Docuity Chat
Secure team messaging for clinical staff, free and part of the Docuity suite — channels and DMs with an option to make a workspace fully end-to-end encrypted, plus light touches into the rota and the chart without switching apps.
- Your choice
- server-held or end-to-end, per workspace
- No names in-channel
- patient references never show who
- Installs like an app
- works on a clinic phone, offline-aware
The problem
Clinical teams end up coordinating over personal WhatsApp or text messages, outside any record and on staff's own devices. Docuity Chat, part of the Docuity suite, gives them a proper team chat built for the job, with encryption strong enough to opt into fully.
What it does
Docuity Chat is free, part of the Docuity suite. Channels for a team, ward, or topic, plus direct messages, with what any team chat needs day to day: threaded replies so a side conversation doesn't flood the channel, emoji reactions, drag-and-drop file and image sharing, @mentions, typing indicators, read receipts, and full search.
Every workspace picks its encryption when it's created. The default keeps messages encrypted at rest but lets the server search and recover a lost history; the alternative is fully end-to-end — a key generated in the browser that the server never sees, with the honest tradeoff that losing the key loses the history and search then runs only on your own device.
A private conversation, just for you, can look up a colleague's rota shifts or on-call status, or pull a quick AI-drafted summary of a patient when asked for by chart number — never posted to a shared channel, and never showing anything a clinician couldn't already get by opening the record directly. A few light commands reach across the suite without switching apps: check who's on call, request a day off from the rota, or claim an open shift, each shown as a plain confirm-and-submit card.
Key features
Channels, DMs, and threads
A channel per ward or team, direct messages for the rest, and threaded replies so a side conversation doesn't take over the main channel.
Choose your encryption, per workspace
Most teams want search and recovery, so that's the default — but a workspace that needs it can go fully end-to-end, where even Docuity can't read the messages.
Files, reactions, mentions, read receipts
The everyday texture of a real team chat — drag-and-drop attachments, a quick emoji instead of another reply, @mentions that actually notify someone, and knowing a handoff was seen.
A private assistant, just for you
Ask your own shifts, who's on call, or a patient's chart number, and get an answer only you see, never posted to a shared channel.
Reference a patient without exposing them
Typing a chart number in a message shows only a small linked reference, never a name — clicking it opens the real chart, and only for people who already have access to it.
Check the rota and claim shifts without leaving chat
Ask who's on call, request leave, or claim an open shift right from the conversation, shown as a card to review and submit, never sent on its own.
Where it stands
A staff coordination tool, not a medical record. Like the rest of the suite, it makes no HIPAA-certification, SOC 2, or Business-Associate-Agreement claim — only end-to-end workspaces are unreadable by the server, and that mode is opt-in, not the default.
Under the hood — for the technically-minded
How it's built
Message content is end-to-end encrypted only when a workspace is created that way; otherwise it's encrypted at rest with the server holding the key, which is what makes search and recovery possible for ordinary teams. Attachments follow whichever mode the workspace uses.
Cross-app requests — the rota lookup, the patient summary — go out carrying the asking staff member's own sign-in, not a shared service credential, so the receiving app enforces that person's real permissions and logs the request against them, not against 'Chat' in general.
A small message-formatting layer renders bold text, links, and the interactive rota and patient references from a whitelist of known patterns rather than by trusting raw content, so a message can carry a clickable action without opening the door to arbitrary content.
The hard problems
Patient information stays out of the shared channel, structurally
A patient reference typed into a message shows only a chart number, never a name — and any AI-generated summary of a patient's history is delivered solely to the person who asked, in their own private conversation, never into the channel it was requested from.
Cross-app actions run as the person who asked, not as 'Chat'
Checking the rota or pulling a patient summary forwards the asking person's own sign-in to the other app, so it enforces their real access and records the request under their name — Chat is never granted a standing, all-access key into EHR or the rota tool.
End-to-end, honestly
Choosing end-to-end for a workspace means the server genuinely cannot read it, which also genuinely means no server-side search and a real risk of losing history if every member loses the key. Both tradeoffs are stated up front, not discovered later.
Built with
- React Router 7
- Drizzle
- Postgres
- Redis
- Passkeys
Building something in this space?
Work with us →