The overnight migration center occupied an old data floor with too few windows. Twelve screens showed separate queues: duplicate IDs, unclear consent, active-dose history and account separation.
On the whiteboard, privacy officer Wanjiru wrote the rule in large letters:
CLINICAL ID ≠ PHONE ≠ CLINIC ACCOUNT.
The old registry had relied heavily on phone numbers and membership accounts. Patients who changed phones, shared family numbers or accumulated duplicate accounts could appear as multiple people—or several people could appear under one contact identity.
Musa, the IT lead, opened a record set. “Same patient, three accounts. Phone changed twice.”
“Do not merge on name and phone alone,” Leila said.
They used a verified Board clinical token and human review.
Another record showed one phone number shared by a woman and two children. Automated merging would have invented a single patient out of three people. The team changed the rule: phone became a contact attribute, never a primary identity key.
The consent queue was worse. Old forms had bundled care, analytics and company communications into one checkbox.
“We cannot migrate that as full sharing consent,” Wanjiru said.
“Do we lose the record?”
“No. Minimum clinical safety data can remain restricted for continuity. Marketing and optional research stay off until the patient chooses.”
More than a thousand records moved into restricted status. The migration slowed, but uncertainty was not interpreted as yes.
Active-dose history began syncing from the clinics. Westpark sent Nuru's record under the permissions she had chosen. Leila saw only validation status, not the clinical content.
“You can see it passed without seeing inside,” Musa said.
“I'm learning.”
Before launch, seventeen active patients remained unresolved. The team contacted them only through their last permitted channels. Some allowed SMS but not calls; some shared devices with relatives. Five resolved their identity before launch. The rest went onto a manual continuity list so they would not disappear from care.
A cross-clinic test then simulated a Calm-X dose at Southline followed by an attempted second dose at Westpark. The red warning fired correctly.
“Go live?” Musa asked.
“Exception log signoff first,” Zawadi said.
IT signed integrity. Privacy signed consent handling. Pharmacy signed dose fields. The Board signed governance. There was no single hero button.
At 2:12 a.m., the portable registry went live.
One remote clinic showed high latency. Instead of caching full charts, the team reduced the safety query to minimum fields: identity status, last dose, protocol alert and critical allergy. Performance improved while less data moved.
“Minimum necessary can also be faster,” Leila said.
Ten minutes after launch, the first real alert appeared. A patient arrived at a clinic outside the old Nocturne network and said he had not taken Calm-X that night. His portable ID showed a dose at another hospital forty-five minutes earlier.
The pharmacist stopped the second authorization. The patient then remembered receiving a dose during a transfer, a detail obscured by a memory gap.
Samwel watched on the monitoring call. “This is the danger Adrian was right to fear.”
Leila nodded. “But the answer does not have to be his account forever.”
The system had preserved continuity without showing debt history, marketing data or private company notes.
Nocturne membership was no longer the patient's identity.
The migration team preserved every exception decision. Records with unclear consent stayed restricted; no one was allowed to convert uncertainty into permission merely to improve completion statistics. For the unresolved active patients, clinics received manual continuity instructions so a privacy safeguard would not become abandonment.
Musa also logged the performance optimization that reduced the safety query to minimum fields, including a rollback plan. Even a midnight engineering change had an owner and a trace. The new registry was not valuable because it never made mistakes. It was valuable because errors and changes did not disappear inside one provider's private account system.
Wanjiru required a brief post-launch privacy check as well. The alert had exposed only the last-dose fact and source facility, not the patient's debt or unrelated notes. Musa confirmed the access event had been logged and would expire from the pharmacist's active view after the clinical window. Continuity did not require permanent visibility.
The patient consented to the corrected treatment plan after the clinician explained what the alert had found. His memory gap became a clinical fact, not a reason to punish him for giving an inaccurate history.
The first live alert prevented a duplicate dose ten minutes after launch.