← The Protokol
The Operating System

What an operating system for a cash-pay clinic actually is — and what a "suite" isn't

By Tom Higgins — I run Zvia, my Lakewood medspa, on the tool behind this.

Every clinic-software demo looks the same for the first ten minutes. A booking screen. A chart. A slick payment flow. A dashboard with your logo on it. It is easy to walk away believing you just saw one system.

Then you go live, and on the third Tuesday you watch your front desk type the same patient’s name, date of birth and allergy list into a fourth screen before the first appointment of the day. That is the moment you learn what the demo hid: the login page was the only thing those tools ever actually shared. There is a plain test that would have told you on the call. It takes about ninety seconds, and it works on any vendor.

A suite shares a login. An operating system shares a record.

A suite is several products bundled and sold together — often bought by the vendor, not built by them — each with its own database, stitched together at the surface by a single sign-on and, if you’re lucky, a nightly sync. It looks unified because someone designed one login screen and one color palette across the top.

An operating system is one record. A patient is entered once, and every function — booking, chart, dispensed vial, charge, follow-up — reads and writes to that same record. The difference isn’t the branding or the number of features. It’s whether a fact entered in one place is instantly true in every other place, with nobody re-keying it and no sync job that can silently fail overnight.

Sync is the tell. When a rep says two parts of the product “sync,” they are telling you there are two copies of the truth that are usually the same. An operating system has one copy.

Three questions to run on any demo call

Ask the rep to create a new patient in front of you. Enter a name, a date of birth, an allergy. Then stop watching the screens they want to show you, and ask these three. The answers separate a record from a bundle every time.

  • Does the chart write to the ledger? When the clinician signs a note that includes an injection, does a charge appear on that same patient’s account without anyone re-typing it — and does that charge land in the same books your accountant reads at month-end? If the note lives in the EHR and the charge lives in a POS that “exports a report,” that’s a seam, and reconciliation leaks through it.
  • Does the vial deduct at dispense? When the injector draws this week’s rung of the GLP-1 ladder — a partial vial, measured in units off a multi-dose vial at a known concentration, not a whole dose — does the remaining balance on that exact lot drop by what was drawn, tied to that chart and that charge? Or do you count the drawer at 8pm and hope the number matches? Most generic systems dispense in whole units and struggle with the decimal, partial-vial math this business runs on.
  • Does the good-faith exam live on the same record as the e-Rx? When the clinician performs the GFE — the screening, the versioned consent, the dated sign-off — and the prescription follows, are they rows in one patient’s record, or does the exam sit in the chart while the script goes out through a separate e-prescribing tool that never met it? The same question applies to your medical director’s oversight: is the per-patient, time-stamped sign-off — and the delegation of who may do what, MA, RN, NP or PA — recorded against the same chart, or asserted in a signed agreement in a drawer?

None of this is legal advice, and the rules for a GFE, for delegation and for supervision vary by state — only a state board or HHS OCR determines whether a given practice is compliant. But the documentation question is the same everywhere: could you produce the exam, the consent and the sign-off, on the same record as the treatment, eighteen months from now?

The seam is where the money and the license leak

Everything expensive happens in the gap between two tools. The charge that never crossed from the chart to the books. The partial vial that got drawn but never deducted, so your true margin on a $1,000 vial is a guess. The good-faith exam that genuinely happened but can’t be produced next to the e-Rx when a board reads the chart a year and a half later.

On a normal day the seam is invisible. It only shows itself on the day you can least afford it — the reconciliation that won’t tie, the inspection, the diligence call before a sale. A suite hides its seams behind a shared login. An operating system doesn’t have them to hide.

Why I built one instead of buying one

I’m Tom. I run Zvia, a cash-pay med spa in Lakewood, Colorado, and I build the software this site is about. The first EHR I bought for my own clinic was built for insurance billing — CPT codes, claims, superbills, the whole apparatus for filing with a payer. A cash-pay practice files none of it. The dispensing, the memberships, the GFE-before-e-Rx flow, the partial-vial GLP-1 math — it fit none of how my clinic actually ran, so I stitched five tools together and became the integration myself, re-keying patients at 11pm.

Nothing fit, so I built the thing that did. ProtokolIQ is the operating system I ended up building for exactly this: a patient is entered once, and the chart, the dispensed vial, the charge and the good-faith exam all live on one record, so a fact entered in one place is surfaced everywhere it’s needed.

You don’t have to take my word for any of it. Take the three questions to your next demo, and watch how fast a suite runs out of answers.

When you want to see where your own practice stands, the Clinic Freedom Score walks you through it in a few minutes — or see the platform. Not a minute before.