A check-in kiosk is a front desk that cannot see the patient
Most of the morning queue at reception is people saying "I'm here." A kiosk takes that off the desk, but it is a public device anyone can walk up to. This guide covers how it knows who it is talking to, what it shows them, and why it never writes to a file on its own.
Look at the reception queue at nine in the morning: most of the people in it need nothing from the receptionist except to know they have arrived. A patient booked for ten, a walk-in who wants a ticket, someone asking whether their old mobile number is still on file. Each one takes a minute or two, and behind them is a patient who actually needs the desk.
A self check-in kiosk — a tablet or touch screen in the waiting room — moves those minutes off the desk. But it is a device in a public place that anyone can walk up to, so the real question is not whether to put one in but how it knows who it is talking to, and what it shows them. It pairs with a waiting-room calling screen: the kiosk hands out the number, the screen calls it.
What a check-in kiosk is for
- Checking in for today's appointment: the patient joins the waiting list and shows on their doctor's list, without stopping at the desk.
- A ticket for a walk-in: for a doctor they choose or whoever is free.
- Confirming contact details: mobile, email, address, emergency contact and insurance — and asking to change them.
- A new patient's details: typed in by the patient before they reach the desk, so the receptionist starts from a filled-in form rather than a sheet of paper.
What it is not for: clinical questions, diagnoses, or showing a balance owed. Anything on a screen in the waiting room can be read by whoever is standing behind the patient.
How the kiosk knows who it is talking to
The rule: something the patient carries, plus something they know easily and a passer-by does not. A mobile or national ID/Iqama number, together with their date of birth. Searching by name is a mistake on a public device: typing "Mohammed" lists every Mohammed in your clinic.
| Way to identify | Fit for a public device? | Note |
|---|---|---|
| Search by name | No | Shows other patients' names to anyone typing |
| Mobile and date of birth | Yes | Family members may share one number |
| ID/Iqama and date of birth | Yes | The most exact, but not everyone knows theirs |
| File number alone | No | Printed on paperwork and easy to guess |
Never say which half was wrong
A kiosk that says "wrong date of birth" has told a stranger that the number belongs to one of your patients. "We couldn't find you" and "wrong birth date" must be one answer, given in about the same time, so the difference cannot be read from how fast it replies.
Limit the attempts, too: per number and per device. After a few wrong tries the patient is sent to reception, so nobody can work through birth dates one after another. And when two people match on number and birth date — twins — the kiosk asks which one they are, by name.
What the screen shows once it knows
Even after a correct match, the screen is visible to whoever is close by. So details are shown masked: enough for the patient to recognise as theirs, not enough for anyone else to use.
| Detail | Shown as | Why |
|---|---|---|
| Name | In full | It is theirs, and it is what the desk will call out |
| Mobile, ID and policy number | •••• 4567 | The last four, which they know and nobody else can use |
| n•••@gmail.com | The first letter and the domain only | |
| Address | First word ••• | Enough to recognise |
| City and insurer | As is | Neither points to one person |
| Birth date, file number, allergies, diagnoses, balance | Never | Nobody needs them to check in |
What matters most is where the masking happens: on the server, before the data leaves it. A tablet that receives the full number and hides it on screen can be read by plugging in a laptop or opening the developer tools. What never reaches the device cannot leak from it.
Why changes wait for reception
Imagine the kiosk updated the file directly. Anyone who knows a person's mobile and birth date — a relative, a colleague — could change their email or number, and their reminders and results would go somewhere else. So every change becomes a request: reception sees the old value beside the new one and approves what is right, field by field, leaving the rest. Name, date of birth and ID number are not changed from the kiosk at all, but at the desk, with a document.
New patients
A short form: full name, sex and mobile, with ID, email and city optional, and a question — would you like a ticket today? It reaches reception as a request at the top of the waiting list; the receptionist opens it as a registration form already filled in, checks the ID, and saves. Many "new" patients registered years ago and forgot, so there must be a way to link the request to the old file instead of creating a duplicate.
Setting one up
Choose the device and its place
Any tablet or touch screen with a modern browser, on a fixed stand at a height that suits someone standing and someone in a wheelchair, near the entrance and in sight of reception, with the screen not facing the seats.
Connect it without signing in
The kiosk never carries a staff account. It is connected with a short code it shows or a QR the manager scans with their phone, and disconnected from Settings in one tap if it is lost or moved.
Choose what it offers
Check-in, walk-in tickets, confirming details and new-patient registration — each one can be switched off. Pick the doctors who take walk-ins, the language, how quickly it clears, and the welcome message.
Test it before day one
Check in a test patient, then enter a wrong birth date and confirm the answer gives nothing away, then leave it untouched and confirm it clears.
Keeping it safe all day
- Clearing when left alone: a patient who walks off halfway must not leave their details for the next person. After some seconds untouched the kiosk asks "Are you still there?" and returns to its welcome.
- Nothing on the device: the kiosk keeps nothing about patients, so stealing it reveals nobody.
- A short session: a few minutes per patient, tied to that device.
- A dropped connection: a kiosk cannot check anyone in offline, so it says so plainly and sends patients to reception, rather than pretending it worked.
- Reception stays: older patients and anyone who does not read find the receptionist as before. The kiosk shortens the queue; it does not replace the desk.
How 3yadtk does it
Self check-in kiosks in 3yadtk are built on the rules above, at no extra cost. Patients identify themselves with their mobile or ID/Iqama number and their date of birth, and "not found" and "wrong birth date" get the same answer. There are five guesses per number and twenty per device. Details are masked on the server, and every change and every new patient reaches reception as a request on the waiting list. A kiosk stays off until the owner or a manager switches it on, a branch manager runs only their own branch's kiosks, and every step is in the activity log. The details are on the features page.
Shorten the queue at reception without opening anyone's file
Self check-in, walk-in tickets, masked details and changes your desk approves — on the one plan. Try it with your own patients.
Start your free trial