Curaeon Help Centre / KB-061
Open in the Help Centre →  ·  All topics
KB-061Security & privacyHow-to
Draft. This article is awaiting technical review and may change — if anything here conflicts with advice from our team, follow the team.

Restrict a patient's record, and open one in an emergency

Close a clinical record to everyone except named staff, know what the rest of the practice sees, and understand exactly what happens when someone opens it under Emergency access.

Before you start

Restricting is a clinician's action, done on the chart. It is for a record only some people should read: a member of staff or their family, a public figure, a patient at risk from someone who might work here, or a patient who asks. A restriction closes the chart — not the front desk's view, and not the Audit log.

Restrict a record

  1. Open the patient's chart and choose Restrict….
  2. Say why.
  3. Name who the record stays open to. You are always one of them.
The Restrict this record dialog: a reason seen only by those named, and the staff the record stays open to — you are already ticked and cannot untick yourself.
The Restrict this record dialog: a reason seen only by those named, and the staff the record stays open to — you are already ticked and cannot untick yourself.

What changes

What stays open. Details, contacts, the next appointment and the account. The patient still books, pays and is reminded; bookings, invoices and claims stay open.

What everyone else sees. Anyone not named sees who the record is open to — not why — instead of the chart. The same gate stands in front of every page of the record, however it is reached: a care plan, a result, a prescription, a referral, a scribe session, a task or a recall opened from a link.

Nothing is added by anyone else. Starting a consult, filing a scanned page, assigning a lab result, adding to the inbox, including the recall in a letter run and merging the record are all refused as restricted. An administrator who must merge one names themselves on it first, and that change is recorded.

On the patients screen. The row says Restricted record instead of an allergy alert or a recall due, and the patient is not counted under Allergy alert or Recall due — either would tell what the restriction keeps.

Lists and reports. Every worklist — inbox, lab feed, requests, scripts, recalls, tasks, the AIR backlog, the message queues, the coding backlog — and every patient-listing report leaves a restricted record's rows out for anyone it is not open to, and says how many it left out, so a list never looks finished when it is not. Being an administrator does not put anyone on a restriction.

The scribe. The appliance reads a restricted record's consult only when it connects with its certificate, or when its account is named on the restriction.

Change or lift a restriction

Those named, or an administrator, can change who the record is open to or lift it, from the banner on the chart. An administrator can do so without reading the record. Every change is kept.

Open a restricted record in an emergency

Anyone can, and the design assumes you will when you must.

  1. On the record, choose Emergency access.
  2. Give the reason in a sentence.
  3. Enter your own password again — so the name on the record is the person at the keyboard, not whoever left a session open.

The record then stays open to you alone for four hours.

What the practice sees afterwards

An alert is raised at once on Settings → Security review and the administrator's dashboard, and the access is listed in the weekly review. While any alert is unacknowledged, every administrator's sidebar carries a Security alerts link with the number on it. Curaeon sends nobody a message; the alert waits there to be read (KB-064 — Sign off the weekly Security review, and act on alerts and audit-log check warnings). Being turned away is recorded too, and an administrator reading the Audit log sees a restricted record's rows as any other — their own reading recorded as well.