clinical chain of custody

Lab results and imaging studies carry their own trail on top of that one — received, processed, sent, viewed, amended — so you can answer who saw a result, and when.

Passwords are never stored

PBKDF2-HMAC-SHA256 at 210,000 iterations with a per-password salt — OWASP’s current floor. The cost is recorded alongside each hash, so it can be raised later without invalidating anybody’s password.

Permissions, not just roles

Every endpoint is gated on a named permission rather than a job title, and any account can be granted or denied one individually — so the ward clerk who also does the banking does not need a second login.

Sessions you can end

Access tokens are short-lived and refresh tokens are revocable, rotated on every use and cancelled wholesale if a spent one is replayed. Disabling an account cuts off its sessions on the very next request.

Guessing gets you nowhere

Sign-in is rate limited per address and each account locks itself after repeated failures — tuned so a shift change arriving together is not mistaken for an attack.

Certification against a specific standard — HIPAA, ISO 27001, SOC 2 — is a property of a deployment and its operator, not of software on its own. If you need to reach one of those, talk to us about what your environment would have to look like.

Pricing

One price for the whole product. Add only what you need.

The base price covers the core system and every operational feature. Paid add-ons are extra, and priced to the size of your facility.

  • Shared service

    • Every client signs in at the same web address.
    • Each client’s data is kept separate from every other client’s.
    • Nothing to install: we run it, and hosting is included in the price.
  • Your own installation

    • A web address only for you, or your own domain.
    • The support ticketing system, for raising issues and following them up.
    • Run by us in the cloud (the cheaper option), or on your own servers for large hospitals.
    • Hosting is billed to you; our price covers the installation, updates and support. A one-off setup fee is charged on the first invoice.

Prices are loaded from our live price list. If they do not appear, contact sales for a quote.

Before you ask

The four questions everyone has.

How long until we’re actually running?

Most facilities go live in 2–4 weeks. We spend one week learning your workflow, one to two weeks setting up the system and moving your data over, and one week training your team. After that, you’re running — no prolonged parallel operation unless you want one.

Multi-site rollouts usually take 6–8 weeks with a phased go-live so you can learn on one site before rolling out to others. Spreadsheet migrations take a few days; moving from a legacy system can take 1–2 weeks, and we always do a dry run first so you see exactly what to expect.

Will it work with the lab and pharmacy systems we already have?

Almost certainly yes. We have pre-built integrations for most common equipment and systems: lab analysers, payment processors (M-Pesa, Stripe, PayPal), and messaging (SMS, WhatsApp). If you have something less common, we can build a connection using our API — the same API the entire product runs on.

See the full list of integrations →

What happens to our data if we leave?

Your data is yours, forever. You can export everything — all your patient records, transactions, everything — at any time in formats you can open (CSV, JSON, SQL). No questions, no exit fees, no tricks. Give 30 days’ notice and we help with the export as part of offboarding.

Is our data safe, and can you prove it?

Yes. Every single action is recorded. Who did it, when they did it, what they changed, and from where — so no one can quietly change a record or a price without you seeing. Our audit trail is not optional or per-screen; it’s built into the database and captures every write.

For passwords, we use industry-standard PBKDF2-HMAC-SHA256 hashing. Sessions are revocable, and every screen and API endpoint is gated on a named permission you can override per staff account.

See our full security practices →