Skip to content

Read a Patient's Records Across Facilities (Break-Glass)

A patient linked across the network has records at more than one facility. Seeing those records from another site is never automatic — it is a deliberate break-glass read: the clinician chooses to open it, the patient’s consent applies, and the access is written to the audit log. There is no ambient cross-facility visibility; a site’s data stays its own until someone consciously, and accountably, reaches for it.

Who / when: a Clinician treating a patient who has been seen at another facility in the network, when seeing the earlier record matters for care. Break-glass means a deliberate, logged access to information that is otherwise closed; it is allowed but it leaves a permanent trace.

We will follow Dr. Adeyemi, seeing a patient at a satellite clinic who was previously treated at the main hospital.

  1. Clinician — open the patient’s chart as usual. Because this patient is linked in the Master Patient Index (see Review and Link MPI Candidates), the chart shows a linked records affordance — a note that this person has a record at another facility in the network.
  2. Clinician — to read it, perform the cross-facility read. Veona checks the network policy (the patient’s consent must permit it) and confirms you intend to open another site’s record.
  3. Clinician — the record from the other facility opens for you to read in the context of this visit. You now have the earlier history you need.

You continue the visit with the fuller picture. The cross-facility read sits in the tamper-evident audit log alongside every other access, so a privacy officer can always account for who saw what across the network. Nothing about the other facility’s data changes — you read it; you did not move or merge it.