Reference codes, not records
A hospital runs on movement: a bed that needs turning over, a patient who needs portering, a door that needs security. push.tt coordinates the people doing that work by room, bed and ticket code — and is built so clinical detail has nowhere to land in the first place.
What this is, and what it is not
Read this part first, because it decides whether push.tt belongs in your organisation at all.
- push.tt is not HIPAA-certified and is not sold as a compliant system of record. We do not offer a business associate agreement today.
- It is operational coordination for the teams around care — porters, housekeeping, transport, security, estates and facilities — not a clinical system.
- Nothing here integrates with an EHR, and nothing here is designed to store patient information.
The honest boundary: the coordination layer is built so that clinical detail is structurally hard to put into it, which is a different and more useful claim than a certification badge. Keep records in the systems your governance already approves.
A ward is a channel
Press, talk, release — the porters' team, the housekeeping floor, the security desk, each on its own channel, reaching a whole shift in the same second without a corridor phone call or an overhead page that the whole ward hears.
- One speaker at a time, arbitrated by the server, so a busy handover stays intelligible
- Private and company channels are locked to your own handsets; push.tt carries them without being able to listen
- Earpieces and a held button keep coordination out of patients' earshot, unlike a speakerphone or a public address
Portering, by code
A porter request goes out from the console as a job carrying a location and a reference — ward, bay, bed, ticket number. The desk watches it move instead of ringing round to ask.
- Jobs move through assigned, en-route, arrived and completed, so the state of every request is on one board
- The job body is end-to-end encrypted between the console and the handset; the server relays it without reading it
- Optional evidence — a photo or a note — attaches over the same encrypted paths, and the server records only that evidence was attached
The design intent is that a job says “Ward 6, bay 3, ticket 4471” and never a name or a condition. What a code means stays inside the systems and the people who already hold that information.
Events from your own systems
Bed management, estates ticketing and housekeeping platforms can post events straight to push.tt over a token URL, so a turnover request reaches the floor without anyone retyping it.
- The intake accepts coded events only — fixed event names, short reference codes, numbers and pre-agreed options. Free text is refused outright, so prose cannot arrive through this door.
- Events land in a queue for a coordinator to act on. Nothing is auto-dispatched, and turning an event into a job is a person's decision.
- Queued events are readable by the push.tt server, and are deleted on a retention window the organisation sets. Your conversations stay end-to-end encrypted throughout.
Structure is enforced; meaning is yours. The intake cannot accept a sentence — but a reference code chosen to encode somebody's name would carry that meaning anyway, so code schemes remain the integrating organisation's responsibility.
Rosters for teams that never stop
Wards, portering pools and support teams run around the clock, and the roster is where that either works or falls apart.
- Published schedules on every handset, open shifts anybody eligible can claim, and shift trades that can require a manager's approval before they take effect
- Clock in and out from the handset, with a payroll export that carries hours and site-distance flags — never coordinates
- Position-stamped punches exist only if the organisation switches them on through a consent gate; those reads are audited and the coordinates are deleted on the organisation's location retention window
When something goes wrong
Emergency is a persistent session rather than a chime. It overrides Busy, Solo and channel mute, and remains active until somebody with permission clears it.
- Raise, acknowledge and clear are separate actions, each written to the audit trail
- The person raising the alert takes the floor even when someone else is speaking
- Abuse controls and an organisation-level off switch are enabled by default
push.tt is operational coordination over commercial data networks, not a certified public-safety or clinical alarm system. Keep crash calls, nurse call and statutory alarms on the equipment and procedures required for them.
Start with one team
A portering pool or a housekeeping floor is enough to see whether the coordination holds up on a real shift.