Home / Current Issue / Paper 1722261
A Three-Tier, Role-Based Architecture for Electronic Patient Records Management in Nigerian Secondary Hospitals: Design and Specification
Subject area: Science,Engineering and Technology · Area of research: Computer Engineering
DOI: https://doi.org/10.64388/IREV10I2-1722261
Abstract
Many secondary hospitals in Nigeria still use paper-based patient records, which are linked to redundant files, slow retrieval times, and disjointed departmental care coordination. The design and technical specifications of a Hospital Management System (HMS) with integrated electronic patient records are presented in this paper. The system is based on a three-tier client-server architecture that consists of a PostgreSQL relational data layer, a Node.js/Express.js application layer, and a React.js presentation layer. Registration, appointment scheduling, clinical consultation, pharmacy, laboratory, billing, reporting, and access control are the eight integrated functional modules that make up the system. These modules operate on a relational schema consisting of seventeen tables that have been normalized to the third normal form. The NIST RBAC standard serves as the foundation for the six-role role-based access control (RBAC) paradigm used in access control. The suggested design fully addresses locally relevant requirements, such as local health-insurance billing integration, that current platforms only partially address, according to an organized, criteria-based comparison against three widely used open-source platforms, OpenMRS, Bahmni, and HospitalRun. The work is provided as a verified architectural blueprint and specification for installation and subsequent empirical assessment in a Nigerian secondary-hospital scenario; it has not yet been benchmarked on an operational deployment as a design-stage contribution.
Keywords
Hospital Management System, Electronic Patient Records, Three-Tier Architecture, Role-Based Access Control, Database Normalization, Health Informatics, Nigeria
References
[1] Codd, E. F. (1970). A relational model of data for large shared data banks. Communications of the ACM, 13(6), 377–387. https://doi.org/10.1145/362384.362685
[2] Fagin, R. (1977). Multivalued dependencies and a new normal form for relational databases. ACM Transactions on Database Systems, 2(3), 262–278. https://doi.org/10.1145/320557.320571
[3] Ferraiolo, D. F., Sandhu, R., Gavrila, S., Kuhn, D. R., & Chandramouli, R. (2001). Proposed NIST standard for role-based access control. ACM Transactions on Information and System Security, 4(3), 224–274. https://doi.org/10.1145/501978.501980
[4] Fowler, M. (2002). Patterns of enterprise application architecture. Addison-Wesley.
[5] Jones, M., Bradley, J., & Sakimura, N. (2015). JSON Web Token (JWT) (RFC 7519). Internet Engineering Task Force. https://doi.org/10.17487/RFC7519
[6] Kruse, C. S., Smith, B., Vanderlinden, H., & Nealand, A. (2017). Security techniques for the electronic health records. Journal of Medical Systems, 41(8), Article 127. https://doi.org/10.1007/s10916-017-0778-4
[7] National Information Technology Development Agency (NITDA). (2019). Nigeria Data Protection Regulation 2019. Federal Republic of Nigeria. https://nitda.gov.ng/ndpr
[8] Nigeria Data Protection Commission (NDPC). (2023). Nigeria Data Protection Act, 2023. Federal Republic of Nigeria. https://ndpc.gov.ng
[9] OpenMRS Community. (2021). OpenMRS developer guide: Architecture and module development. OpenMRS Inc. https://wiki.openmrs.org/display/docs/Developer+Guide
[10] Adenuga, K. I., Iahad, N. A., & Miskon, S. (2017). Towards reinforcing telemedicine adoption amongst clinicians in Nigeria. International Journal of Medical Informatics, 104, 84–96. https://doi.org/10.1016/j.ijmedinf.2017.05.008
[11] Seebregts, C. J., Mamlin, B. W., Biondich, P. G., Fraser, H. S. F., Wolfe, B. A., Jazayeri, D., Allen, C., Miranda, J., Baker, E., Musinguzi, N., Kayiwa, D., Fourie, C., Lesh, N., Kanter, A., Yiannoutsos, C. T., Bailey, C., & the OpenMRS Implementers Network. (2009). The OpenMRS Implementers Network. International Journal of Medical Informatics, 78(11), 711–720. https://doi.org/10.1016/j.ijmedinf.2008.09.005
How to cite this paper
@article{1722261,
author = {Chukwuma Emmanuel Chinenye, Michael Oghale Ighofiomoni},
title = {A Three-Tier, Role-Based Architecture for Electronic Patient Records Management in Nigerian Secondary Hospitals: Design and Specification},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {2},
pages = {975-979},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722261.pdf},
abstract = {Many secondary hospitals in Nigeria still use paper-based patient records, which are linked to redundant files, slow retrieval times, and disjointed departmental care coordination. The design and technical specifications of a Hospital Management System (HMS) with integrated electronic patient records are presented in this paper. The system is based on a three-tier client-server architecture that consists of a PostgreSQL relational data layer, a Node.js/Express.js application layer, and a React.js presentation layer. Registration, appointment scheduling, clinical consultation, pharmacy, laboratory, billing, reporting, and access control are the eight integrated functional modules that make up the system. These modules operate on a relational schema consisting of seventeen tables that have been normalized to the third normal form. The NIST RBAC standard serves as the foundation for the six-role role-based access control (RBAC) paradigm used in access control. The suggested design fully addresses locally relevant requirements, such as local health-insurance billing integration, that current platforms only partially address, according to an organized, criteria-based comparison against three widely used open-source platforms, OpenMRS, Bahmni, and HospitalRun. The work is provided as a verified architectural blueprint and specification for installation and subsequent empirical assessment in a Nigerian secondary-hospital scenario; it has not yet been benchmarked on an operational deployment as a design-stage contribution.},
keywords = {Hospital Management System, Electronic Patient Records, Three-Tier Architecture, Role-Based Access Control, Database Normalization, Health Informatics, Nigeria},
month = {August},
doi = {https://doi.org/10.64388/IREV10I2-1722261}
}