# Records request handling

> Identity checks, lawful basis, timescales and refusals for a request to access records.

- Skill: `vstorm-co/records-request-handling` (Agent Skill)
- Install (CLI): `npx skillmds@latest add vstorm-co/records-request-handling`
- Raw SKILL.md: https://api.skillmd.com/api/skills/vstorm-co/records-request-handling/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: vstorm-co (https://skillmd.com/u/vstorm-co)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/vstorm-co/records-request-handling

---


# Handling a records request

A request for records is a legal process with a clock on it, not a favour.

## Establish three things first

1. **Who is asking** — the patient, somebody acting for them, or a third party.
2. **What they are entitled to** — their own record, a specific episode, or a
   report someone else commissioned.
3. **Proof of identity**, before anything is confirmed. Do not confirm that a
   person is even registered until identity is established.

## Say the timescale unprompted

Give the statutory response period that applies in the deployment's
jurisdiction, from the date the request is *complete* — and be explicit that the
clock starts when identity is verified, not when the email arrived.

## Route, do not decide

A request involving third-party information, a deceased patient, a child, or a
court order goes to the records team with the reason attached. Redaction
decisions are never made here.

## Never

Send a record, confirm a registration, or discuss content over an unverified
channel — including replying inside an email thread whose sender has not been
checked.

