# Model: MedicalRecord

**Table**: `clinic_medical_records` (new)

## Purpose

The diagnosis, prescription and report a doctor writes for one completed booking. Editable
afterwards, with every edit logged (per the brief: "the doctor can edit the prescription/report
later, with the edit date recorded and the patient notified").

## Fields

| Column | Type | Constraints | Notes |
|---|---|---|---|
| `id` | bigint | PK | |
| `booking_id` | bigint | `foreignId('booking_id')->unique()->constrained('clinic_bookings')->cascadeOnDelete()` | 1:1 |
| `doctor_id` | bigint | `foreignId('doctor_id')->constrained('clinic_doctors')->restrictOnDelete()` | denormalized from `booking.doctor_id` for simpler queries/permission checks |
| `patient_id` | bigint | `foreignId('patient_id')->constrained('users')->restrictOnDelete()` | denormalized from `booking.patient_id`, same reason |
| `diagnosis` | text | nullable | |
| `prescription` | text | nullable | free text/structured — v1 keeps it as text per the brief's simplicity; revisit if a structured drug-list UI is wanted later |
| `report` | text | nullable | |
| `published_at` | datetime | nullable | when the doctor first finalized/shared it with the patient |
| `last_edited_at` | datetime | nullable | updated on every post-publish edit |
| `created_at` / `updated_at` | timestamp | | |

## Relationships

| Relation | Type | Target |
|---|---|---|
| `booking()` | `belongsTo` | `Booking` |
| `doctor()` | `belongsTo` | `Doctor` |
| `patient()` | `belongsTo` | `User` |

## Edit history — reuse `System\ActivityLog`, don't build a new revisions table

Rather than a dedicated `clinic_medical_record_revisions` table, log every post-publish edit to
the existing `App\Models\System\ActivityLog` (already used platform-wide for audit trails),
tagged with the record's `id` and the doctor who made the change. On edit, also trigger a
`NotificationService`-based notice to the patient ("your report/prescription was updated"),
matching the existing notification dispatch pattern (`app/Services/System/NotificationService.php`).

If a structured diff view ever becomes a hard requirement, a dedicated revisions table can be
added later — starting with `ActivityLog` avoids building a second audit system prematurely.

## Decisions

- **Visible to Doctor and Patient only.** Never selected/loaded from any `Admin\Clinic\*`
  controller or service — see `03-permissions-and-roles.md` §4. Super Admin is blocked by
  default too, per the brief ("even Super Admin is prevented from viewing medical file content
  unless granted special access") — if that special-access path is ever built, it should be an
  explicit, logged, opt-in action, not a standing permission.
