# Model: PatientProfile

**Table**: `clinic_patient_profiles` (new) · 1:1 extension of `App\Models\User` (guard `web`, reused as-is)

## Purpose

Turns an existing site customer account into a patient by attaching the medical profile fields
from the brief's registration form (اسئلة1.pdf), without touching the `users` table or the
existing Site auth flow.

## Fields

| Column | Type | Constraints | Notes |
|---|---|---|---|
| `id` | bigint | PK | |
| `user_id` | bigint | `foreignId('user_id')->unique()->constrained('users')->cascadeOnDelete()` | 1:1 |
| `date_of_birth` | date | nullable | |
| `gender` | string | nullable | `male` / `female` |
| `occupation` | string | nullable | optional field per the brief |
| `medical_history` | json | nullable | `{ "hypertension": true, "diabetes": true, "heart_disease": false, "thyroid": true, "autoimmune": true, "reflux": true, "other": "text" }` |
| `surgical_history` | json | nullable | `{ "had_surgery": true, "type": "...", "date": "...", "hospital": "...", "notes": "..." }` |
| `medication_history` | json | nullable | `{ "on_medication": true, "steroids": true, "contraceptives": true, "psychiatric": true, "weight_gain": true, "other": "text", "notes": "..." }` |
| `allergy_type` | string | nullable | `drug` / `food` / `other` |
| `allergy_substance` | string | nullable | |
| `allergy_severity` | string | nullable | `mild` / `moderate` / `severe` |
| `allergy_notes` | text | nullable | |
| `created_at` / `updated_at` | timestamp | | |

## Relationships

| Relation | Type | Target |
|---|---|---|
| `user()` | `belongsTo` | `User` |
| `bookings()` | `hasMany` (via `user_id` on `clinic_bookings.patient_id`) | `Booking` |

## Decisions

- JSON columns for grouped checkbox-style data (matches the source form's structure directly:
  medical history, medication history are each a set of yes/no checkboxes plus a free-text
  "other") rather than a wide flat table of booleans — easier to extend if the checklist changes,
  and this data is always read/written as a whole group (a "medical profile"), never queried
  column-by-column.
- **Visible to Doctor and Patient only** — see `03-permissions-and-roles.md` §4. Never eager-load
  or select this table from any `Admin\Clinic\*` controller/service.
- The account itself (name, mobile, email, password, DOB verification) stays on the existing
  `users` table / `Site\AuthController` — this table only adds what's new.
