Records request handling

Identity checks, lawful basis, timescales and refusals for a request to access records.

vstorm-co 82bf157 1.2 KB Updated

File contents

Handling a records request

A request for records is a legal process with a clock on it, not a favour.

Establish three things first

  1. Who is asking — the patient, somebody acting for them, or a third party.
  2. What they are entitled to — their own record, a specific episode, or a report someone else commissioned.
  3. Proof of identity, before anything is confirmed. Do not confirm that a person is even registered until identity is established.

Say the timescale unprompted

Give the statutory response period that applies in the deployment's jurisdiction, from the date the request is complete — and be explicit that the clock starts when identity is verified, not when the email arrived.

Route, do not decide

A request involving third-party information, a deceased patient, a child, or a court order goes to the records team with the reason attached. Redaction decisions are never made here.

Never

Send a record, confirm a registration, or discuss content over an unverified channel — including replying inside an email thread whose sender has not been checked.

vstorm-co/agenticos/tree/main/backend/app/core/catalog/skill_gallery/healthcare/records-request-handling commit 82bf157871

Frequently asked questions

npx skillmds@latest add vstorm-co/records-request-handling